分析任务

分析类型 虚拟机标签 开始时间 结束时间 持续时间
文件 (Windows) win7-sp1-x64-hpdapp01-2 2020-02-19 09:10:41 2020-02-19 09:13:05 144 秒

魔盾分数

10.0

Malicious病毒

文件详细信息

文件名 Inquiry.exe
文件大小 118784 字节
文件类型 PE32 executable (GUI) Intel 80386, for MS Windows
MD5 72a572262f8ecaf6ae4d1c7e45ef732a
SHA1 c5476ba693a0205a0e680b1e8fc535ed63311c46
SHA256 64e0eacf28f646f2bc2357a34f3c8d7c2ad1f0145d50cda93b169d1bf4c0f4db
SHA512 db36bddcfe0945d1a14157b4bc82df964d13e55f0155bae8fd13b57d37ef63f0617c147e4102d4875ab25721590345087394caeb1e1d713a9bf33b9a5cdd8186
CRC32 EAD24A2A
Ssdeep 1536:g9/4wX3L1szl8SIMRA6W+TzGQFKszl8SIM2f3Nb4/G:4VnaufGAtQFbufBNO
Yara 登录查看Yara规则
样本下载 提交误报

登录查看威胁特征

运行截图


访问主机纪录 (可点击查询WPING实时安全评级)

无主机纪录.

域名解析 (可点击查询WPING实时安全评级)

无域名信息.


摘要

登录查看详细行为信息

PE 信息

初始地址 0x00400000
入口地址 0x00401214
声明校验值 0x0002bd2d
实际校验值 0x0002bd2d
最低操作系统版本要求 4.0
编译时间 2014-05-01 20:12:16
载入哈希 fb29227a0492c8f9b86e5f46ba6a6132

版本信息

Translation
InternalName
FileVersion
CompanyName
LegalTrademarks
Comments
ProductName
ProductVersion
OriginalFilename

PE 数据组成

名称 虚拟地址 虚拟大小 原始数据大小 特征 熵(Entropy)
.text 0x00001000 0x0000da2c 0x0000e000 IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 6.08
.data 0x0000f000 0x000009f0 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0.00
.rsrc 0x00010000 0x0000c7e0 0x0000d000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 6.00

导入

库: MSVBVM60.DLL:
0x401000 _CIcos
0x401004 _adj_fptan
0x401008 __vbaFreeVar
0x40100c None
0x401010 __vbaFreeVarList
0x401014 _adj_fdiv_m64
0x401018 _adj_fprem1
0x40101c __vbaStrCat
0x401024 _adj_fdiv_m32
0x401028 __vbaObjSet
0x40102c _adj_fdiv_m16i
0x401030 __vbaObjSetAddref
0x401034 _adj_fdivr_m16i
0x401038 __vbaFpR8
0x40103c _CIsin
0x401040 None
0x401044 __vbaChkstk
0x401048 EVENT_SINK_AddRef
0x40104c __vbaStrCmp
0x401050 _adj_fpatan
0x401054 EVENT_SINK_Release
0x401058 _CIsqrt
0x401060 __vbaExceptHandler
0x401064 _adj_fprem
0x401068 _adj_fdivr_m64
0x40106c __vbaFPException
0x401070 _CIlog
0x401074 None
0x401078 __vbaNew2
0x40107c _adj_fdiv_m32i
0x401080 _adj_fdivr_m32i
0x401084 __vbaFreeStrList
0x401088 _adj_fdivr_m32
0x40108c _adj_fdiv_r
0x401090 None
0x401094 None
0x401098 __vbaInStrB
0x40109c _CIatan
0x4010a0 __vbaStrMove
0x4010a4 _allmul
0x4010a8 _CItan
0x4010ac _CIexp
0x4010b0 __vbaFreeStr
0x4010b4 __vbaFreeObj

.text
`.data
.rsrc
MSVBVM60.DLL
KRUEGER
Dollbeer5
augurers
WO.****-OW
M4-3P7.-5iB
augurers
Form_T
VB5!6&*
Khedaet7
Skopuds
KRUEGER
KRUEGER
Dollbeer5
Form_T
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
testabl
VBA6.DLL
__vbaFreeStrList
__vbaStrCat
__vbaInStrB
__vbaFpR8
__vbaObjSetAddref
__vbaNew2
__vbaFreeVarList
__vbaFreeObj
__vbaHresultCheckObj
__vbaObjSet
__vbaFreeVar
__vbaFreeStr
__vbaStrMove
__vbaStrCmp
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaFreeVar
__vbaFreeVarList
_adj_fdiv_m64
_adj_fprem1
__vbaStrCat
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaObjSet
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaFpR8
_CIsin
__vbaChkstk
EVENT_SINK_AddRef
__vbaStrCmp
_adj_fpatan
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
_CIlog
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaInStrB
_CIatan
__vbaStrMove
_allmul
_CItan
_CIexp
__vbaFreeStr
__vbaFreeObj
:bSB
:bSB
:bSB
:bSB
:bSB
:bSB
:bSB
:bSB
:bSB
:bSB
:bSB
:bSB
:bSB
:bSB
:bSB
:bSB
:bSB
M4-3P7.-5iB
WO.****-OW
qiYWdkX5SoPtWIwC0lrHvJOiSrtaOb222
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
Comments
STRIFEPRO
CompanyName
Fummme9
LegalTrademarks
Goorals
ProductName
Svinemr3
FileVersion
ProductVersion
InternalName
Khedaet7
OriginalFilename
Khedaet7.exe
防病毒引擎/厂商 病毒名/规则匹配 病毒库日期
Bkav 未发现病毒 20200122
MicroWorld-eScan Trojan.GenericKD.32985215 20200125
FireEye Trojan.GenericKD.32985215 20200125
CAT-QuickHeal 未发现病毒 20200124
ALYac 未发现病毒 20200125
Cylance 未发现病毒 20200125
Zillya 未发现病毒 20200123
SUPERAntiSpyware 未发现病毒 20200125
Sangfor Malware 20200114
K7AntiVirus 未发现病毒 20200125
Alibaba 未发现病毒 20190527
K7GW Trojan ( 0055f5a41 ) 20200125
CrowdStrike win/malicious_confidence_60% (W) 20190702
Arcabit Trojan.Generic.D1F7507F 20200125
Invincea 未发现病毒 20191211
BitDefenderTheta Gen:NN.ZevbaF.34084.hm0@aOJMgygi 20200120
F-Prot 未发现病毒 20200125
TotalDefense 未发现病毒 20200123
Baidu 未发现病毒 20190318
APEX Malicious 20200125
Paloalto generic.ml 20200125
ClamAV 未发现病毒 20200124
GData Trojan.GenericKD.32985215 20200125
Kaspersky Trojan.Win32.Vebzenpak.wo 20200125
BitDefender Trojan.GenericKD.32985215 20200125
NANO-Antivirus 未发现病毒 20200125
ViRobot 未发现病毒 20200124
Avast Win32:Trojan-gen 20200125
Rising Trojan.Injector!8.C4 (CLOUD) 20200125
Ad-Aware Trojan.GenericKD.32985215 20200125
Emsisoft Trojan.GenericKD.32985215 (B) 20200125
Comodo 未发现病毒 20200125
F-Secure 未发现病毒 20200125
DrWeb 未发现病毒 20200125
VIPRE 未发现病毒 20200125
TrendMicro 未发现病毒 20200125
McAfee-GW-Edition BehavesLike.Win32.Trojan.cm 20200124
Trapmine malicious.high.ml.score 20200123
CMC 未发现病毒 20190321
Sophos Mal/Generic-S 20200125
Ikarus Win32.SuspectCrc 20200124
Cyren W32/Trojan.YMKW-8187 20200125
Jiangmin 未发现病毒 20200125
Webroot 未发现病毒 20200125
Avira 未发现病毒 20200125
Antiy-AVL 未发现病毒 20200125
Kingsoft 未发现病毒 20200125
Microsoft Trojan:Win32/Wacatac.C!ml 20200125
Endgame 未发现病毒 20190918
AegisLab 未发现病毒 20200125
ZoneAlarm Trojan.Win32.Vebzenpak.wo 20200125
Avast-Mobile 未发现病毒 20200124
TACHYON 未发现病毒 20200125
AhnLab-V3 Trojan/Win32.VBKrypt.R319273 20200124
Acronis 未发现病毒 20200123
McAfee RDN/Generic.dx 20200125
MAX malware (ai score=89) 20200125
VBA32 未发现病毒 20200124
Malwarebytes Trojan.MalPack.VB 20200125
Zoner 未发现病毒 20200125
ESET-NOD32 a variant of Win32/Injector.EKED 20200125
TrendMicro-HouseCall TROJ_GEN.F0D1C00AO20 20200125
Tencent 未发现病毒 20200125
Yandex 未发现病毒 20200124
SentinelOne 未发现病毒 20191218
eGambit Unsafe.AI_Score_100% 20200125
Fortinet 未发现病毒 20200122
AVG Win32:Trojan-gen 20200125
Cybereason 未发现病毒 20190616
Panda 未发现病毒 20200124
Qihoo-360 Win32/Trojan.20e 20200125

进程树


Inquiry.exe, PID: 2728, 上一级进程 PID: 2324

访问主机纪录 (可点击查询WPING实时安全评级)

无主机纪录.

TCP

无TCP连接纪录.

UDP

无UDP连接纪录.

域名解析 (可点击查询WPING实时安全评级)

无域名信息.

TCP

无TCP连接纪录.

UDP

无UDP连接纪录.

HTTP 请求

未发现HTTP请求.

SMTP 流量

无SMTP流量.

IRC 流量

无IRC请求.

ICMP 流量

无ICMP流量.

CIF 报告

无 CIF 结果

网络警报

无警报

TLS

No TLS

Suricata HTTP

No Suricata HTTP

未发现网络提取文件
抱歉! 没有任何文件投放。
没有发现相似的分析.
HTML 总结报告
(需15-60分钟同步)
下载

Processing ( 21.992 seconds )

  • 15.477 Suricata
  • 3.14 BehaviorAnalysis
  • 1.268 VirusTotal
  • 0.906 Static
  • 0.43 peid
  • 0.356 TargetInfo
  • 0.346 NetworkAnalysis
  • 0.053 AnalysisInfo
  • 0.013 Strings
  • 0.003 Memory

Signatures ( 1.563 seconds )

  • 0.192 api_spamming
  • 0.152 stealth_timeout
  • 0.135 injection_createremotethread
  • 0.135 injection_runpe
  • 0.133 stealth_decoy_document
  • 0.063 mimics_filetime
  • 0.062 hancitor_behavior
  • 0.059 reads_self
  • 0.055 virus
  • 0.051 stealth_file
  • 0.049 antivm_generic_disk
  • 0.043 bootkit
  • 0.034 stealth_hidden_window
  • 0.031 debugs_self
  • 0.03 maldun_anomaly_write_exe_and_dll_under_winroot_run
  • 0.029 bcdedit_command
  • 0.026 maldun_anomaly_heavy_create_suspended
  • 0.026 upatre_behavior
  • 0.024 powershell_command
  • 0.024 dead_link
  • 0.023 stealth_childproc
  • 0.023 deletes_shadow_copies
  • 0.022 antiav_detectreg
  • 0.014 injection_needextension
  • 0.013 md_url_bl
  • 0.011 md_domain_bl
  • 0.01 infostealer_ftp
  • 0.007 anomaly_persistence_autorun
  • 0.007 antiav_detectfile
  • 0.006 infostealer_im
  • 0.006 ransomware_files
  • 0.005 antianalysis_detectreg
  • 0.005 infostealer_bitcoin
  • 0.005 ransomware_extensions
  • 0.004 infostealer_mail
  • 0.003 tinba_behavior
  • 0.003 antivm_vbox_files
  • 0.003 geodo_banking_trojan
  • 0.003 disables_browser_warn
  • 0.002 antiemu_wine_func
  • 0.002 rat_nanocore
  • 0.002 betabot_behavior
  • 0.002 infostealer_browser_password
  • 0.002 cerber_behavior
  • 0.002 kovter_behavior
  • 0.002 bot_drive
  • 0.002 browser_security
  • 0.002 modify_proxy
  • 0.001 hawkeye_behavior
  • 0.001 antivm_vbox_libs
  • 0.001 ursnif_behavior
  • 0.001 kibex_behavior
  • 0.001 shifu_behavior
  • 0.001 exec_crash
  • 0.001 antidbg_windows
  • 0.001 antianalysis_detectfile
  • 0.001 antidbg_devices
  • 0.001 antivm_parallels_keys
  • 0.001 antivm_xen_keys
  • 0.001 banker_zeus_mutex
  • 0.001 bot_drive2
  • 0.001 browser_addon
  • 0.001 disables_system_restore
  • 0.001 disables_windows_defender
  • 0.001 maldun_malicious_drop_executable_file_to_temp_folder
  • 0.001 md_bad_drop
  • 0.001 stealth_modify_uac_prompt

Reporting ( 1.341 seconds )

  • 0.888 ReportHTMLSummary
  • 0.453 Malheur
Task ID 513080
Mongo ID 5e4c8bce2f8f2e0df16c6b18
Cuckoo release 1.4-Maldun