分析任务

分析类型 虚拟机标签 开始时间 结束时间 持续时间
文件 (Windows) win7-sp1-x64-hpdapp01-1 2020-09-25 20:51:40 2020-09-25 20:54:03 143 秒

魔盾分数

10.0

危险的

文件详细信息

文件名 XP.exe
文件大小 203264 字节
文件类型 PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5 9d6754d2d1357d31024affaf81e1eea3
SHA1 f52ad00f106f0d73ce9d0e044d26ec5a163648dd
SHA256 699cbd27ee8aab789823ee073c1d231075c7465f45af7f0c1be5a9905a8b137d
SHA512 3261b5c526eabe537f1b4bb66911870636ae60c7ac498f9e68ea5c28c8441c5f970a75795dd3e8e2914a1b7485b2c0a7171f39afb35db5e0624fabb126949fd2
CRC32 D73F72E7
Ssdeep 6144:ybZWaqUZQtQne3l1D0+TMDWNnzyDVqUrb:cEa1e33HNgq
Yara
  • Detected UPX. Commonly used by RAT!
样本下载 提交误报

登录查看威胁特征

运行截图


访问主机纪录 (可点击查询WPING实时安全评级)

无主机纪录.

域名解析 (可点击查询WPING实时安全评级)

域名 安全评级 响应
acroipm.adobe.com A 23.198.99.176
CNAME acroipm.adobe.com.edgesuite.net
CNAME a1983.dscd.akamai.net
A 23.198.99.183

摘要

C:\Users\test\AppData\Local\Temp
C:\Program Files (x86)
C:\Users\test\AppData\Local\Temp\XP.exe
C:\Program Files (x86)\Systds.pif
C:\Windows\System32\11234557.bak
C:\Windows\Temp
C:\Windows\sysnative\LogFiles\Scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp
C:\Windows\ServiceProfiles
C:\Windows\ServiceProfiles\LocalService
C:\Windows\sysnative\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime
C:\Windows\sysnative\LogFiles\Scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c
C:\Windows\sysnative\Tasks\Microsoft\Windows\WindowsBackup\ConfigNotification
C:\Windows\sysnative\LogFiles\Scm\34583c36-c717-46d6-9414-5c9857a3fb58
C:\Windows\sysnative\LogFiles\Scm\47536d45-eeec-4bdc-8183-a4dc1f8da9e4
C:\Windows\sysnative\Tasks\Microsoft\Windows\Customer Experience Improvement Program\UsbCeip
B:
C:\
D:
E:
F:
G:
H:
I:
J:
K:
L:
M:
N:
O:
P:
Q:
R:
S:
T:
U:
V:
W:
X:
Y:
Z:
[:
C:\Users\test\AppData\Local\Temp\XP.exe
C:\Windows\System32\11234557.bak
C:\Windows\sysnative\LogFiles\Scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec
C:\Windows\sysnative\LogFiles\Scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c
C:\Windows\sysnative\LogFiles\Scm\34583c36-c717-46d6-9414-5c9857a3fb58
C:\Windows\sysnative\LogFiles\Scm\47536d45-eeec-4bdc-8183-a4dc1f8da9e4
C:\Program Files (x86)\Systds.pif
C:\Program Files (x86)\Systds.pif
C:\Windows\System32\11234557.bak
C:\Windows\sysnative\LogFiles\Scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec
C:\Windows\sysnative\LogFiles\Scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Rspkbm zpifhsbt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\InstallTime
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\WOW64
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_USERS\S-1-5-18
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\.DEFAULT\Environment
HKEY_USERS\.DEFAULT\Volatile Environment
HKEY_USERS\.DEFAULT\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\Environment
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Windows
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\NoInteractiveServices
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Time Zones\China Standard Time\Dynamic DST
HKEY_USERS\S-1-5-19
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\S-1-5-19\Environment
HKEY_USERS\S-1-5-19\Volatile Environment
HKEY_USERS\S-1-5-19\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ObjectName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\Remark
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\~MHz
HKEY_CURRENT_USER\Software\Microsoft\ActiveMovie\devenum\{860BB310-5D01-11D0-BD3B-00A0C911CE86}
HKEY_CLASSES_ROOT\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{860BB310-5D01-11D0-BD3B-00A0C911CE86}\Instance
HKEY_CLASSES_ROOT\DirectShow\MediaObjects
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\DirectShow\MediaObjects\Categories\860bb310-5d01-11d0-bd3b-00a0c911ce86
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo2
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo3
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo4
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo5
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo6
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo8
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\WOW64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows\NoInteractiveServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Type
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Start
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ErrorControl
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Tag
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\DependOnGroup
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ObjectName
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\Remark
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\~MHz
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo1
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo2
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo3
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo4
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo5
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo6
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo7
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo8
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32\msvideo9
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\InstallTime
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\Description
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\Group
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Rspkbm zpifhsbt\InstallTime
kernel32.dll.FormatMessageA
kernel32.dll.RtlUnwind
kernel32.dll.RaiseException
kernel32.dll.GetStartupInfoA
kernel32.dll.GetCommandLineA
kernel32.dll.ExitProcess
kernel32.dll.TerminateProcess
kernel32.dll.HeapReAlloc
kernel32.dll.HeapSize
kernel32.dll.GetACP
kernel32.dll.GetTimeZoneInformation
kernel32.dll.SetUnhandledExceptionFilter
kernel32.dll.UnhandledExceptionFilter
kernel32.dll.FreeEnvironmentStringsA
kernel32.dll.FreeEnvironmentStringsW
kernel32.dll.GetEnvironmentStrings
kernel32.dll.GetEnvironmentStringsW
kernel32.dll.GetStdHandle
kernel32.dll.GetFileType
kernel32.dll.GetEnvironmentVariableA
kernel32.dll.GetVersionExA
kernel32.dll.HeapDestroy
kernel32.dll.HeapCreate
kernel32.dll.IsBadWritePtr
kernel32.dll.LCMapStringA
kernel32.dll.LCMapStringW
kernel32.dll.GetStringTypeA
kernel32.dll.GetStringTypeW
kernel32.dll.IsBadReadPtr
kernel32.dll.IsBadCodePtr
kernel32.dll.SetStdHandle
kernel32.dll.CompareStringA
kernel32.dll.CompareStringW
kernel32.dll.SetEnvironmentVariableA
kernel32.dll.GetFileTime
kernel32.dll.GetFileSize
kernel32.dll.GetFileAttributesA
kernel32.dll.GetTickCount
kernel32.dll.FileTimeToLocalFileTime
kernel32.dll.FileTimeToSystemTime
kernel32.dll.GetFullPathNameA
kernel32.dll.GetVolumeInformationA
kernel32.dll.FindFirstFileA
kernel32.dll.FindClose
kernel32.dll.SetEndOfFile
kernel32.dll.UnlockFile
kernel32.dll.LockFile
kernel32.dll.FlushFileBuffers
kernel32.dll.SetFilePointer
kernel32.dll.WriteFile
kernel32.dll.ReadFile
kernel32.dll.CreateFileA
kernel32.dll.GetCurrentProcess
kernel32.dll.DuplicateHandle
kernel32.dll.SetErrorMode
kernel32.dll.GetOEMCP
kernel32.dll.GetCPInfo
kernel32.dll.GetThreadLocale
kernel32.dll.GetProcessVersion
kernel32.dll.GetLastError
kernel32.dll.WritePrivateProfileStringA
kernel32.dll.GlobalFlags
kernel32.dll.lstrcpynA
kernel32.dll.TlsGetValue
kernel32.dll.LocalReAlloc
kernel32.dll.TlsSetValue
kernel32.dll.EnterCriticalSection
kernel32.dll.GlobalReAlloc
kernel32.dll.LeaveCriticalSection
kernel32.dll.TlsFree
kernel32.dll.GlobalHandle
kernel32.dll.DeleteCriticalSection
kernel32.dll.TlsAlloc
kernel32.dll.InitializeCriticalSection
kernel32.dll.LocalFree
kernel32.dll.LocalAlloc
kernel32.dll.MulDiv
kernel32.dll.SetLastError
kernel32.dll.MultiByteToWideChar
kernel32.dll.WideCharToMultiByte
kernel32.dll.lstrlenA
kernel32.dll.InterlockedIncrement
kernel32.dll.GetVersion
kernel32.dll.lstrcatA
kernel32.dll.GlobalGetAtomNameA
kernel32.dll.GlobalAddAtomA
kernel32.dll.GlobalFindAtomA
kernel32.dll.lstrcpyA
kernel32.dll.GetModuleHandleA
kernel32.dll.GlobalUnlock
kernel32.dll.InterlockedDecrement
kernel32.dll.FindResourceA
kernel32.dll.LoadResource
kernel32.dll.LockResource
kernel32.dll.GlobalFree
kernel32.dll.CloseHandle
kernel32.dll.GetModuleFileNameA
kernel32.dll.GlobalLock
kernel32.dll.GlobalAlloc
kernel32.dll.GlobalDeleteAtom
kernel32.dll.lstrcmpA
kernel32.dll.lstrcmpiA
kernel32.dll.GetCurrentThread
kernel32.dll.GetCurrentThreadId
kernel32.dll.FreeLibrary
kernel32.dll.VirtualFree
kernel32.dll.HeapFree
kernel32.dll.VirtualAlloc
kernel32.dll.GetProcessHeap
kernel32.dll.HeapAlloc
kernel32.dll.LoadLibraryA
kernel32.dll.SetHandleCount
kernel32.dll.GetProcAddress
advapi32.dll.RegCloseKey
advapi32.dll.RegSetValueExA
advapi32.dll.RegOpenKeyExA
advapi32.dll.RegCreateKeyExA
comctl32.dll.#17
comdlg32.dll.GetFileTitleA
gdi32.dll.GetWindowExtEx
gdi32.dll.PtVisible
gdi32.dll.RectVisible
gdi32.dll.TextOutA
gdi32.dll.ExtTextOutA
gdi32.dll.Escape
gdi32.dll.GetTextColor
gdi32.dll.GetBkColor
gdi32.dll.DPtoLP
gdi32.dll.LPtoDP
gdi32.dll.GetViewportExtEx
gdi32.dll.GetMapMode
gdi32.dll.GetDeviceCaps
gdi32.dll.DeleteObject
gdi32.dll.CreateBitmap
gdi32.dll.ScaleWindowExtEx
gdi32.dll.SetWindowExtEx
gdi32.dll.ScaleViewportExtEx
gdi32.dll.SetViewportExtEx
gdi32.dll.OffsetViewportOrgEx
gdi32.dll.SetViewportOrgEx
gdi32.dll.SetMapMode
gdi32.dll.GetStockObject
gdi32.dll.SelectObject
gdi32.dll.RestoreDC
gdi32.dll.SaveDC
gdi32.dll.DeleteDC
gdi32.dll.GetObjectA
gdi32.dll.SetBkColor
gdi32.dll.SetTextColor
gdi32.dll.GetClipBox
ole32.dll.CoFreeUnusedLibraries
ole32.dll.OleInitialize
ole32.dll.CoTaskMemAlloc
ole32.dll.CoTaskMemFree
ole32.dll.CreateILockBytesOnHGlobal
ole32.dll.StgCreateDocfileOnILockBytes
ole32.dll.StgOpenStorageOnILockBytes
ole32.dll.CoGetClassObject
ole32.dll.CLSIDFromString
ole32.dll.CLSIDFromProgID
ole32.dll.CoRegisterMessageFilter
ole32.dll.CoRevokeClassObject
ole32.dll.OleIsCurrentClipboard
ole32.dll.OleFlushClipboard
ole32.dll.OleUninitialize
oleaut32.dll.#7
oleaut32.dll.#150
oleaut32.dll.#2
oleaut32.dll.#12
oleaut32.dll.#10
oleaut32.dll.#185
oleaut32.dll.#9
oleaut32.dll.#4
oleaut32.dll.#6
oledlg.dll.#8
olepro32.dll.#253
user32.dll.GetSysColorBrush
user32.dll.CharNextA
user32.dll.CopyAcceleratorTableA
user32.dll.SetRect
user32.dll.GetNextDlgGroupItem
user32.dll.MessageBeep
user32.dll.CharUpperA
user32.dll.RegisterClipboardFormatA
user32.dll.LoadCursorA
user32.dll.GrayStringA
user32.dll.DrawTextA
user32.dll.TabbedTextOutA
user32.dll.EndPaint
user32.dll.BeginPaint
user32.dll.GetWindowDC
user32.dll.ReleaseDC
user32.dll.GetDC
user32.dll.ClientToScreen
user32.dll.DestroyMenu
user32.dll.LoadStringA
user32.dll.ShowWindow
user32.dll.MoveWindow
user32.dll.SetWindowTextA
user32.dll.IsDialogMessageA
user32.dll.UpdateWindow
user32.dll.SendDlgItemMessageA
user32.dll.MapWindowPoints
user32.dll.GetSysColor
user32.dll.SetFocus
user32.dll.AdjustWindowRectEx
user32.dll.CopyRect
user32.dll.GetTopWindow
user32.dll.IsChild
user32.dll.GetCapture
user32.dll.WinHelpA
user32.dll.wsprintfA
user32.dll.GetClassInfoA
user32.dll.GetMenu
user32.dll.GetMenuItemCount
user32.dll.GetSubMenu
user32.dll.GetMenuItemID
user32.dll.GetWindowTextA
user32.dll.GetDlgCtrlID
user32.dll.CreateWindowExA
user32.dll.GetClassLongA
user32.dll.SetPropA
user32.dll.GetPropA
user32.dll.CallWindowProcA
user32.dll.RemovePropA
user32.dll.DefWindowProcA
user32.dll.GetMessageTime
user32.dll.GetMessagePos
user32.dll.GetForegroundWindow
user32.dll.SetForegroundWindow
user32.dll.SetWindowLongA
user32.dll.RegisterWindowMessageA
user32.dll.OffsetRect
user32.dll.SystemParametersInfoA
user32.dll.GetWindowPlacement
user32.dll.GetWindowRect
user32.dll.EndDialog
user32.dll.SetActiveWindow
user32.dll.IsWindow
user32.dll.CreateDialogIndirectParamA
user32.dll.DestroyWindow
user32.dll.GetDlgItem
user32.dll.UnhookWindowsHookEx
user32.dll.MapDialogRect
user32.dll.SetWindowPos
user32.dll.GetWindow
user32.dll.SetWindowContextHelpId
user32.dll.GetMenuCheckMarkDimensions
user32.dll.LoadBitmapA
user32.dll.GetMenuState
user32.dll.ModifyMenuA
user32.dll.SetMenuItemBitmaps
user32.dll.CheckMenuItem
user32.dll.EnableMenuItem
user32.dll.GetFocus
user32.dll.GetNextDlgTabItem
user32.dll.PtInRect
user32.dll.GetClassNameA
user32.dll.GetDesktopWindow
user32.dll.TranslateMessage
user32.dll.DispatchMessageA
user32.dll.GetActiveWindow
user32.dll.GetKeyState
user32.dll.CallNextHookEx
user32.dll.ValidateRect
user32.dll.IsWindowVisible
user32.dll.PeekMessageA
user32.dll.GetCursorPos
user32.dll.SetWindowsHookExA
user32.dll.GetParent
user32.dll.GetLastActivePopup
user32.dll.IsWindowEnabled
user32.dll.GetWindowLongA
user32.dll.MessageBoxA
user32.dll.SetCursor
user32.dll.PostQuitMessage
user32.dll.PostMessageA
user32.dll.EnableWindow
user32.dll.IsIconic
user32.dll.GetSystemMetrics
user32.dll.GetClientRect
user32.dll.DrawIcon
user32.dll.SendMessageA
user32.dll.LoadIconA
user32.dll.PostThreadMessageA
user32.dll.GetInputState
user32.dll.GetMessageA
user32.dll.RegisterClassA
user32.dll.UnregisterClassA
winspool.drv.ClosePrinter
winspool.drv.DocumentPropertiesA
winspool.drv.OpenPrinterA
kernel32.dll.IsProcessorFeaturePresent
msvcrt.dll._adjust_fdiv
msvcrt.dll.malloc
msvcrt.dll._initterm
msvcrt.dll._onexit
msvcrt.dll.__dllonexit
msvcrt.dll.??1type_info@@UAE@XZ
msvcrt.dll.strchr
msvcrt.dll._beginthreadex
msvcrt.dll.??3@YAXPAX@Z
msvcrt.dll.realloc
msvcrt.dll.strcmp
msvcrt.dll._access
msvcrt.dll.strcat
msvcrt.dll.strrchr
msvcrt.dll.strncpy
msvcrt.dll._iob
msvcrt.dll.fprintf
msvcrt.dll.sprintf
msvcrt.dll.printf
msvcrt.dll.strcpy
msvcrt.dll.time
msvcrt.dll.srand
msvcrt.dll.rand
msvcrt.dll.atoi
msvcrt.dll._local_unwind2
msvcrt.dll._except_handler3
msvcrt.dll._strcmpi
msvcrt.dll._strupr
msvcrt.dll._CxxThrowException
msvcrt.dll.memcmp
msvcrt.dll.??2@YAPAXI@Z
msvcrt.dll.strstr
msvcrt.dll.memset
msvcrt.dll.strlen
msvcrt.dll.__CxxFrameHandler
msvcrt.dll._ftol
msvcrt.dll.ceil
msvcrt.dll.memcpy
msvcrt.dll.free
msvcrt.dll._stricmp
mfc42.dll.#6648
mfc42.dll.#2764
mfc42.dll.#4129
mfc42.dll.#926
mfc42.dll.#924
mfc42.dll.#922
mfc42.dll.#858
mfc42.dll.#6663
mfc42.dll.#860
mfc42.dll.#4278
mfc42.dll.#939
mfc42.dll.#6877
mfc42.dll.#537
mfc42.dll.#540
mfc42.dll.#2818
mfc42.dll.#2915
mfc42.dll.#535
mfc42.dll.#800
kernel32.dll.DisableThreadLibraryCalls
kernel32.dll.VirtualProtect
kernel32.dll.GetDriveTypeA
kernel32.dll.GetDiskFreeSpaceExA
kernel32.dll.DefineDosDeviceA
kernel32.dll.MoveFileExA
kernel32.dll.ExpandEnvironmentStringsA
kernel32.dll.CopyFileA
kernel32.dll.SetFileAttributesA
kernel32.dll.CreateDirectoryA
kernel32.dll.GetLocalTime
kernel32.dll.GlobalMemoryStatusEx
kernel32.dll.CreateToolhelp32Snapshot
kernel32.dll.Process32First
kernel32.dll.OpenProcess
kernel32.dll.Process32Next
kernel32.dll.GetCurrentProcessId
kernel32.dll.ExitThread
kernel32.dll.CreateThread
kernel32.dll.CancelIo
kernel32.dll.InterlockedExchange
kernel32.dll.SetEvent
kernel32.dll.Sleep
kernel32.dll.OutputDebugStringA
kernel32.dll.ResetEvent
kernel32.dll.CreateEventA
kernel32.dll.WaitForSingleObject
user32.dll.FindWindowA
advapi32.dll.OpenEventLogA
advapi32.dll.ClearEventLogA
advapi32.dll.CloseEventLog
advapi32.dll.ChangeServiceConfig2A
advapi32.dll.SetServiceStatus
advapi32.dll.RegisterServiceCtrlHandlerA
advapi32.dll.AdjustTokenPrivileges
advapi32.dll.LookupPrivilegeValueA
advapi32.dll.OpenProcessToken
advapi32.dll.StartServiceCtrlDispatcherA
shell32.dll.SHGetSpecialFolderPathA
shell32.dll.ShellExecuteA
shell32.dll.ShellExecuteExA
wininet.dll.InternetOpenUrlA
wininet.dll.InternetGetConnectedState
ws2_32.dll.#116
ws2_32.dll.#9
ws2_32.dll.#23
ws2_32.dll.#16
ws2_32.dll.#18
ws2_32.dll.#3
ws2_32.dll.#19
ws2_32.dll.#21
ws2_32.dll.#11
ws2_32.dll.#20
ws2_32.dll.#12
ws2_32.dll.WSASocketA
ws2_32.dll.#8
ws2_32.dll.#57
ws2_32.dll.#115
ws2_32.dll.WSAIoctl
ws2_32.dll.#111
ws2_32.dll.#52
ws2_32.dll.#4
shlwapi.dll.PathRemoveFileSpecA
kernel32.dll.CreateProcessA
kernel32.dll.CreateMutexA
kernel32.dll.ReleaseMutex
kernel32.dll.TerminateThread
kernel32.dll.GetExitCodeProcess
kernel32.dll.GetSystemInfo
kernel32.dll.GetSystemDirectoryA
kernel32.dll.MoveFileA
kernel32.dll.WTSGetActiveConsoleSessionId
user32.dll.ExitWindowsEx
user32.dll.EnumWindows
ws2_32.dll.WSAStartup
ws2_32.dll.WSACleanup
ws2_32.dll.socket
ws2_32.dll.gethostbyname
ws2_32.dll.htons
ws2_32.dll.connect
ws2_32.dll.send
ws2_32.dll.recv
ws2_32.dll.closesocket
ws2_32.dll.setsockopt
ws2_32.dll.select
ws2_32.dll.getsockname
ws2_32.dll.gethostname
advapi32.dll.OpenSCManagerA
advapi32.dll.OpenServiceA
advapi32.dll.StartServiceA
advapi32.dll.CloseServiceHandle
advapi32.dll.QueryServiceStatus
advapi32.dll.ControlService
advapi32.dll.CreateServiceA
advapi32.dll.DeleteService
advapi32.dll.DuplicateTokenEx
advapi32.dll.SetTokenInformation
advapi32.dll.CreateProcessAsUserA
user32.dll.OpenInputDesktop
user32.dll.OpenDesktopA
user32.dll.CloseDesktop
user32.dll.GetThreadDesktop
user32.dll.GetUserObjectInformationA
user32.dll.SetThreadDesktop
advapi32.dll.RegDeleteKeyA
advapi32.dll.RegDeleteValueA
sspicli.dll.LogonUserExExW
userenv.dll.CreateEnvironmentBlock
sechost.dll.ConvertSidToStringSidW
sspicli.dll.GetUserNameExW
advapi32.dll.RegQueryValueExA
advapi32.dll.RegEnumValueA
advapi32.dll.RegEnumKeyExA
rasapi32.dll.RasConnectionNotificationW
sechost.dll.NotifyServiceStatusChangeA
cryptbase.dll.SystemFunction036
ntdll.dll.RtlGetNtVersionNumbers
kernel32.dll.IsWow64Process
ole32.dll.CoInitialize
ole32.dll.CoUninitialize
ole32.dll.CoCreateInstance
oleaut32.dll.SysFreeString
wintrust.dll.WinVerifyTrust
msdmo.dll.DMOEnum
msdmo.dll.DMOGetTypes
msdmo.dll.DMOGetName
avicap32.dll.capGetDriverDescriptionW
C:\Program Files (x86)\Systds.pif
C:\Windows\system32\sc.exe start w32time task_started
C:\Windows\System32\sdclt.exe /CONFIGNOTIFICATION
taskhost.exe SYSTEM
C:\Program Files (x86)\Systds.pif Win7
103.42.29.55:9090:Rspkbm zpifhsbt
Rspkbm zpifhsbt
Rspkbm zpifhsbt

PE 信息

初始地址 0x00400000
入口地址 0x00488350
声明校验值 0x00000000
实际校验值 0x00037fa5
最低操作系统版本要求 4.0
编译时间 2018-04-10 22:00:35
载入哈希 b22c3df0049f8a255e1f7a57de0600db

版本信息

LegalCopyright
InternalName
FileVersion
CompanyName
LegalTrademarks
ProductName
ProductVersion
FileDescription
OriginalFilename
Debugger
Translation

PEiD 规则

[u'UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser']

PE 数据组成

名称 虚拟地址 虚拟大小 原始数据大小 特征 熵(Entropy)
UPX0 0x00001000 0x0005a000 0x00000000 IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0.00
UPX1 0x0005b000 0x0002e000 0x0002d600 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 7.93
.rsrc 0x00089000 0x00004000 0x00004000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 4.02

资源

名称 偏移量 大小 语言 子语言 熵(Entropy) 文件类型
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_CURSOR 0x0004d8ec 0x00000040 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_BITMAP 0x0004de4c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_BITMAP 0x0004de4c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
RT_BITMAP 0x0004de4c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None

导入

库: KERNEL32.DLL:
0x48cd48 LoadLibraryA
0x48cd4c GetProcAddress
0x48cd50 ExitProcess
库: ADVAPI32.dll:
0x48cd58 RegCloseKey
库: COMCTL32.dll:
0x48cd60 None
库: comdlg32.dll:
0x48cd68 GetFileTitleA
库: GDI32.dll:
0x48cd70 Escape
库: ole32.dll:
0x48cd78 OleInitialize
库: OLEAUT32.dll:
0x48cd80 SysFreeString
库: oledlg.dll:
0x48cd88 None
库: OLEPRO32.DLL:
0x48cd90 None
库: USER32.dll:
0x48cd98 GetDC
库: WINSPOOL.DRV:
0x48cda0 ClosePrinter

.rsrc
+8@<(P
nE{'!@l=B
aDPLAY
5}\vKb\0
?H:mm:ss
k<f>f-
S/f24
i333&
FUjyA
^G/UN
yF_vC
Om:wi5
X&/W$
=x@wly
|p<|uv^
9YV*=!J@
没有防病毒引擎扫描信息!

进程树


XP.exe, PID: 2436, 上一级进程 PID: 2164
services.exe, PID: 428, 上一级进程 PID: 340
Systds.pif, PID: 2744, 上一级进程 PID: 428
Systds.pif, PID: 2836, 上一级进程 PID: 2744

访问主机纪录 (可点击查询WPING实时安全评级)

无主机纪录.

TCP

源地址 源端口 目标地址 目标端口
192.168.122.201 49164 103.42.29.55 9090
192.168.122.201 49158 23.198.99.176 acroipm.adobe.com 80

UDP

源地址 源端口 目标地址 目标端口
192.168.122.201 63282 192.168.122.1 53

域名解析 (可点击查询WPING实时安全评级)

域名 安全评级 响应
acroipm.adobe.com A 23.198.99.176
CNAME acroipm.adobe.com.edgesuite.net
CNAME a1983.dscd.akamai.net
A 23.198.99.183

TCP

源地址 源端口 目标地址 目标端口
192.168.122.201 49164 103.42.29.55 9090
192.168.122.201 49158 23.198.99.176 acroipm.adobe.com 80

UDP

源地址 源端口 目标地址 目标端口
192.168.122.201 63282 192.168.122.1 53

HTTP 请求

URI HTTP数据
URL专业沙箱检测 -> http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip
GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1
Accept: */*
If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT
User-Agent: IPM
Host: acroipm.adobe.com
Connection: Keep-Alive
Cache-Control: no-cache

SMTP 流量

无SMTP流量.

IRC 流量

无IRC请求.

ICMP 流量

无ICMP流量.

CIF 报告

无 CIF 结果

网络警报

无警报

TLS

No TLS

Suricata HTTP

No Suricata HTTP

未发现网络提取文件
抱歉! 没有任何文件投放。
没有发现相似的分析.
HTML 总结报告
(需15-60分钟同步)
下载

Processing ( 24.583 seconds )

  • 17.302 Suricata
  • 2.561 VirusTotal
  • 1.623 BehaviorAnalysis
  • 1.246 Static
  • 0.888 NetworkAnalysis
  • 0.427 peid
  • 0.389 TargetInfo
  • 0.128 AnalysisInfo
  • 0.016 Strings
  • 0.003 Memory

Signatures ( 2.482 seconds )

  • 1.846 md_url_bl
  • 0.098 api_spamming
  • 0.08 stealth_timeout
  • 0.076 stealth_decoy_document
  • 0.024 kovter_behavior
  • 0.024 antiav_detectreg
  • 0.023 md_domain_bl
  • 0.022 antiemu_wine_func
  • 0.02 process_interest
  • 0.02 infostealer_browser_password
  • 0.019 injection_createremotethread
  • 0.017 stealth_file
  • 0.014 antisandbox_sleep
  • 0.013 injection_runpe
  • 0.012 vawtrak_behavior
  • 0.011 infostealer_ftp
  • 0.008 antivm_vbox_libs
  • 0.008 anomaly_persistence_autorun
  • 0.008 process_needed
  • 0.008 antiav_detectfile
  • 0.007 infostealer_im
  • 0.006 geodo_banking_trojan
  • 0.006 infostealer_bitcoin
  • 0.006 ransomware_extensions
  • 0.006 ransomware_files
  • 0.005 antianalysis_detectreg
  • 0.004 mimics_filetime
  • 0.004 reads_self
  • 0.004 exec_crash
  • 0.004 antivm_generic_disk
  • 0.004 virus
  • 0.004 antivm_vbox_files
  • 0.004 infostealer_mail
  • 0.004 network_http
  • 0.003 tinba_behavior
  • 0.003 bootkit
  • 0.003 antivm_generic_scsi
  • 0.003 shifu_behavior
  • 0.003 hancitor_behavior
  • 0.003 disables_browser_warn
  • 0.003 network_torgateway
  • 0.002 rat_nanocore
  • 0.002 antiav_avast_libs
  • 0.002 antivm_vmware_libs
  • 0.002 antisandbox_sunbelt_libs
  • 0.002 antisandbox_sboxie_libs
  • 0.002 antiav_bitdefender_libs
  • 0.002 cerber_behavior
  • 0.002 browser_security
  • 0.002 modify_proxy
  • 0.002 md_bad_drop
  • 0.002 network_cnc_http
  • 0.001 network_tor
  • 0.001 antivm_generic_services
  • 0.001 betabot_behavior
  • 0.001 ursnif_behavior
  • 0.001 kazybot_behavior
  • 0.001 kibex_behavior
  • 0.001 anormaly_invoke_kills
  • 0.001 antianalysis_detectfile
  • 0.001 antidbg_devices
  • 0.001 antivm_generic_diskreg
  • 0.001 antivm_parallels_keys
  • 0.001 antivm_xen_keys
  • 0.001 banker_zeus_mutex
  • 0.001 bot_drive
  • 0.001 bot_drive2
  • 0.001 browser_addon
  • 0.001 disables_system_restore
  • 0.001 disables_windows_defender
  • 0.001 maldun_malicious_drop_executable_file_to_temp_folder
  • 0.001 stealth_modify_uac_prompt

Reporting ( 1.236 seconds )

  • 0.96 ReportHTMLSummary
  • 0.276 Malheur
Task ID 577691
Mongo ID 5f6de8972f8f2e0aba52d0c1
Cuckoo release 1.4-Maldun