分析任务

分析类型 虚拟机标签 开始时间 结束时间 持续时间
文件 (Windows) win7-sp1-x64-shaapp02-1 2020-09-28 23:25:45 2020-09-28 23:25:46 1 秒

魔盾分数

1.75

正常的

文件详细信息

文件名 N_m3u8DL-CLI.exe
文件大小 923136 字节
文件类型 PE32 executable (console) Intel 80386, for MS Windows
MD5 53badba61b86d9864257be4cf955d800
SHA1 c761701de1c93b7f059eaf89d3c5208ab8ffda43
SHA256 5b69c8c67cbcee5821358237f3c22ac1c48c6e3cad1933993e5aa4a0496e9380
SHA512 0225343d6a8ebab1448edd4533f66d27f59e93c599881b87fe6c7dc95a0dca8bccf89a70133b5f042fb41fe86da19b547b332a7f8ff56643f5ef757c5fb7b133
CRC32 EF01E421
Ssdeep 24576:16+EmuyeO/RaKGjV2p7JJvFDKyxfWmA5nAUkTtiqF:16+EZLjjVwvFDhL
Yara 登录查看Yara规则
样本下载 提交漏报

登录查看威胁特征

运行截图

没有可用的屏幕截图

访问主机纪录 (可点击查询WPING实时安全评级)

无主机纪录.

域名解析 (可点击查询WPING实时安全评级)

无域名信息.


摘要

登录查看详细行为信息

PE 信息

初始地址 0x00400000
入口地址 0x0042238e
声明校验值 0x00000000
实际校验值 0x000e729b
最低操作系统版本要求 4.0
编译时间 2020-09-20 13:32:41
载入哈希 ae4ae436602a0fced8410c4c48e4ae05

版本信息

Translation
LegalCopyright
Assembly Version
InternalName
FileVersion
CompanyName
LegalTrademarks
Comments
ProductName
ProductVersion
FileDescription
OriginalFilename

PE 数据组成

名称 虚拟地址 虚拟大小 原始数据大小 特征 熵(Entropy)
.text 0x00002000 0x00020394 0x00020400 IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 5.21
.rsrc 0x00024000 0x00006ad8 0x00006c00 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5.92
.reloc 0x0002c000 0x0000000c 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 0.10
.enigma1 0x0002e000 0x00002000 0x00076000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 7.91
.enigma2 0x00030000 0x00044000 0x00044000 IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 5.94

导入

库: kernel32.dll:
0x46818c VirtualFree
0x468190 VirtualAlloc
0x468194 LocalFree
0x468198 LocalAlloc
0x46819c GetTickCount
0x4681a4 GetVersion
0x4681a8 GetCurrentThreadId
0x4681b4 VirtualQuery
0x4681b8 WideCharToMultiByte
0x4681bc MultiByteToWideChar
0x4681c0 lstrlenA
0x4681c4 lstrcpynA
0x4681c8 LoadLibraryExA
0x4681cc GetThreadLocale
0x4681d0 GetStartupInfoA
0x4681d4 GetProcAddress
0x4681d8 GetModuleHandleA
0x4681dc GetModuleFileNameA
0x4681e0 GetLocaleInfoA
0x4681e4 GetCommandLineA
0x4681e8 FreeLibrary
0x4681ec FindFirstFileA
0x4681f0 FindClose
0x4681f4 ExitProcess
0x4681f8 ExitThread
0x4681fc WriteFile
0x468204 RtlUnwind
0x468208 RaiseException
0x46820c GetStdHandle
库: user32.dll:
0x468214 GetKeyboardType
0x468218 LoadStringA
0x46821c MessageBoxA
0x468220 CharNextA
库: advapi32.dll:
0x468228 RegQueryValueExA
0x46822c RegOpenKeyExA
0x468230 RegCloseKey
库: oleaut32.dll:
0x468238 SysFreeString
0x46823c SysReAllocStringLen
0x468240 SysAllocStringLen
库: kernel32.dll:
0x468248 TlsSetValue
0x46824c TlsGetValue
0x468250 TlsFree
0x468254 TlsAlloc
0x468258 LocalFree
0x46825c LocalAlloc
库: advapi32.dll:
0x468264 RegOpenKeyA
库: kernel32.dll:
0x46826c WriteProcessMemory
0x468270 WriteFile
0x468274 WideCharToMultiByte
0x468278 WaitForSingleObject
0x46827c VirtualQuery
0x468280 VirtualProtectEx
0x468284 VirtualProtect
0x468288 VirtualFree
0x46828c VirtualAllocEx
0x468290 VirtualAlloc
0x468298 SizeofResource
0x46829c SetThreadContext
0x4682a0 SetLastError
0x4682a4 SetFileTime
0x4682a8 SetFilePointer
0x4682ac SetFileAttributesW
0x4682b0 SetFileAttributesA
0x4682b4 SetEvent
0x4682b8 SetErrorMode
0x4682bc SetEndOfFile
0x4682c8 ResetEvent
0x4682cc RemoveDirectoryW
0x4682d0 RemoveDirectoryA
0x4682d4 ReadProcessMemory
0x4682d8 ReadFile
0x4682dc QueryDosDeviceW
0x4682e4 MultiByteToWideChar
0x4682e8 LockResource
0x4682ec LoadResource
0x4682f0 LoadLibraryW
0x4682f4 LoadLibraryA
0x4682fc IsBadWritePtr
0x468300 IsBadStringPtrW
0x468304 IsBadReadPtr
0x468314 GetVersionExA
0x468318 GetVersion
0x46831c GetThreadLocale
0x468320 GetThreadContext
0x468324 GetTempPathW
0x468328 GetTempPathA
0x46832c GetTempFileNameW
0x468330 GetTempFileNameA
0x468334 GetSystemDirectoryW
0x468338 GetSystemDirectoryA
0x46833c GetStringTypeExW
0x468340 GetStringTypeExA
0x468344 GetStdHandle
0x468348 GetProcAddress
0x46834c GetModuleHandleA
0x468350 GetModuleFileNameW
0x468354 GetModuleFileNameA
0x46835c GetLocaleInfoW
0x468360 GetLocaleInfoA
0x468364 GetLocalTime
0x468368 GetLastError
0x46836c GetFullPathNameW
0x468370 GetFullPathNameA
0x468374 GetFileSize
0x468378 GetFileAttributesW
0x46837c GetFileAttributesA
0x468380 GetDiskFreeSpaceA
0x468384 GetDateFormatA
0x468388 GetCurrentThreadId
0x46838c GetCurrentProcessId
0x468390 GetCurrentProcess
0x46839c GetCPInfo
0x4683a0 GetACP
0x4683a4 FreeResource
0x4683a8 FreeLibrary
0x4683ac FormatMessageA
0x4683b4 FindResourceW
0x4683b8 FindNextFileW
0x4683bc FindNextFileA
0x4683c0 FindFirstFileW
0x4683c4 FindFirstFileA
0x4683c8 FindClose
0x4683d4 ExitProcess
0x4683d8 EnumCalendarInfoA
0x4683e0 DeleteFileW
0x4683e4 DeleteFileA
0x4683ec CreateFileW
0x4683f0 CreateFileA
0x4683f4 CreateEventA
0x4683f8 CreateDirectoryW
0x4683fc CreateDirectoryA
0x468400 CompareStringW
0x468404 CompareStringA
0x468408 CloseHandle
库: user32.dll:
0x468410 MessageBoxA
0x468414 LoadStringA
0x468418 GetSystemMetrics
0x46841c CharUpperBuffW
0x468420 CharUpperW
0x468424 CharLowerBuffW
0x468428 CharLowerW
0x46842c CharNextA
0x468430 CharLowerA
0x468434 CharUpperA
0x468438 CharToOemA
库: kernel32.dll:
0x468440 Sleep
库: kernel32.dll:
0x468448 ActivateActCtx
0x46844c CreateActCtxW
0x468450 QueryDosDeviceW
库: ole32.dll:
0x46845c CoUninitialize
0x468460 CoInitialize
库: oleaut32.dll:
0x468468 GetErrorInfo
0x46846c SysFreeString
库: oleaut32.dll:
0x468474 SafeArrayPtrOfIndex
0x468478 SafeArrayGetUBound
0x46847c SafeArrayGetLBound
0x468480 SafeArrayCreate
0x468484 VariantChangeType
0x468488 VariantCopy
0x46848c VariantClear
0x468490 VariantInit
库: ntdll.dll:
库: SHFolder.dll:
0x4684ac SHGetFolderPathW
0x4684b0 SHGetFolderPathA
库: ntdll.dll:
库: shlwapi.dll:
0x4684c0 PathMatchSpecW
库: ntdll.dll:
0x4684d0 RtlInitAnsiString
0x4684d8 LdrLoadDll

.text
`.rsrc
@.reloc
B.enigma1
.enigma2
Y `!`
-gr2l
-vr2l
j[l(J
j[l(J
v4.0.30319
#Strings
#GUID
#Blob
<>c__DisplayClass80_0
<>9__2_0
<DecodeKey>b__2_0
<>c__DisplayClass3_0
<>c__DisplayClass4_0
<>9__5_0
<Main>b__5_0
<>c__DisplayClass27_0
<ReAdjustVtt>g__MsToTime|49_0
<DoDownload>b__0
<Has>b__0
<PartialCombineMultipleFiles>b__0
<Get>b__0
<>9__80_1
<DoDownload>b__80_1
<ReAdjustVtt>g__TimeToMs|49_1
Func`1
IEnumerable`1
Action`1
IEnumerator`1
List`1
Get302
ToUInt32
ToInt32
<DoDownload>b__2
Func`2
Converter`2
Dictionary`2
<>9__80_3
<DoDownload>b__80_3
get_KeyBase64
set_KeyBase64
keyBase64
UInt64
ToInt64
ext_x_scte35
Func`5
get_UTF8
get_invalidM3u8
DecodeM3u8
get_downloadingM3u8
get_parsingM3u8
DecryptM3u8
<Module>
<PrivateImplementationDetails>
MEDIA_SUB
get_ExitedCtrlC
STOP_SPEED
MAX_SPEED
LOGFILE
VIDEO_TYPE
AUDIO_TYPE
STOPLOG
get_ASCII
N_m3u8DL-CLI
N_m3u8DL_CLI
CombineURL
BYTEDOWN
System.IO
MEDIA_AUDIO
LOGGER
REC_DUR
NiL.JS
CheckMPEGTS
ConvertToMPEGTS
get_remuxToMPEGTS
REC_DUR_LIMIT
isVTT
set_IV
get_KeyIV
set_KeyIV
keyIV
ILCreateFromPathW
CommandLineToArgvW
ext_x_media
get_Data
get_wrtingMeta
get_wrtingMasterMeta
System.Web
mscorlib
externalSub
bestUrlSub
System.Collections.Generic
DecodeImooc
get_DelAd
set_DelAd
delAd
hasAd
OpenRead
get_CurrentThread
DoDownload
get_newerVerisonDownloaded
get_recordLimitReached
set_Enabled
get_newerVerisonDownloadFailed
get_downloadFailed
add_Renamed
OnRenamed
add_Elapsed
add_Created
OnCreated
get_newerVisionDetected
add_Deleted
OnDeleted
get_IsCompleted
add_ErrorDataReceived
System.Collections.Specialized
<TotalDuration>k__BackingField
GetField
get_RangeEnd
set_RangeEnd
rangeEnd
ReadToEnd
get_DurEnd
set_DurEnd
durEnd
ext_x_cue_end
Append
RegexFind
get_masterListFound
set_IsBackground
get_Method
set_Method
get_notSupportMethod
method
Record
Replace
ext_x_media_sequence
ext_x_discontinuity_sequence
get_ExitedForce
GetWebSource
CancellationTokenSource
source
set_Mode
FileMode
PaddingMode
CompressionMode
CipherMode
UrlDecode
ILFree
get_Message
AddRange
setRange
ext_x_byterange
get_NoMerge
set_NoMerge
noMerge
BinaryMerge
ext_x_allow_cache
EndInvoke
BeginInvoke
GetVariable
GetEnvironmentVariable
SetEnvironmentVariable
Enumerable
IDisposable
set_CursorVisible
ToDouble
RuntimeTypeHandle
GetTypeFromHandle
HttpDownloadFile
CombineMultipleFilesIntoSingleFile
get_LiveFile
set_LiveFile
liveFile
jsonFile
get_downloadingMapFile
get_ReportFile
set_ReportFile
reportFile
get_KeyFile
set_KeyFile
keyFile
IsVolatile
Console
set_Title
title
get_MainModule
ProcessModule
get_Name
get_FileName
set_FileName
MakeValidFileName
GetValidFileName
GetUrlFileName
GetFileName
get_fileName
fflogName
get_FullName
get_DownName
set_DownName
downName
audioName
argumentName
GetDirectoryName
get_CalcTime
set_CalcTime
calcTime
DateTime
FormatTime
ext_x_program_date_time
BeginErrorReadLine
lpCmdLine
get_CommandLine
commandLine
WriteLine
PrintLine
lastKeyLine
Combine
HandlerRoutine
get_ffmpegDone
get_taskDone
get_DelAfterDone
set_DelAfterDone
delAfterDone
get_IsDone
set_IsDone
isDone
SecurityProtocolType
CtrlType
ext_x_playlist_type
FileShare
NiL.JS.Core
System.Core
N_m3u8DL_CLI.NetCore
get_CurrentUICulture
set_CurrentUICulture
get_Culture
set_Culture
resourceCulture
set_DefaultThreadCurrentCulture
Capture
numBase
HttpWebResponse
GetResponse
AppendBytesToFileStreamAndDoNotClose
Dispose
Parse
get_WriteDate
set_WriteDate
writeDate
nowDate
X509Certificate
ValidateServerCertificate
certificate
CheckUpdate
Create
ControlCtrlDelegate
MulticastDelegate
EditorBrowsableState
ParallelLoopState
loopstate
Delete
get_downloadComplete
IsComplete
OpenWrite
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
GetTagAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
get_ExpectByte
set_ExpectByte
expectByte
get_StartByte
set_StartByte
startByte
ivByte
keyByte
JSValue
get_Value
GetValue
SetValue
value
get_IsLive
set_IsLive
isLive
set_KeepAlive
Remove
N_m3u8DL-CLI.exe
get_Size
get_DownloadedSize
set_DownloadedSize
downloadedSize
FormatFileSize
fileSize
set_BlockSize
set_KeySize
Serialize
Deserialize
LastIndexOf
encryptedBuff
ext_x_i_frame_stream_inf
ext_x_stream_inf
extinf
bflag
firstSeg
isNewSeg
FFmpeg
System.Threading
get_startDownloading
set_Padding
get_liveStreamFoundAndRecoding
MD5Encoding
set_StandardErrorEncoding
get_ContentEncoding
get_dolbyVisionContentMerging
get_startMerging
System.Runtime.Versioning
Warning
FromBase64String
ToBase64String
ConvertJsonString
ToString
GetString
GetQueryString
Substring
get_startReParsing
get_startParsing
set_Formatting
get_SomethingWasWrong
FindLog
InitLog
ForEach
IsMatch
ComputeHash
ComputeStringHash
set_AutoFlush
set_Path
outputFilePath
filePath
m3u8SavePath
get_SavePath
set_SavePath
jsonSavePath
get_savePath
get_LocalPath
get_FullPath
get_OutPutPath
set_OutPutPath
outPutPath
pszPath
bestBandwidth
get_Length
get_ContentLength
GetDirectoryLength
EndsWith
StartsWith
PtrToStringUni
get_InvalidUri
get_ResponseUri
AsyncCallback
RemoteCertificateValidationCallback
set_ServerCertificateValidationCallback
callback
get_downloadingExternalSubtitleTrack
get_hasExternalSubtitleTrack
get_downloadingExternalAudioTrack
get_hasExternalAudioTrack
MasterListCheck
get_DisableIntegrityCheck
set_DisableIntegrityCheck
get_disableIntegrityCheck
LogWriteLock
EnterWriteLock
ExitWriteLock
TransformFinalBlock
FreeHGlobal
Marshal
get_Total
set_Total
total
get_Interval
set_Interval
Cancel
System.ComponentModel
Parallel
printLevel
ConvertAll
kernel32.dll
shell32.dll
set_SecurityProtocol
encodingTool
get_M3u8Url
set_M3u8Url
GetVaildM3u8Url
m3u8Url
externalSubUrl
subUrl
get_FileUrl
set_FileUrl
fileUrl
get_BaseUrl
set_BaseUrl
GetBaseUrl
baseUrl
externalAudioUrl
audioUrl
bestUrl
m3u8url
baseurl
FileStream
GetResponseStream
get_LiveStream
set_LiveStream
liveStream
get_EndOfStream
GZipStream
MemoryStream
Program
get_Item
set_Item
System
SymmetricAlgorithm
HashAlgorithm
ReaderWriterLockSlim
ICryptoTransform
set_MaxDegreeOfParallelism
GetNum
SetIn
resourceMan
ToBoolean
TimeSpan
ext_x_cue_span
JToken
get_Token
set_CancellationToken
children
GetSign
X509Chain
chain
SeekOrigin
get_Extension
GetExtension
GetFileNameWithoutExtension
ext_x_version
System.IO.Compression
get_fileDuration
get_TotalDuration
set_TotalDuration
totalDuration
ext_x_targetduration
set_Indentation
System.Globalization
op_Subtraction
System.Reflection
NameValueCollection
MatchCollection
GroupCollection
WebHeaderCollection
Function
get_waitForCompletion
SetCursorPosition
Win32Exception
ArgumentException
Newtonsoft.Json
get_MuxSetJson
set_MuxSetJson
muxSetJson
isFirstJson
isQiQiuYun
DecodeDdyun
WriteTo
MoveTo
CopyTo
HadReadInfo
FieldInfo
get_readingFileInfo
GetCultureInfo
FileSystemInfo
GetVideoInfo
get_helpInfo
get_StartInfo
ProcessStartInfo
ConsoleKeyInfo
DirectoryInfo
externalAudio
bestUrlAudio
segsPadZero
partsPadZero
ext_x_map
Sleep
get_ffmpegTip
downloadingM3u8KeyTip
GetTimeStamp
get_ShouldStop
set_ShouldStop
shouldStop
WatcherStop
TimerStop
Group
group
System.Linq
Newtonsoft.Json.Linq
Clear
ToChar
set_IndentChar
nowVer
TrySkipPngHeader
StringReader
StreamReader
JsonReader
JsonTextReader
HLSLiveDownloader
StringBuilder
sender
DownloadManager
get_ResourceManager
ServicePointManager
FileSystemWatcher
watcher
cancelHandler
SetConsoleCtrlHandler
GzipHandler
RenamedEventHandler
ElapsedEventHandler
DataReceivedEventHandler
FileSystemEventHandler
System.CodeDom.Compiler
Timer
timer
JContainer
ToUpper
set_Referer
CommandLineArgumentParser
StringWriter
StreamWriter
JsonWriter
JsonTextWriter
get_UseAACFilter
set_UseAACFilter
useAACFilter
set_Filter
Decrypter
poster
ToLower
JsonSerializer
workDir
get_DownDir
set_DownDir
downDir
get_HasSetDir
set_HasSetDir
hasSetDir
get_ForegroundColor
set_ForegroundColor
set_BackgroundColor
ConsoleColor
ResetColor
get_StandardError
set_RedirectStandardError
WriteLineError
IEnumerator
GetEnumerator
.ctor
.cctor
CreateDecryptor
ReadIntPtr
hexStr
get_SegDur
set_SegDur
segDur
System.Diagnostics
get_Threads
set_Threads
threads
get_Seconds
get_TotalSeconds
get_Milliseconds
get_TotalMilliseconds
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
N_m3u8DL_CLI.strings.resources
DebuggingModes
Matches
GetDirectories
set_IncludeSubdirectories
DecodeNfmovies
PartialCombineMultipleFiles
GetFiles
files
NumberStyles
System.Security.Cryptography.X509Certificates
get_Minutes
ReadAllBytes
WriteAllBytes
HttpDownloadFileToBytes
HexStringToBytes
GetBytes
get_HasValues
HLSTags
BindingFlags
dwFlags
strings
pNumArgs
RenamedEventArgs
ElapsedEventArgs
DataReceivedEventArgs
FileSystemEventArgs
<>4__this
System.Threading.Tasks
Equals
SHOpenFolderAndSelectItems
Contains
NiL.JS.Extensions
JSValueExtensions
System.Text.RegularExpressions
System.Collections
ParallelOptions
RegexOptions
get_Groups
get_Chars
GetInvalidFileNameChars
get_Headers
set_Headers
headers
System.Timers
SslPolicyErrors
sslPolicyErrors
get_Hours
rawPass
FileAccess
sendProcess
GetCurrentProcess
address
ext_is_independent_segments
set_Arguments
ParseArguments
_arguments
set_EnableRaisingEvents
extLists
Exists
get_Previous
RemoveAt
Concat
get_MuxFormat
set_MuxFormat
muxFormat
WatcherStrat
JObject
GlobalObject
object
Select
Collect
set_AllowAutoRedirect
System.Net
set_AutoReset
PadLeft
PadRight
copyright
get_ffmpegMergingPleaseWait
get_partialMergingPleaseWait
get_binaryMergingPleaseWait
op_Implicit
Split
set_DefaultConnectionLimit
WriteInit
get_parseExit
WaitForExit
get_pressAnyKeyExit
get_Default
FirstOrDefault
IAsyncResult
ParallelLoopResult
result
parseInt
set_UserAgent
WebClient
replacement
get_downloadingFirstSegement
comment
Environment
CommandLineArgument
argument
Component
GetParent
get_Current
get_Count
set_Count
get_downloadedCount
get_selectedCount
GetFileCount
get_segCount
stopCount
get_ProcessorCount
get_PartsCount
set_PartsCount
partsCount
get_RetryCount
set_RetryCount
get_retryCount
count
set_Accept
Microsoft.JScript
AES128Decrypt
ThreadStart
get_RangeStart
set_RangeStart
rangeStart
TimerStart
get_DurStart
set_DurStart
durStart
get_MuxFastStart
set_MuxFastStart
muxFastStart
fastStart
ext_x_cue_start
ext_x_cue_out_start
ext_x_start
Convert
Abort
HttpWebRequest
GetWebRequest
UpdateList
attributeList
pidlList
toDownList
ArrayList
ext_x_endlist
get_selectPlaylist
get_ffmpegLost
ReAdjustVtt
get_TimeOut
set_TimeOut
timeOut
ext_x_cue_out
set_Timeout
set_ReadWriteTimeout
setTimeout
timeout
get_StandardInput
OpenStandardInput
set_RedirectStandardInput
input
set_RedirectStandardOutput
output
get_Next
MoveNext
System.Text
AppendText
ReadAllText
WriteAllText
_argumentText
Context
ext_m3u
get_Iv
set_Iv
get_Now
set_Now
get_UtcNow
set_CreateNoWindow
WebClientEx
get_SegIndex
set_SegIndex
segIndex
FFmpegCorsorIndex
CursorIndex
cursorIndex
_index
Regex
regex
JArray
byteArray
ToArray
get_downloadingM3u8Key
get_Key
set_Key
ReadKey
GetDecodeKey
encodeKey
ParseKey
Decode51CtoKey
ContainsKey
m3u8CurrentKey
ext_x_key
System.Security.Cryptography
get_Assembly
ext_i_frames_only
NiL.JS.BaseLibrary
get_PathAndQuery
ForceCanonicalPathAndQuery
CreateDirectory
get_CurrentDirectory
GetCurrentDirectory
SetCurrentDirectory
get_Retry
set_Retry
retry
op_Equality
op_Inequality
HttpUtility
System.Net.Security
ext_x_discontinuity
IsNullOrEmpty
set_Proxy
IWebProxy
get_NoProxy
set_NoProxy
noProxy
N_m3u8DL-CLI
nilaoda
2020
$4fb61439-b738-46ac-b3af-2bf72150d057
2.7.4.0
16.0.0.0
ExitedCtrlC
InvalidUri,
SomethingWasWrong:
binaryMergingPleaseWaitR
disableIntegrityChecku
没有防病毒引擎扫描信息!

访问主机纪录 (可点击查询WPING实时安全评级)

无主机纪录.

TCP

无TCP连接纪录.

UDP

无UDP连接纪录.

域名解析 (可点击查询WPING实时安全评级)

无域名信息.

TCP

无TCP连接纪录.

UDP

无UDP连接纪录.

HTTP 请求

未发现HTTP请求.

SMTP 流量

无SMTP流量.

IRC 流量

无IRC请求.

ICMP 流量

无ICMP流量.

CIF 报告

无 CIF 结果

网络警报

无警报

TLS

No TLS

Suricata HTTP

No Suricata HTTP

未发现网络提取文件
抱歉! 没有任何文件投放。
没有发现相似的分析.
HTML 总结报告
(需15-60分钟同步)
下载

Processing ( 5.424 seconds )

  • 2.843 Static
  • 1.54 VirusTotal
  • 0.374 TargetInfo
  • 0.356 peid
  • 0.296 Strings
  • 0.01 AnalysisInfo
  • 0.002 Memory
  • 0.002 config_decoder
  • 0.001 BehaviorAnalysis

Signatures ( 0.075 seconds )

  • 0.011 antiav_detectreg
  • 0.009 md_domain_bl
  • 0.009 md_url_bl
  • 0.005 anomaly_persistence_autorun
  • 0.005 infostealer_ftp
  • 0.004 antiav_detectfile
  • 0.004 ransomware_files
  • 0.003 infostealer_bitcoin
  • 0.003 infostealer_im
  • 0.003 ransomware_extensions
  • 0.002 tinba_behavior
  • 0.002 antianalysis_detectreg
  • 0.002 antivm_vbox_files
  • 0.002 disables_browser_warn
  • 0.002 infostealer_mail
  • 0.001 rat_nanocore
  • 0.001 cerber_behavior
  • 0.001 geodo_banking_trojan
  • 0.001 bot_drive
  • 0.001 bot_drive2
  • 0.001 browser_security
  • 0.001 modify_proxy
  • 0.001 maldun_malicious_drop_executable_file_to_temp_folder
  • 0.001 md_bad_drop

Reporting ( 0.492 seconds )

  • 0.432 ReportHTMLSummary
  • 0.06 Malheur
Task ID 578322
Mongo ID 5f720084dc327b356122958a
Cuckoo release 1.4-Maldun