分析任务

分析类型 虚拟机标签 开始时间 结束时间 持续时间
文件 (Windows) win7-sp1-x64-hpdapp01-2 2020-02-19 10:46:25 2020-02-19 10:49:24 179 秒

魔盾分数

3.15

可疑的

文件详细信息

文件名 Connect.exe
文件大小 3526656 字节
文件类型 PE32 executable (GUI) Intel 80386, for MS Windows
MD5 08b818c14e0f7613695da7270009ac54
SHA1 1257cffea7183bf66536781328551ac58e49b412
SHA256 e80d09f69dbfcefa5fc784fda8e7a73e2c73d4d554d309eb3dec715715c56a8e
SHA512 329ed5549cef982b928b871190ab324dfeeda93f14262faec6df5d210143153104a4d9534ed23d32d5221994502360574af008dad8af0ee7656080b1c98ea7ab
CRC32 121BCD74
Ssdeep 98304:xtDuSSugoQimxRco/4Tr2B2glIZ2sFLOAkGkzdnEVomFHKnPk:8ZoKxuGdlIZ2sFLOyomFHKnPk
Yara 登录查看Yara规则
样本下载 提交漏报

登录查看威胁特征

运行截图


访问主机纪录 (可点击查询WPING实时安全评级)

无主机纪录.

域名解析 (可点击查询WPING实时安全评级)

无域名信息.


摘要

登录查看详细行为信息

PE 信息

初始地址 0x00400000
入口地址 0x00528c74
声明校验值 0x00000000
实际校验值 0x0035d5ab
最低操作系统版本要求 5.1
PDB路径 D:\\xe7\xa8\x8b\xe5\xba\x8f\xe4\xbb\xa3\xe7\xa0\x81\\xe4\xb8\x80\xe5\x8f\xa5\xe8\xaf\x9d\xe5\x90\x8e\xe9\x97\xa8\Connect\Release\Connect.pdb
编译时间 2016-10-06 18:37:12
载入哈希 4327311590f944b66b3a99f6fbcc405d

版本信息

LegalCopyright
InternalName
FileVersion
CompanyName
ProductName
ProductVersion
FileDescription
OriginalFilename
Translation

PE 数据组成

名称 虚拟地址 虚拟大小 原始数据大小 特征 熵(Entropy)
.text 0x00001000 0x0015183c 0x00151a00 IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 6.54
.rdata 0x00153000 0x0005142e 0x00051600 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4.99
.data 0x001a5000 0x0000de70 0x00006600 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 4.79
.rsrc 0x001b3000 0x00151850 0x00151a00 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 7.61
.reloc 0x00305000 0x00061be8 0x00061c00 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 2.76

导入

库: KERNEL32.dll:
0x5531d4 GetConsoleCP
0x5531d8 GetConsoleMode
0x5531dc ReadConsoleW
0x5531e0 SetFilePointerEx
0x5531e8 GetStringTypeW
0x5531ec OutputDebugStringW
0x5531f0 GetACP
0x5531f4 LCMapStringW
0x5531f8 WriteConsoleW
0x553200 IsValidCodePage
0x553204 GetCPInfo
0x553208 GetOEMCP
0x55320c TerminateProcess
0x553224 GetStartupInfoW
0x553228 GetProcessHeap
0x55322c GetStdHandle
0x55323c HeapSize
0x553240 GetFileType
0x553244 SetStdHandle
0x55324c IsDebuggerPresent
0x553250 ExitThread
0x553254 CreateThread
0x553258 HeapReAlloc
0x55325c RaiseException
0x553260 VirtualQuery
0x553264 VirtualAlloc
0x553268 GetSystemInfo
0x55326c GetModuleHandleExW
0x553270 ExitProcess
0x553274 RtlUnwind
0x553278 HeapAlloc
0x55327c HeapFree
0x553280 GetCommandLineW
0x553284 FindResourceExW
0x55328c SearchPathW
0x553290 GetProfileIntW
0x553294 Sleep
0x553298 VirtualProtect
0x55329c GetTempPathW
0x5532a0 GetTempFileNameW
0x5532a4 GetTickCount
0x5532a8 SetErrorMode
0x5532ac GlobalGetAtomNameW
0x5532b0 VerifyVersionInfoW
0x5532b4 VerSetConditionMask
0x5532b8 GetFileTime
0x5532bc GetFileSizeEx
0x5532c8 lstrcmpiW
0x5532cc GetCurrentProcess
0x5532d0 DuplicateHandle
0x5532d4 WriteFile
0x5532d8 UnlockFile
0x5532dc SetFilePointer
0x5532e0 SetEndOfFile
0x5532e4 ReadFile
0x5532e8 LockFile
0x5532f0 GetFullPathNameW
0x5532f4 GetFileSize
0x5532f8 FlushFileBuffers
0x5532fc FindFirstFileW
0x553300 FindClose
0x553304 CreateFileW
0x553308 DeleteFileW
0x55330c GlobalFlags
0x553318 GetLocaleInfoW
0x55331c CompareStringW
0x553328 LocalReAlloc
0x55332c LocalAlloc
0x553330 GlobalHandle
0x553334 GlobalReAlloc
0x553338 TlsFree
0x55333c TlsSetValue
0x553340 TlsGetValue
0x553344 TlsAlloc
0x553348 GetThreadLocale
0x553350 GlobalFindAtomW
0x553354 GetSystemDirectoryW
0x55335c DecodePointer
0x553360 EncodePointer
0x553364 GlobalAddAtomW
0x553368 ResumeThread
0x55336c SuspendThread
0x553370 SetThreadPriority
0x553374 CreateEventW
0x553378 WaitForSingleObject
0x55337c SetEvent
0x553380 CloseHandle
0x553384 CopyFileW
0x553388 FormatMessageW
0x55338c MulDiv
0x553390 LocalFree
0x553394 GlobalSize
0x5533a4 LoadLibraryW
0x5533a8 LoadLibraryA
0x5533ac GetProcAddress
0x5533b0 GetModuleHandleW
0x5533b4 GetModuleHandleA
0x5533b8 GetVersion
0x5533bc GetLastError
0x5533c0 OutputDebugStringA
0x5533c4 GetFileAttributesW
0x5533c8 lstrcpyW
0x5533cc GlobalFree
0x5533d0 FreeResource
0x5533d4 GetCurrentProcessId
0x5533d8 SetLastError
0x5533dc WideCharToMultiByte
0x5533e0 lstrcmpW
0x5533e4 lstrcmpA
0x5533e8 GlobalDeleteAtom
0x5533ec LoadLibraryExW
0x5533f0 GetModuleFileNameW
0x5533f4 FreeLibrary
0x5533f8 GetVersionExW
0x5533fc GetCurrentThreadId
0x553400 GetCurrentThread
0x553404 InterlockedExchange
0x55340c GlobalUnlock
0x553410 GlobalLock
0x553414 GlobalAlloc
0x553424 MultiByteToWideChar
0x553428 FindResourceW
0x55342c LoadResource
0x553430 LockResource
0x553434 SizeofResource
库: USER32.dll:
0x5534e4 GetKeyboardState
0x5534e8 GetKeyboardLayout
0x5534ec ToUnicodeEx
0x5534f4 ReuseDDElParam
0x5534f8 UnpackDDElParam
0x5534fc InsertMenuItemW
0x553504 LoadAcceleratorsW
0x553508 UnregisterClassW
0x55350c UpdateLayeredWindow
0x553510 GetUpdateRect
0x553514 SetClassLongW
0x55351c ModifyMenuW
0x553520 IsMenu
0x553524 SetMenuDefaultItem
0x553528 GetMenuDefaultItem
0x55352c CopyIcon
0x553530 GetIconInfo
0x553534 GetDoubleClickTime
0x553538 EnableScrollBar
0x55353c LockWindowUpdate
0x553540 CreatePopupMenu
0x553544 BringWindowToTop
0x553548 UnionRect
0x55354c SetCursorPos
0x553550 NotifyWinEvent
0x553554 GetSystemMenu
0x553558 GetAsyncKeyState
0x55355c IsZoomed
0x553560 TrackMouseEvent
0x553564 LoadImageW
0x553568 DestroyIcon
0x55356c MonitorFromPoint
0x553570 SetParent
0x553574 EnumDisplayMonitors
0x553578 SetRectEmpty
0x553580 MessageBeep
0x553584 GetNextDlgGroupItem
0x553588 IntersectRect
0x55358c SetRect
0x553590 InvalidateRgn
0x553598 CharNextW
0x55359c CharUpperW
0x5535a4 DeleteMenu
0x5535a8 CopyImage
0x5535ac LoadCursorW
0x5535b0 WindowFromPoint
0x5535b4 ReleaseCapture
0x5535b8 SetCapture
0x5535c0 GetMenuItemInfoW
0x5535c4 DestroyMenu
0x5535c8 SendDlgItemMessageA
0x5535cc IsDialogMessageW
0x5535d0 SetWindowTextW
0x5535d4 CheckDlgButton
0x5535d8 SetDlgItemTextW
0x5535dc GetDlgItemInt
0x5535e0 MoveWindow
0x5535e4 ShowWindow
0x5535e8 GetMonitorInfoW
0x5535ec MonitorFromWindow
0x5535f0 WinHelpW
0x5535f4 GetScrollInfo
0x5535f8 SetScrollInfo
0x5535fc GetTopWindow
0x553600 GetClassLongW
0x553604 SetWindowLongW
0x553608 AdjustWindowRectEx
0x553610 GetWindowTextW
0x553614 RemovePropW
0x553618 GetPropW
0x55361c SetPropW
0x553620 ShowScrollBar
0x553624 GetScrollRange
0x553628 SetScrollRange
0x55362c GetScrollPos
0x553630 SetScrollPos
0x553634 ScrollWindow
0x553638 SetForegroundWindow
0x55363c GetForegroundWindow
0x553640 TrackPopupMenu
0x553644 SetMenu
0x553648 GetMenu
0x55364c GetCapture
0x553650 SetFocus
0x553654 GetDlgCtrlID
0x553658 EndDeferWindowPos
0x55365c DeferWindowPos
0x553660 BeginDeferWindowPos
0x553664 SetWindowPlacement
0x553668 GetWindowPlacement
0x55366c IsChild
0x553670 CreateWindowExW
0x553674 GetClassInfoExW
0x553678 GetClassInfoW
0x55367c RegisterClassW
0x553680 CallWindowProcW
0x553684 DefWindowProcW
0x553688 GetMessageTime
0x55368c GetMessagePos
0x553690 GetClassNameW
0x553694 InvalidateRect
0x553698 UpdateWindow
0x55369c SetCursor
0x5536a0 ShowOwnedPopups
0x5536a4 ValidateRect
0x5536a8 GetKeyState
0x5536ac TranslateMessage
0x5536b0 GetMessageW
0x5536b4 LoadBitmapW
0x5536b8 SetMenuItemInfoW
0x5536c0 SetMenuItemBitmaps
0x5536c4 EnableMenuItem
0x5536c8 CheckMenuItem
0x5536cc CallNextHookEx
0x5536d0 UnhookWindowsHookEx
0x5536d4 SetWindowsHookExW
0x5536d8 PtInRect
0x5536dc ScreenToClient
0x5536e0 ClientToScreen
0x5536e4 EndPaint
0x5536e8 BeginPaint
0x5536ec GetWindowDC
0x5536f0 TabbedTextOutW
0x5536f4 GrayStringW
0x5536f8 EnableWindow
0x5536fc LoadIconW
0x553700 SendMessageW
0x553704 IsIconic
0x553708 GetSystemMetrics
0x55370c DrawTextExW
0x553710 DrawTextW
0x553714 RemoveMenu
0x553718 AppendMenuW
0x55371c InsertMenuW
0x553720 GetMenuItemCount
0x553724 GetMenuItemID
0x553728 GetMenuState
0x55372c GetMenuStringW
0x553730 CopyRect
0x553734 ReleaseDC
0x553738 GetDC
0x55373c MapVirtualKeyW
0x553740 GetKeyNameTextW
0x553744 GetDesktopWindow
0x553748 GetWindowRgn
0x55374c DestroyCursor
0x553750 CreateMenu
0x553754 InvertRect
0x553758 HideCaret
0x55375c GetComboBoxInfo
0x553760 SubtractRect
0x553764 DefMDIChildProcW
0x553768 DefFrameProcW
0x55376c SetActiveWindow
0x553770 GetActiveWindow
0x553774 DrawMenuBar
0x553778 MapVirtualKeyExW
0x55377c IsCharLowerW
0x553780 CharUpperBuffW
0x553784 PostThreadMessageW
0x55378c FrameRect
0x553790 EqualRect
0x553794 GetClientRect
0x553798 DrawIcon
0x55379c LoadMenuW
0x5537a0 GetSubMenu
0x5537a4 GetCursorPos
0x5537a8 OpenClipboard
0x5537ac EmptyClipboard
0x5537b0 CloseClipboard
0x5537b4 SetClipboardData
0x5537b8 PostMessageW
0x5537bc PostQuitMessage
0x5537c0 DispatchMessageW
0x5537c4 PeekMessageW
0x5537c8 WaitMessage
0x5537cc SetTimer
0x5537d0 KillTimer
0x5537d4 IsWindowEnabled
0x5537d8 MessageBoxW
0x5537dc GetWindowLongW
0x5537e0 GetParent
0x5537e8 GetLastActivePopup
0x5537ec SetWindowPos
0x5537f4 GetWindow
0x5537f8 MapDialogRect
0x553800 DrawEdge
0x553804 DrawFrameControl
0x553808 IsWindowVisible
0x55380c GetFocus
0x553810 DrawStateW
0x553814 SetWindowRgn
0x553818 RedrawWindow
0x55381c GetWindowRect
0x553820 MapWindowPoints
0x553824 GetSysColor
0x553828 GetSysColorBrush
0x55382c DrawFocusRect
0x553830 FillRect
0x553834 InflateRect
0x553838 OffsetRect
0x55383c IsRectEmpty
0x553840 DrawIconEx
0x553844 IsWindow
0x553848 DestroyWindow
0x553850 EndDialog
0x553854 GetDlgItem
0x553858 GetNextDlgTabItem
库: GDI32.dll:
0x553038 GetObjectW
0x55303c MoveToEx
0x553040 TextOutW
0x553044 SetViewportExtEx
0x553048 SetViewportOrgEx
0x55304c SetWindowExtEx
0x553050 SetWindowOrgEx
0x553054 OffsetViewportOrgEx
0x553058 OffsetWindowOrgEx
0x55305c ScaleViewportExtEx
0x553060 ScaleWindowExtEx
0x553064 CreateFontIndirectW
0x553068 GetRgnBox
0x55306c GetMapMode
0x553070 SetRectRgn
0x553074 DPtoLP
0x55307c CreateDIBitmap
0x553080 EnumFontFamiliesW
0x553084 GetTextCharsetInfo
0x553088 RealizePalette
0x55308c SetPixel
0x553090 StretchBlt
0x553094 CreateDIBSection
0x553098 SetDIBColorTable
0x55309c CreateRoundRectRgn
0x5530a0 Rectangle
0x5530a4 OffsetRgn
0x5530a8 RoundRect
0x5530ac GetPaletteEntries
0x5530b8 EnumFontFamiliesExW
0x5530bc ExtFloodFill
0x5530c0 SetPaletteEntries
0x5530c4 FillRgn
0x5530c8 FrameRgn
0x5530cc GetBoundsRect
0x5530d0 PtInRegion
0x5530d4 GetViewportOrgEx
0x5530d8 LPtoDP
0x5530dc GetWindowOrgEx
0x5530e0 SetPixelV
0x5530e4 GetTextFaceW
0x5530e8 SetBkMode
0x5530ec SetBkColor
0x5530f0 SetTextAlign
0x5530f4 SetTextColor
0x5530f8 SetROP2
0x5530fc SetPolyFillMode
0x553100 GetLayout
0x553104 SetLayout
0x553108 SetMapMode
0x55310c CreatePalette
0x553110 CombineRgn
0x553114 SelectPalette
0x553118 SelectObject
0x55311c ExtSelectClipRgn
0x553120 SelectClipRgn
0x553124 SaveDC
0x553128 RestoreDC
0x55312c RectVisible
0x553130 PtVisible
0x553134 LineTo
0x553138 IntersectClipRect
0x55313c GetWindowExtEx
0x553140 GetViewportExtEx
0x553144 GetStockObject
0x553148 GetPixel
0x55314c GetObjectType
0x553150 GetClipBox
0x553154 ExcludeClipRect
0x553158 Escape
0x55315c DeleteObject
0x553160 DeleteDC
0x553164 CreatePatternBrush
0x553168 CreatePen
0x55316c CreateCompatibleDC
0x553170 CreateBitmap
0x553174 BitBlt
0x553178 GetDeviceCaps
0x55317c CreateDCW
0x553180 CopyMetaFileW
0x553184 GetTextMetricsW
0x553188 Polyline
0x55318c Polygon
0x553190 CreatePolygonRgn
0x553194 ExtTextOutW
0x553198 PatBlt
0x5531a0 GetTextColor
0x5531a4 GetBkColor
0x5531a8 Ellipse
0x5531ac CreateSolidBrush
0x5531b4 CreateRectRgn
0x5531b8 CreateHatchBrush
0x5531bc CreateEllipticRgn
库: MSIMG32.dll:
0x553440 TransparentBlt
0x553444 AlphaBlend
库: WINSPOOL.DRV:
0x5538a0 DocumentPropertiesW
0x5538a4 OpenPrinterW
0x5538a8 ClosePrinter
库: ADVAPI32.dll:
0x553000 RegEnumKeyExW
0x553004 RegEnumValueW
0x553008 RegQueryValueW
0x55300c RegEnumKeyW
0x553010 RegCloseKey
0x553014 RegSetValueExW
0x553018 RegDeleteValueW
0x55301c RegDeleteKeyW
0x553020 RegCreateKeyExW
0x553024 RegQueryValueExW
0x553028 RegOpenKeyExW
库: SHELL32.dll:
0x553498 DragFinish
0x5534a4 SHBrowseForFolderW
0x5534a8 SHGetDesktopFolder
0x5534ac SHGetFileInfoW
0x5534b0 ShellExecuteW
0x5534b4 SHGetMalloc
0x5534b8 DragQueryFileW
0x5534bc SHAppBarMessage
库: COMCTL32.dll:
库: SHLWAPI.dll:
0x5534c4 PathFindFileNameW
0x5534c8 PathIsUNCW
0x5534cc PathStripToRootW
0x5534d0 StrFormatKBSizeW
0x5534d4 PathRemoveFileSpecW
0x5534d8 PathFindExtensionW
库: UxTheme.dll:
0x553864 GetWindowTheme
0x553868 GetThemeSysColor
0x553870 GetThemePartSize
0x553874 OpenThemeData
0x553878 CloseThemeData
0x55387c DrawThemeBackground
0x553880 GetThemeColor
0x553884 GetCurrentThemeName
0x553888 IsAppThemed
0x55388c DrawThemeText
库: ole32.dll:
0x553930 CLSIDFromProgID
0x553934 CLSIDFromString
0x553938 CoCreateGuid
0x55393c CoCreateInstance
0x553940 CoUninitialize
0x553944 CoInitialize
0x553948 IsAccelerator
0x553954 CoTaskMemAlloc
0x553958 CoTaskMemFree
0x55395c OleFlushClipboard
0x553960 OleDuplicateData
0x553964 ReleaseStgMedium
0x553968 CoInitializeEx
0x55396c CoGetClassObject
0x553984 OleInitialize
0x553988 OleUninitialize
0x553990 DoDragDrop
0x553994 OleGetClipboard
0x5539a4 CoRevokeClassObject
0x5539a8 OleLockRunning
0x5539ac RevokeDragDrop
0x5539b0 OleRun
0x5539b4 RegisterDragDrop
库: OLEAUT32.dll:
0x55345c SysAllocString
0x553460 SysAllocStringLen
0x553464 VariantChangeType
0x553468 SysStringLen
0x553474 SafeArrayDestroy
0x553478 VariantClear
0x553480 VariantCopy
0x553484 VariantInit
0x553488 SysFreeString
0x55348c GetErrorInfo
0x553490 VarBstrFromDate
库: oledlg.dll:
0x5539bc OleUIBusyW
库: gdiplus.dll:
0x5538d4 GdipCloneImage
0x5538d8 GdipDrawImageRectI
0x5538e0 GdipCreateFromHDC
0x5538e8 GdipDrawImageI
0x5538ec GdipDeleteGraphics
0x5538f4 GdipBitmapLockBits
0x553904 GdipGetImagePalette
0x55390c GdipGetImageHeight
0x553910 GdipGetImageWidth
0x553918 GdipDisposeImage
0x55391c GdiplusShutdown
0x553920 GdiplusStartup
0x553924 GdipFree
0x553928 GdipAlloc
库: WS2_32.dll:
0x5538b0 WSASetLastError
0x5538b4 WSACleanup
0x5538b8 WSAStartup
0x5538bc closesocket
0x5538c0 sendto
0x5538c4 inet_addr
0x5538c8 htons
0x5538cc socket
库: OLEACC.dll:
0x553454 LresultFromObject
库: IMM32.dll:
0x5531c4 ImmGetContext
0x5531c8 ImmGetOpenStatus
0x5531cc ImmReleaseContext
库: WINMM.dll:
0x553898 PlaySoundW

.text
`.rdata
@.data
.rsrc
@.reloc
D$0hxiX
PhXiX
RhDYX
Vh0'@
PPh8iX
Ph0iX
Ph0iX
t3h<=U
Gh0[U
thPJU
[hdJU
VhxJU
tchtqZ
@ h(IU
@ h<IU
@ hPIU
@ h`IU
@ htIU
WhtqZ
WhtqZ
Qh<NU
tAh$NU
PhXNU
@ Sh1+A
1h0[U
PhtqZ
Ph xZ
wahnJA
#hnJA
tDhxeU
VWhnJA
u8h(mU
8h@mU
ShTlU
ShhlU
VhnJA
RhpfU
VhnJA
0hnJA
uIhnJA
Sh<fU
urh<fU
@DdeI
Ph,lX
防病毒引擎/厂商 病毒名/规则匹配 病毒库日期
Bkav 未发现病毒 20190930
MicroWorld-eScan 未发现病毒 20190930
CMC 未发现病毒 20190321
CAT-QuickHeal 未发现病毒 20190930
McAfee 未发现病毒 20190930
Malwarebytes 未发现病毒 20190930
Zillya 未发现病毒 20190930
AegisLab 未发现病毒 20190930
K7AntiVirus 未发现病毒 20190930
Alibaba 未发现病毒 20190527
K7GW 未发现病毒 20190930
Cybereason 未发现病毒 20190616
TrendMicro 未发现病毒 20190930
Baidu 未发现病毒 20190318
Cyren 未发现病毒 20190930
Symantec 未发现病毒 20190930
TotalDefense 未发现病毒 20190930
APEX 未发现病毒 20190928
Paloalto 未发现病毒 20190930
ClamAV 未发现病毒 20190930
GData 未发现病毒 20190930
Kaspersky 未发现病毒 20190930
BitDefender 未发现病毒 20190930
NANO-Antivirus 未发现病毒 20190930
ViRobot 未发现病毒 20190930
Rising 未发现病毒 20190930
Endgame 未发现病毒 20190918
Sophos 未发现病毒 20190930
Comodo 未发现病毒 20190930
F-Secure 未发现病毒 20190930
DrWeb 未发现病毒 20190930
VIPRE 未发现病毒 20190928
Invincea 未发现病毒 20190904
McAfee-GW-Edition 未发现病毒 20190930
Trapmine 未发现病毒 20190826
FireEye 未发现病毒 20190930
Emsisoft 未发现病毒 20190930
SentinelOne 未发现病毒 20190807
F-Prot 未发现病毒 20190930
Jiangmin 未发现病毒 20190930
Webroot 未发现病毒 20190930
Avira 未发现病毒 20190930
Antiy-AVL 未发现病毒 20190926
Kingsoft 未发现病毒 20190930
Arcabit 未发现病毒 20190930
SUPERAntiSpyware 未发现病毒 20190927
ZoneAlarm 未发现病毒 20190930
Avast-Mobile 未发现病毒 20190930
Microsoft 未发现病毒 20190930
AhnLab-V3 未发现病毒 20190930
Acronis 未发现病毒 20190930
ALYac 未发现病毒 20190930
TACHYON 未发现病毒 20190930
VBA32 未发现病毒 20190930
Panda 未发现病毒 20190930
Zoner 未发现病毒 20190930
ESET-NOD32 未发现病毒 20190930
TrendMicro-HouseCall 未发现病毒 20190930
Tencent 未发现病毒 20190930
Yandex 未发现病毒 20190930
MAX 未发现病毒 20190930
eGambit 未发现病毒 20190930
Fortinet 未发现病毒 20190930
Ad-Aware 未发现病毒 20190930
AVG 未发现病毒 20190930
Avast 未发现病毒 20190930
CrowdStrike 未发现病毒 20190702
Qihoo-360 未发现病毒 20190930

进程树


Connect.exe, PID: 2736, 上一级进程 PID: 2320

访问主机纪录 (可点击查询WPING实时安全评级)

无主机纪录.

TCP

无TCP连接纪录.

UDP

无UDP连接纪录.

域名解析 (可点击查询WPING实时安全评级)

无域名信息.

TCP

无TCP连接纪录.

UDP

无UDP连接纪录.

HTTP 请求

未发现HTTP请求.

SMTP 流量

无SMTP流量.

IRC 流量

无IRC请求.

ICMP 流量

无ICMP流量.

CIF 报告

无 CIF 结果

网络警报

无警报

TLS

No TLS

Suricata HTTP

No Suricata HTTP

未发现网络提取文件
抱歉! 没有任何文件投放。
没有发现相似的分析.
HTML 总结报告
(需15-60分钟同步)
下载

Processing ( 39.434 seconds )

  • 18.467 Static
  • 16.435 Suricata
  • 2.069 VirusTotal
  • 1.183 TargetInfo
  • 0.621 peid
  • 0.36 NetworkAnalysis
  • 0.139 BehaviorAnalysis
  • 0.128 AnalysisInfo
  • 0.015 Strings
  • 0.014 config_decoder
  • 0.003 Memory

Signatures ( 0.213 seconds )

  • 0.033 antiav_detectreg
  • 0.022 md_url_bl
  • 0.018 md_domain_bl
  • 0.013 infostealer_ftp
  • 0.008 antiav_detectfile
  • 0.008 infostealer_im
  • 0.008 ransomware_files
  • 0.007 anomaly_persistence_autorun
  • 0.007 antianalysis_detectreg
  • 0.007 ransomware_extensions
  • 0.006 api_spamming
  • 0.005 stealth_timeout
  • 0.005 infostealer_bitcoin
  • 0.005 infostealer_mail
  • 0.004 stealth_decoy_document
  • 0.003 tinba_behavior
  • 0.003 antivm_vbox_files
  • 0.003 geodo_banking_trojan
  • 0.003 disables_browser_warn
  • 0.002 rat_nanocore
  • 0.002 betabot_behavior
  • 0.002 kibex_behavior
  • 0.002 cerber_behavior
  • 0.002 antivm_parallels_keys
  • 0.002 browser_security
  • 0.002 modify_proxy
  • 0.002 md_bad_drop
  • 0.001 antiemu_wine_func
  • 0.001 network_tor
  • 0.001 antivm_generic_services
  • 0.001 ursnif_behavior
  • 0.001 antivm_generic_scsi
  • 0.001 shifu_behavior
  • 0.001 infostealer_browser_password
  • 0.001 antidbg_windows
  • 0.001 kovter_behavior
  • 0.001 antianalysis_detectfile
  • 0.001 antidbg_devices
  • 0.001 antivm_generic_diskreg
  • 0.001 antivm_xen_keys
  • 0.001 banker_zeus_mutex
  • 0.001 bot_drive
  • 0.001 bot_drive2
  • 0.001 browser_addon
  • 0.001 disables_system_restore
  • 0.001 disables_windows_defender
  • 0.001 darkcomet_regkeys
  • 0.001 maldun_malicious_drop_executable_file_to_temp_folder
  • 0.001 office_security
  • 0.001 rat_pcclient
  • 0.001 rat_spynet
  • 0.001 recon_fingerprint
  • 0.001 stealth_hiddenreg
  • 0.001 stealth_hide_notifications
  • 0.001 stealth_modify_uac_prompt
  • 0.001 stealth_modify_security_center_warnings

Reporting ( 1.134 seconds )

  • 0.815 ReportHTMLSummary
  • 0.319 Malheur
Task ID 513122
Mongo ID 5e4ca2672f8f2e0df86c6fe4
Cuckoo release 1.4-Maldun