分析类型 | 虚拟机标签 | 开始时间 | 结束时间 | 持续时间 |
---|---|---|---|---|
文件 (Windows) | win7-sp1-x64-hpdapp01-1 | 2019-12-09 18:13:02 | 2019-12-09 18:15:38 | 156 秒 |
文件名 | MasterZ_Custom_93.exe |
---|---|
文件大小 | 10454664 字节 |
文件类型 | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
MD5 | 70028b45526712f0a0e2e303c9832ad3 |
SHA1 | 59d669e7beae9d90d1cbd67a7422446bb85e80a4 |
SHA256 | 9a7d4bdcf84cec14b83c9442bbc97aeac78429273bb313c70d5bc8f203be2b0a |
SHA512 | 693f13e85ded9b60a417b463bb246d3ece24b90bac9aea68203ad0fa2a342ae5d6ef7b32cf740f4a96b8ad47be923249c5ce99f47c89e025e1d5067de7c72ee8 |
CRC32 | 8F240AE4 |
Ssdeep | 196608:oIOwfMKp3AN4Jzt4x7QC/lp+9xSH94pqWKCjagaGnDSO0uUXlYpVILJ8:oIEKp3g4ht4xSmHOqij0Gni+VI |
Yara | 登录查看Yara规则 |
样本下载 提交误报 |
无主机纪录.
无域名信息.
初始地址 | 0x00400000 |
---|---|
入口地址 | 0x0040354b |
声明校验值 | 0x009fabc1 |
实际校验值 | 0x009fabc1 |
最低操作系统版本要求 | 5.0 |
编译时间 | 2010-04-10 20:19:31 |
载入哈希 | b729b61eb1515fcf7b3e511e4e66258b |
LegalCopyright | |
---|---|
ProductName | |
ProductVersion | |
FileDescription | |
Translation |
SHA1 | 时间戳 | 有效性 | 错误 |
---|---|---|---|
None | Fri Nov 22 09:36:36 2019 | 无 |
证书链 | Certificate Chain 1 |
发行给 | Certum Trusted Network CA |
发行人 | Certum Trusted Network CA |
有效期 | Mon Dec 31 200737 2029 |
SHA1 哈希 | 07e032e020b72c3f192f0628a2593a19a70f069e |
证书链 | Certificate Chain 2 |
发行给 | WoTrus Code Signing CA |
发行人 | Certum Trusted Network CA |
有效期 | Tue May 18 162015 2027 |
SHA1 哈希 | d0c864713473adbd12052962e7c68d876a90dbbf |
证书链 | Certificate Chain 3 |
发行给 | Shenzhen Shangzhou Net Technology Co., Ltd. |
发行人 | WoTrus Code Signing CA |
有效期 | Sun Dec 20 154303 2020 |
SHA1 哈希 | 98f4327966f8b44f5aaa75ffa19e5c6a0a1c40e5 |
证书链 | Timestamp Chain 1 |
发行给 | DigiCert Assured ID Root CA |
发行人 | DigiCert Assured ID Root CA |
有效期 | Mon Nov 10 080000 2031 |
SHA1 哈希 | 0563b8630d62d75abbc8ab1e4bdfb5a899b24d43 |
证书链 | Timestamp Chain 2 |
发行给 | DigiCert SHA2 Assured ID Timestamping CA |
发行人 | DigiCert Assured ID Root CA |
有效期 | Tue Jan 07 200000 2031 |
SHA1 哈希 | 3ba63a6e4841355772debef9cdcf4d5af353a297 |
证书链 | Timestamp Chain 3 |
发行给 | TIMESTAMP-SHA256-2019-10-15 |
发行人 | DigiCert SHA2 Assured ID Timestamping CA |
有效期 | Thu Oct 17 080000 2030 |
SHA1 哈希 | 0325bd505eda96302dc22f4fa01e4c28be2834c5 |
名称 | 虚拟地址 | 虚拟大小 | 原始数据大小 | 特征 | 熵(Entropy) |
---|---|---|---|---|---|
.text | 0x00001000 | 0x000063a2 | 0x00006400 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ | 6.48 |
.rdata | 0x00008000 | 0x000018f2 | 0x00001a00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 4.89 |
.data | 0x0000a000 | 0x0006669c | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 1.43 |
.ndata | 0x00071000 | 0x000a1000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 0.00 |
.rsrc | 0x00112000 | 0x00006ee8 | 0x00007000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 5.76 |
防病毒引擎/厂商 | 病毒名/规则匹配 | 病毒库日期 |
---|---|---|
Bkav | 未发现病毒 | 20191209 |
MicroWorld-eScan | 未发现病毒 | 20191209 |
CMC | 未发现病毒 | 20190321 |
CAT-QuickHeal | 未发现病毒 | 20191208 |
McAfee | 未发现病毒 | 20191209 |
Cylance | 未发现病毒 | 20191209 |
Zillya | 未发现病毒 | 20191207 |
SUPERAntiSpyware | 未发现病毒 | 20191203 |
Sangfor | 未发现病毒 | 20191031 |
K7AntiVirus | 未发现病毒 | 20191209 |
Alibaba | 未发现病毒 | 20190527 |
K7GW | 未发现病毒 | 20191209 |
Cybereason | 未发现病毒 | 20190616 |
TrendMicro | 未发现病毒 | 20191209 |
Baidu | 未发现病毒 | 20190318 |
F-Prot | 未发现病毒 | 20191209 |
Symantec | 未发现病毒 | 20191208 |
TotalDefense | 未发现病毒 | 20191209 |
APEX | 未发现病毒 | 20191207 |
Avast | 未发现病毒 | 20191209 |
ClamAV | 未发现病毒 | 20191208 |
GData | 未发现病毒 | 20191209 |
Kaspersky | 未发现病毒 | 20191209 |
BitDefender | 未发现病毒 | 20191209 |
NANO-Antivirus | 未发现病毒 | 20191209 |
ViRobot | 未发现病毒 | 20191209 |
Tencent | 未发现病毒 | 20191209 |
Endgame | 未发现病毒 | 20190918 |
Emsisoft | 未发现病毒 | 20191209 |
Comodo | 未发现病毒 | 20191209 |
F-Secure | 未发现病毒 | 20191209 |
DrWeb | DLOADER.Trojan | 20191209 |
VIPRE | Dialer.Win32.GBDialer.i (v) | 20191209 |
Invincea | 未发现病毒 | 20190904 |
McAfee-GW-Edition | 未发现病毒 | 20191208 |
FireEye | 未发现病毒 | 20191209 |
Sophos | 未发现病毒 | 20191209 |
Paloalto | 未发现病毒 | 20191209 |
Cyren | 未发现病毒 | 20191209 |
Jiangmin | 未发现病毒 | 20191209 |
Webroot | 未发现病毒 | 20191209 |
Avira | 未发现病毒 | 20191209 |
Antiy-AVL | 未发现病毒 | 20191209 |
Kingsoft | 未发现病毒 | 20191209 |
Microsoft | 未发现病毒 | 20191209 |
Arcabit | 未发现病毒 | 20191209 |
AegisLab | 未发现病毒 | 20191209 |
ZoneAlarm | 未发现病毒 | 20191209 |
Avast-Mobile | 未发现病毒 | 20191209 |
TACHYON | 未发现病毒 | 20191209 |
AhnLab-V3 | 未发现病毒 | 20191209 |
Acronis | 未发现病毒 | 20191209 |
VBA32 | 未发现病毒 | 20191209 |
ALYac | 未发现病毒 | 20191209 |
MAX | 未发现病毒 | 20191209 |
Ad-Aware | 未发现病毒 | 20191209 |
Malwarebytes | 未发现病毒 | 20191209 |
Zoner | 未发现病毒 | 20191209 |
ESET-NOD32 | 未发现病毒 | 20191209 |
TrendMicro-HouseCall | 未发现病毒 | 20191209 |
Rising | 未发现病毒 | 20191209 |
Yandex | 未发现病毒 | 20191208 |
SentinelOne | 未发现病毒 | 20191203 |
MaxSecure | 未发现病毒 | 20191207 |
Fortinet | 未发现病毒 | 20191209 |
BitDefenderTheta | 未发现病毒 | 20191204 |
AVG | 未发现病毒 | 20191209 |
Panda | 未发现病毒 | 20191208 |
CrowdStrike | 未发现病毒 | 20190702 |
Qihoo-360 | 未发现病毒 | 20191209 |
无主机纪录.
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
112.74.102.50 | 21 | 192.168.122.201 | 49207 |
112.74.102.50 | 30392 | 192.168.122.201 | 49208 |
112.74.102.50 | 30393 | 192.168.122.201 | 49209 |
112.74.102.50 | 30394 | 192.168.122.201 | 49210 |
112.74.102.50 | 30395 | 192.168.122.201 | 49211 |
112.74.102.50 | 30396 | 192.168.122.201 | 49212 |
112.74.102.50 | 30397 | 192.168.122.201 | 49213 |
112.74.102.50 | 30398 | 192.168.122.201 | 49214 |
112.74.102.50 | 30399 | 192.168.122.201 | 49215 |
112.74.102.50 | 30400 | 192.168.122.201 | 49216 |
112.74.102.50 | 30401 | 192.168.122.201 | 49217 |
112.74.102.50 | 30402 | 192.168.122.201 | 49218 |
112.74.102.50 | 30403 | 192.168.122.201 | 49219 |
112.74.102.50 | 30404 | 192.168.122.201 | 49220 |
112.74.102.50 | 30405 | 192.168.122.201 | 49221 |
112.74.102.50 | 30406 | 192.168.122.201 | 49222 |
112.74.102.50 | 30407 | 192.168.122.201 | 49223 |
112.74.102.50 | 30408 | 192.168.122.201 | 49224 |
112.74.102.50 | 30409 | 192.168.122.201 | 49225 |
112.74.102.50 | 30410 | 192.168.122.201 | 49226 |
112.74.102.50 | 30411 | 192.168.122.201 | 49227 |
112.74.102.50 | 30412 | 192.168.122.201 | 49228 |
112.74.102.50 | 30413 | 192.168.122.201 | 49229 |
112.74.102.50 | 30414 | 192.168.122.201 | 49230 |
112.74.102.50 | 30415 | 192.168.122.201 | 49231 |
112.74.102.50 | 30416 | 192.168.122.201 | 49232 |
112.74.102.50 | 30417 | 192.168.122.201 | 49233 |
112.74.102.50 | 30418 | 192.168.122.201 | 49234 |
112.74.102.50 | 30419 | 192.168.122.201 | 49235 |
112.74.102.50 | 30420 | 192.168.122.201 | 49236 |
112.74.102.50 | 30421 | 192.168.122.201 | 49237 |
112.74.102.50 | 30422 | 192.168.122.201 | 49238 |
112.74.102.50 | 30423 | 192.168.122.201 | 49239 |
112.74.102.50 | 30424 | 192.168.122.201 | 49240 |
112.74.102.50 | 30425 | 192.168.122.201 | 49241 |
112.74.102.50 | 30426 | 192.168.122.201 | 49242 |
112.74.102.50 | 30427 | 192.168.122.201 | 49243 |
112.74.102.50 | 30428 | 192.168.122.201 | 49244 |
112.74.102.50 | 30429 | 192.168.122.201 | 49245 |
112.74.102.50 | 30430 | 192.168.122.201 | 49246 |
112.74.102.50 | 30431 | 192.168.122.201 | 49247 |
112.74.102.50 | 30432 | 192.168.122.201 | 49248 |
112.74.102.50 | 30433 | 192.168.122.201 | 49249 |
112.74.102.50 | 30434 | 192.168.122.201 | 49250 |
112.74.102.50 | 30435 | 192.168.122.201 | 49251 |
112.74.102.50 | 30436 | 192.168.122.201 | 49252 |
112.74.102.50 | 30437 | 192.168.122.201 | 49253 |
112.74.102.50 | 30438 | 192.168.122.201 | 49254 |
112.74.102.50 | 30439 | 192.168.122.201 | 49255 |
112.74.102.50 | 30440 | 192.168.122.201 | 49256 |
112.74.102.50 | 30441 | 192.168.122.201 | 49257 |
112.74.102.50 | 30442 | 192.168.122.201 | 49258 |
112.74.102.50 | 30443 | 192.168.122.201 | 49259 |
112.74.102.50 | 30444 | 192.168.122.201 | 49260 |
112.74.102.50 | 30445 | 192.168.122.201 | 49261 |
112.74.102.50 | 30446 | 192.168.122.201 | 49262 |
112.74.102.50 | 30447 | 192.168.122.201 | 49263 |
112.74.102.50 | 30448 | 192.168.122.201 | 49264 |
112.74.102.50 | 30449 | 192.168.122.201 | 49265 |
112.74.102.50 | 30451 | 192.168.122.201 | 49266 |
112.74.102.50 | 30452 | 192.168.122.201 | 49267 |
112.74.102.50 | 30453 | 192.168.122.201 | 49268 |
112.74.102.50 | 30454 | 192.168.122.201 | 49269 |
112.74.102.50 | 30455 | 192.168.122.201 | 49270 |
112.74.102.50 | 30456 | 192.168.122.201 | 49271 |
112.74.102.50 | 30457 | 192.168.122.201 | 49272 |
112.74.102.50 | 30458 | 192.168.122.201 | 49273 |
112.74.102.50 | 30459 | 192.168.122.201 | 49274 |
112.74.102.50 | 30460 | 192.168.122.201 | 49275 |
112.74.102.50 | 30461 | 192.168.122.201 | 49276 |
112.74.102.50 | 30462 | 192.168.122.201 | 49277 |
112.74.102.50 | 30463 | 192.168.122.201 | 49278 |
112.74.102.50 | 30464 | 192.168.122.201 | 49279 |
112.74.102.50 | 30465 | 192.168.122.201 | 49280 |
112.74.102.50 | 30466 | 192.168.122.201 | 49281 |
112.74.102.50 | 30469 | 192.168.122.201 | 49282 |
112.74.102.50 | 30471 | 192.168.122.201 | 49283 |
112.74.102.50 | 30472 | 192.168.122.201 | 49284 |
112.74.102.50 | 30474 | 192.168.122.201 | 49285 |
112.74.102.50 | 30477 | 192.168.122.201 | 49286 |
112.74.102.50 | 30482 | 192.168.122.201 | 49287 |
112.74.102.50 | 30485 | 192.168.122.201 | 49288 |
112.74.102.50 | 30487 | 192.168.122.201 | 49289 |
112.74.102.50 | 30489 | 192.168.122.201 | 49290 |
112.74.102.50 | 30492 | 192.168.122.201 | 49291 |
112.74.102.50 | 30493 | 192.168.122.201 | 49292 |
112.74.102.50 | 30494 | 192.168.122.201 | 49293 |
112.74.102.50 | 30495 | 192.168.122.201 | 49294 |
112.74.102.50 | 30496 | 192.168.122.201 | 49295 |
112.74.102.50 | 30497 | 192.168.122.201 | 49296 |
112.74.102.50 | 30498 | 192.168.122.201 | 49297 |
112.74.102.50 | 30499 | 192.168.122.201 | 49298 |
112.74.102.50 | 30500 | 192.168.122.201 | 49299 |
112.74.102.50 | 30502 | 192.168.122.201 | 49300 |
112.74.102.50 | 30504 | 192.168.122.201 | 49301 |
112.74.102.50 | 30505 | 192.168.122.201 | 49302 |
112.74.102.50 | 30507 | 192.168.122.201 | 49303 |
112.74.102.50 | 30509 | 192.168.122.201 | 49304 |
112.74.102.50 | 30511 | 192.168.122.201 | 49305 |
无UDP连接纪录.
无域名信息.
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
112.74.102.50 | 21 | 192.168.122.201 | 49207 |
112.74.102.50 | 30392 | 192.168.122.201 | 49208 |
112.74.102.50 | 30393 | 192.168.122.201 | 49209 |
112.74.102.50 | 30394 | 192.168.122.201 | 49210 |
112.74.102.50 | 30395 | 192.168.122.201 | 49211 |
112.74.102.50 | 30396 | 192.168.122.201 | 49212 |
112.74.102.50 | 30397 | 192.168.122.201 | 49213 |
112.74.102.50 | 30398 | 192.168.122.201 | 49214 |
112.74.102.50 | 30399 | 192.168.122.201 | 49215 |
112.74.102.50 | 30400 | 192.168.122.201 | 49216 |
112.74.102.50 | 30401 | 192.168.122.201 | 49217 |
112.74.102.50 | 30402 | 192.168.122.201 | 49218 |
112.74.102.50 | 30403 | 192.168.122.201 | 49219 |
112.74.102.50 | 30404 | 192.168.122.201 | 49220 |
112.74.102.50 | 30405 | 192.168.122.201 | 49221 |
112.74.102.50 | 30406 | 192.168.122.201 | 49222 |
112.74.102.50 | 30407 | 192.168.122.201 | 49223 |
112.74.102.50 | 30408 | 192.168.122.201 | 49224 |
112.74.102.50 | 30409 | 192.168.122.201 | 49225 |
112.74.102.50 | 30410 | 192.168.122.201 | 49226 |
112.74.102.50 | 30411 | 192.168.122.201 | 49227 |
112.74.102.50 | 30412 | 192.168.122.201 | 49228 |
112.74.102.50 | 30413 | 192.168.122.201 | 49229 |
112.74.102.50 | 30414 | 192.168.122.201 | 49230 |
112.74.102.50 | 30415 | 192.168.122.201 | 49231 |
112.74.102.50 | 30416 | 192.168.122.201 | 49232 |
112.74.102.50 | 30417 | 192.168.122.201 | 49233 |
112.74.102.50 | 30418 | 192.168.122.201 | 49234 |
112.74.102.50 | 30419 | 192.168.122.201 | 49235 |
112.74.102.50 | 30420 | 192.168.122.201 | 49236 |
112.74.102.50 | 30421 | 192.168.122.201 | 49237 |
112.74.102.50 | 30422 | 192.168.122.201 | 49238 |
112.74.102.50 | 30423 | 192.168.122.201 | 49239 |
112.74.102.50 | 30424 | 192.168.122.201 | 49240 |
112.74.102.50 | 30425 | 192.168.122.201 | 49241 |
112.74.102.50 | 30426 | 192.168.122.201 | 49242 |
112.74.102.50 | 30427 | 192.168.122.201 | 49243 |
112.74.102.50 | 30428 | 192.168.122.201 | 49244 |
112.74.102.50 | 30429 | 192.168.122.201 | 49245 |
112.74.102.50 | 30430 | 192.168.122.201 | 49246 |
112.74.102.50 | 30431 | 192.168.122.201 | 49247 |
112.74.102.50 | 30432 | 192.168.122.201 | 49248 |
112.74.102.50 | 30433 | 192.168.122.201 | 49249 |
112.74.102.50 | 30434 | 192.168.122.201 | 49250 |
112.74.102.50 | 30435 | 192.168.122.201 | 49251 |
112.74.102.50 | 30436 | 192.168.122.201 | 49252 |
112.74.102.50 | 30437 | 192.168.122.201 | 49253 |
112.74.102.50 | 30438 | 192.168.122.201 | 49254 |
112.74.102.50 | 30439 | 192.168.122.201 | 49255 |
112.74.102.50 | 30440 | 192.168.122.201 | 49256 |
112.74.102.50 | 30441 | 192.168.122.201 | 49257 |
112.74.102.50 | 30442 | 192.168.122.201 | 49258 |
112.74.102.50 | 30443 | 192.168.122.201 | 49259 |
112.74.102.50 | 30444 | 192.168.122.201 | 49260 |
112.74.102.50 | 30445 | 192.168.122.201 | 49261 |
112.74.102.50 | 30446 | 192.168.122.201 | 49262 |
112.74.102.50 | 30447 | 192.168.122.201 | 49263 |
112.74.102.50 | 30448 | 192.168.122.201 | 49264 |
112.74.102.50 | 30449 | 192.168.122.201 | 49265 |
112.74.102.50 | 30451 | 192.168.122.201 | 49266 |
112.74.102.50 | 30452 | 192.168.122.201 | 49267 |
112.74.102.50 | 30453 | 192.168.122.201 | 49268 |
112.74.102.50 | 30454 | 192.168.122.201 | 49269 |
112.74.102.50 | 30455 | 192.168.122.201 | 49270 |
112.74.102.50 | 30456 | 192.168.122.201 | 49271 |
112.74.102.50 | 30457 | 192.168.122.201 | 49272 |
112.74.102.50 | 30458 | 192.168.122.201 | 49273 |
112.74.102.50 | 30459 | 192.168.122.201 | 49274 |
112.74.102.50 | 30460 | 192.168.122.201 | 49275 |
112.74.102.50 | 30461 | 192.168.122.201 | 49276 |
112.74.102.50 | 30462 | 192.168.122.201 | 49277 |
112.74.102.50 | 30463 | 192.168.122.201 | 49278 |
112.74.102.50 | 30464 | 192.168.122.201 | 49279 |
112.74.102.50 | 30465 | 192.168.122.201 | 49280 |
112.74.102.50 | 30466 | 192.168.122.201 | 49281 |
112.74.102.50 | 30469 | 192.168.122.201 | 49282 |
112.74.102.50 | 30471 | 192.168.122.201 | 49283 |
112.74.102.50 | 30472 | 192.168.122.201 | 49284 |
112.74.102.50 | 30474 | 192.168.122.201 | 49285 |
112.74.102.50 | 30477 | 192.168.122.201 | 49286 |
112.74.102.50 | 30482 | 192.168.122.201 | 49287 |
112.74.102.50 | 30485 | 192.168.122.201 | 49288 |
112.74.102.50 | 30487 | 192.168.122.201 | 49289 |
112.74.102.50 | 30489 | 192.168.122.201 | 49290 |
112.74.102.50 | 30492 | 192.168.122.201 | 49291 |
112.74.102.50 | 30493 | 192.168.122.201 | 49292 |
112.74.102.50 | 30494 | 192.168.122.201 | 49293 |
112.74.102.50 | 30495 | 192.168.122.201 | 49294 |
112.74.102.50 | 30496 | 192.168.122.201 | 49295 |
112.74.102.50 | 30497 | 192.168.122.201 | 49296 |
112.74.102.50 | 30498 | 192.168.122.201 | 49297 |
112.74.102.50 | 30499 | 192.168.122.201 | 49298 |
112.74.102.50 | 30500 | 192.168.122.201 | 49299 |
112.74.102.50 | 30502 | 192.168.122.201 | 49300 |
112.74.102.50 | 30504 | 192.168.122.201 | 49301 |
112.74.102.50 | 30505 | 192.168.122.201 | 49302 |
112.74.102.50 | 30507 | 192.168.122.201 | 49303 |
112.74.102.50 | 30509 | 192.168.122.201 | 49304 |
112.74.102.50 | 30511 | 192.168.122.201 | 49305 |
无UDP连接纪录.
未发现HTTP请求.
无SMTP流量.
无IRC请求.
无ICMP流量.
无 CIF 结果
Timestamp | Source IP | Source Port | Destination IP | Destination Port | Protocol | SID | Signature | Category |
---|---|---|---|---|---|---|---|---|
2019-12-09 18:14:52.988963+0800 | 112.74.102.50 | 21 | 192.168.122.201 | 49207 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
No TLS
No Suricata HTTP
HTML 总结报告 (需15-60分钟同步) |
下载 |
---|
Task ID | 471283 |
---|---|
Mongo ID | 5dee1f5b2f8f2e4e2ab0d847 |
Cuckoo release | 1.4-Maldun |