分析任务

分析类型 虚拟机标签 开始时间 结束时间 持续时间
文件 (Windows) win7-sp1-x64 2016-11-06 20:10:21 2016-11-06 20:12:36 135 秒

魔盾分数

2.0

正常的

文件详细信息

文件名 index.dat
文件大小 49152 字节
文件类型 Internet Explorer cache file version Ver 5.2
MD5 7ad7458a9350e61dfaa035d5708dccbf
SHA1 0a8175fb63a81cabdecf72dcda91a961d33da613
SHA256 bae5b46b567b39d8907106c4e2c46fb53bc0062409b410b9ebc0f1dd683bafc8
SHA512 580c415f10527c2607167ea948f0a5a6e2eb376bd2bd5fdb41900fca2b0d35199d4a7594cfedaa9f27d691ee13fadf8e2ecd765f14622f31c79cefce62388dd2
CRC32 8FED115B
Ssdeep 192:cFQeNHSQCkCVCSsZseIuoV/zYBFYfA60G:LEHSQCkCVCSsyeIuoV/zYjYfD0G
Yara 登录查看Yara规则
样本下载 提交漏报

登录查看威胁特征

运行截图


访问主机纪录 (可点击查询WPING实时安全评级)

无主机纪录.

域名解析 (可点击查询WPING实时安全评级)

无域名信息.


摘要

登录查看详细行为信息
没有可用的静态分析.
Client UrlCache MMF Ver 5.2
HASH
Cookie:test@ynuf.alipay.com/
test@ynuf.alipay[1].txt
Cookie:test@pos.baidu.com/
test@pos.baidu[2].txt
Cookie:test@java.com/
test@java[1].txt
Cookie:test@mmstat.com/
test@mmstat[1].txt
Cookie:test@cpro.baidustatic.com/
test@cpro.baidustatic[1].txt
Cookie:test@behe.com/
test@behe[2].txt
Cookie:test@miaozhen.com/
test@miaozhen[1].txt
Cookie:test@springairlines.sc.omtrdc.net/
test@springairlines.sc.omtrdc[2].txt
Cookie:test@zhidao.baidu.com/
test@zhidao.baidu[1].txt
Cookie:test@firefoxchina.cn/
test@firefoxchina[1].txt
Cookie:test@taobao.com/
test@taobao[1].txt
Cookie:test@wrating.com/
test@wrating[1].txt
Cookie:test@cdn.tanx.com/
test@cdn.tanx[3].txt
Cookie:test@www.sohu.com/
test@www.sohu[2].txt
Cookie:test@stackoverflow.com/
test@stackoverflow[2].txt
Cookie:test@officestore.microsoft.com/
test@officestore.microsoft[1].txt
Cookie:test@pccppc.com/
test@pccppc[2].txt
Cookie:test@tanx.com/
test@tanx[2].txt
Cookie:test@kejet.net/
test@kejet[2].txt
Cookie:test@www.sina.com.cn/
test@www.sina.com[2].txt
Cookie:test@passport.weibo.com/visitor/
test@passport.weibo[1].txt
Cookie:test@revsci.net/
test@revsci[1].txt
Cookie:test@baifendian.com/
test@baifendian[1].txt
Cookie:test@mediav.com/
test@mediav[2].txt
Cookie:test@mlt01.com/
test@mlt01[1].txt
Cookie:test@sina.com.cn/
test@sina.com[1].txt
Cookie:test@imgur.com/
test@imgur[2].txt
Cookie:test@weibo.com/
test@weibo[2].txt
Cookie:test@passport.weibo.com/
test@passport.weibo[3].txt
Cookie:test@cdn.tanx.com/t/acookie/
test@cdn.tanx[1].txt
Cookie:test@qtmojo.com/
test@qtmojo[2].txt
Cookie:test@release.baidu.com/
test@release.baidu[1].txt
Cookie:test@count.612.com/
test@count.612[1].txt
Cookie:test@ad-plus.cn/
test@ad-plus[1].txt
Cookie:test@www.bing.com/
test@www.bing[1].txt
Cookie:test@quantserve.com/
test@quantserve[1].txt
Cookie:test@cn.bing.com/
test@cn.bing[2].txt
Cookie:test@doubanio.com/
test@doubanio[1].txt
Cookie:test@oracle.112.2o7.net/
test@oracle.112.2o7[2].txt
Cookie:test@github.com/
test@github[1].txt
Cookie:test@ipinyou.com/
test@ipinyou[2].txt
Cookie:test@shields.io/
test@shields[2].txt
Cookie:test@rarfile.readthedocs.io/
test@rarfile.readthedocs[1].txt
Cookie:test@doubleclick.net/
test@doubleclick[1].txt
Cookie:test@hm.baidu.com/
test@hm.baidu[2].txt
Cookie:test@softpedia.com/
test@softpedia[2].txt
Cookie:test@adzerk.net/
test@adzerk[1].txt
Cookie:test@passport.baidu.com/
test@passport.baidu[2].txt
Cookie:test@daomubj2.b0.upaiyun.com/
test@daomubj2.b0.upaiyun[1].txt
Cookie:test@blog.csdn.net/
test@blog.csdn[2].txt
Cookie:test@rarlab.com/
test@rarlab[1].txt
Cookie:test@yigao.com/
test@yigao[1].txt
Cookie:test@emarbox.com/
test@emarbox[2].txt
Cookie:test@sh.114so.cn/
test@sh.114so[2].txt
Cookie:test@youku.com/
test@youku[2].txt
Cookie:test@scorecardresearch.com/
test@scorecardresearch[2].txt
Cookie:test@softonic.com/
test@softonic[2].txt
Cookie:test@engine.adzerk.net/
test@engine.adzerk[1].txt
Cookie:test@maldun.com/
test@maldun[1].txt
Cookie:test@casalemedia.com/
test@casalemedia[1].txt
Cookie:test@ch.com/
test@ch[1].txt
Cookie:test@irs01.com/
test@irs01[2].txt
Cookie:test@ad.winrar.com.cn/
test@ad.winrar.com[1].txt
Cookie:test@python.org/
test@python[1].txt
Cookie:test@cnzz.mmstat.com/
test@cnzz.mmstat[1].txt
Cookie:test@a.adt100.com/
test@a.adt100[1].txt
Cookie:test@cnzz.com/
test@cnzz[1].txt
Cookie:test@lc.ch.com/
test@lc.ch[1].txt
Cookie:test@bing.com/
test@bing[1].txt
Cookie:test@ad-stir.com/
test@ad-stir[2].txt
Cookie:test@tynt.com/
test@tynt[2].txt
Cookie:test@outofmemory.cn/
test@outofmemory[1].txt
Cookie:test@agkn.com/
test@agkn[2].txt
Cookie:test@mookie1.com/
test@mookie1[2].txt
Cookie:test@rarzilla-free-unrar.en.softonic.com/
test@rarzilla-free-unrar.en.softonic[2].txt
Cookie:test@serving-sys.com/
test@serving-sys[2].txt
Cookie:test@bs.serving-sys.com/
test@bs.serving-sys[1].txt
Cookie:test@admaster.com.cn/
test@admaster.com[1].txt
Cookie:test@rfihub.com/
test@rfihub[2].txt
Cookie:test@baidu.com/
test@baidu[2].txt
Cookie:test@cr173.com/
test@cr173[1].txt
Cookie:test@www.baidu.com/
test@www.baidu[1].txt
Cookie:test@gtags.net/
test@gtags[2].txt
Cookie:test@www.cr173.com/
test@www.cr173[2].txt
Cookie:test@maldun.com/
test@maldun[2].txt
没有防病毒引擎扫描信息!

进程树


cmd.exe, PID: 2520, 上一级进程 PID: 2556
services.exe, PID: 452, 上一级进程 PID: 356
svchost.exe, PID: 1220, 上一级进程 PID: 452
rundll32.exe, PID: 1908, 上一级进程 PID: 2520

访问主机纪录 (可点击查询WPING实时安全评级)

无主机纪录.

TCP

无TCP连接纪录.

UDP

无UDP连接纪录.

域名解析 (可点击查询WPING实时安全评级)

无域名信息.

TCP

无TCP连接纪录.

UDP

无UDP连接纪录.

HTTP 请求

未发现HTTP请求.

SMTP 流量

无SMTP流量.

IRC 流量

无IRC请求.

ICMP 流量

无ICMP流量.

CIF 报告

无 CIF 结果

网络警报

无警报

TLS

No TLS

Suricata HTTP

No Suricata HTTP

未发现网络提取文件
抱歉! 没有任何文件投放。
没有发现相似的分析.
HTML 总结报告
(需15-60分钟同步)
下载

Processing ( 3.839 seconds )

  • 3.34 VirusTotal
  • 0.218 BehaviorAnalysis
  • 0.189 TargetInfo
  • 0.041 NetworkAnalysis
  • 0.023 AnalysisInfo
  • 0.009 Strings
  • 0.008 Debug
  • 0.006 Static
  • 0.002 Dropped
  • 0.002 Memory
  • 0.001 ProcessMemory

Signatures ( 0.154 seconds )

  • 0.036 antiav_detectreg
  • 0.014 infostealer_ftp
  • 0.008 betabot_behavior
  • 0.008 stealth_timeout
  • 0.008 infostealer_im
  • 0.007 antianalysis_detectreg
  • 0.007 antiav_detectfile
  • 0.006 persistence_autorun
  • 0.006 infostealer_mail
  • 0.005 ransomware_files
  • 0.004 infostealer_bitcoin
  • 0.004 md_bad_drop
  • 0.003 tinba_behavior
  • 0.003 shifu_behavior
  • 0.003 geodo_banking_trojan
  • 0.003 bot_drive2
  • 0.003 disables_browser_warn
  • 0.002 mimics_filetime
  • 0.002 kibex_behavior
  • 0.002 antivm_generic_disk
  • 0.002 antivm_vbox_files
  • 0.002 bot_drive
  • 0.002 browser_security
  • 0.001 bootkit
  • 0.001 reads_self
  • 0.001 stealth_file
  • 0.001 antivm_generic_scsi
  • 0.001 vawtrak_behavior
  • 0.001 virus
  • 0.001 antivm_generic_diskreg
  • 0.001 banker_zeus_mutex
  • 0.001 bot_athenahttp
  • 0.001 browser_addon
  • 0.001 modify_proxy
  • 0.001 darkcomet_regkeys
  • 0.001 modify_uac_prompt
  • 0.001 recon_fingerprint

Reporting ( 1.633 seconds )

  • 0.874 ReportPDF
  • 0.749 ReportHTMLSummary
  • 0.01 Malheur
Task ID 47985
Mongo ID 581f1e3a4d3bd03ea99e075d
Cuckoo release 1.4-Maldun