分析任务

分析类型 虚拟机标签 开始时间 结束时间 持续时间
文件 (Windows) win7-sp1-x64-shaapp02-1 2024-04-29 20:14:20 2024-04-29 20:15:09 49 秒

魔盾分数

6.075

危险的

文件详细信息

文件名 steamworks.exe
文件大小 3739376 字节
文件类型 PE32 executable (GUI) Intel 80386, for MS Windows
MD5 91ab4023c2870d3adbc35385a9ea882a
SHA1 2521af9a53f46a511a86dd73ad57a7eb90e1e752
SHA256 9497c75c31829796573df742c5fb39a699d9a267de703023a7d5c596435cc462
SHA512 aac0478bdf70aa00da3f4cdd6aa4951d8c172c3f64927b1ba18ac84d0ef135b8d8e5e303dc7178f4d3aa21511803ff8ce98265dfadce6a3238845212a040103f
CRC32 973AC0FA
Ssdeep 98304:T7BQoH9MunPvQGttD9LE1hO0iDnk/cozI6evaYZbyMv:veG/PIGNATO0iDgjCZbj
Yara 登录查看Yara规则
找不到该样本 提交误报

登录查看威胁特征

运行截图


访问主机纪录 (可点击查询WPING实时安全评级)

直接 IP 安全评级 地理位置
104.18.38.233 美国

域名解析 (可点击查询WPING实时安全评级)

域名 安全评级 响应
crt.usertrust.com 未知 A 104.18.38.233
CNAME crt.comodoca.com
A 172.64.149.23
CNAME crt.comodoca.com.cdn.cloudflare.net
steamgogo.gtx3080ti.cc 未知 A 106.52.235.100

摘要

登录查看详细行为信息

PE 信息

初始地址 0x00400000
入口地址 0x010a50dc
声明校验值 0x00393d9b
实际校验值 0x00393d9b
最低操作系统版本要求 6.0
编译时间 2024-03-26 18:26:18
载入哈希 e23255b5d7d4d07b1e607657a7ad9a85
导出DLL库名称 \x31\x31\x31\x39\x31\x31\x31\x31\x31\x31\x34\x31\x31\x31

版本信息

LegalCopyright
InternalName
FileVersion
ProductVersion
CompanyName
Translation

微软证书验证 (Sign Tool)

SHA1 时间戳 有效性 错误
69541a600e202185faad95c203bf294a638c4cbb Tue Mar 26 18:27:57 2024
WinVerifyTrust returned error 0x800B010A
证书链 Certificate Chain 1
发行给 Sectigo Public Code Signing Root R46
发行人 AAA Certificate Services
有效期 Mon Jan 01 075959 2029
SHA1 哈希 329b78a5c9ebc2043242de90ce1b7c6b1ba6c692
证书链 Certificate Chain 2
发行给 Sectigo Public Code Signing CA EV R36
发行人 Sectigo Public Code Signing Root R46
有效期 Sat Mar 22 075959 2036
SHA1 哈希 0185ff9961ff0aa2e431817948c28e83d3f3ec70
证书链 Certificate Chain 3
发行给
发行人 Sectigo Public Code Signing CA EV R36
有效期 Fri Oct 25 075959 2024
SHA1 哈希 496f8959b98c497a25eadd3da8db08913e0986a4
证书链 Timestamp Chain 1
发行给 USERTrust RSA Certification Authority
发行人 AAA Certificate Services
有效期 Mon Jan 01 075959 2029
SHA1 哈希 d89e3bd43d5d909b47a18977aa9d5ce36cee184c
证书链 Timestamp Chain 2
发行给 Sectigo RSA Time Stamping CA
发行人 USERTrust RSA Certification Authority
有效期 Tue Jan 19 075959 2038
SHA1 哈希 02d65b95e28370c1570095fa88f923dd937fad8f
证书链 Timestamp Chain 3
发行给 Sectigo RSA Time Stamping Signer #4
发行人 Sectigo RSA Time Stamping CA
有效期 Thu Aug 03 075959 2034
SHA1 哈希 ae62af750a0cbd47d6461f7568e2bc8ce7ca4f94

PE 数据组成

名称 虚拟地址 虚拟大小 原始数据大小 特征 熵(Entropy)
0x00001000 0x001e8000 0x000cd000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 8.00
0x001e9000 0x00075000 0x00027c00 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 8.00
0x0025e000 0x00022000 0x00001e00 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 7.95
0x00280000 0x00052000 0x00035800 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 8.00
0x002d2000 0x0001c000 0x0000ee00 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 8.00
.rsrc 0x002ee000 0x00006000 0x00005800 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4.86
0x002f4000 0x0079a000 0x00032800 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 8.00
.data 0x00a8e000 0x00219000 0x00218a00 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 7.97

资源

名称 偏移量 大小 语言 子语言 熵(Entropy) 文件类型
XML 0x002d0768 0x00000be4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
XML 0x002d0768 0x00000be4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None
XML 0x002d0768 0x00000be4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 None

导入

库: kernel32.dll:
0xe965fc GetModuleHandleA
0xe96600 GetProcAddress
0xe96604 ExitProcess
0xe96608 LoadLibraryA
库: user32.dll:
0xe96610 MessageBoxA
库: advapi32.dll:
0xe96618 RegCloseKey
库: oleaut32.dll:
0xe96620 SysFreeString
库: gdi32.dll:
0xe96628 CreateFontA
库: shell32.dll:
0xe96630 ShellExecuteA
库: version.dll:
0xe96638 GetFileVersionInfoA
库: dbghelp.dll:
0xe96640 MiniDumpWriteDump
库: ole32.dll:
0xe96648 OleLockRunning
库: CRYPT32.dll:
0xe96650 CryptMsgGetParam
库: SHLWAPI.dll:
库: IMM32.dll:
0xe96660 ImmAssociateContext
库: WININET.dll:
0xe96668 InternetOpenW
库: WS2_32.dll:
0xe96670 WSAStartup
库: WINHTTP.dll:
0xe96678 WinHttpOpen
库: gdiplus.dll:
库: MSIMG32.dll:
0xe96688 GradientFill

导出

序列 地址 名称
1 0x4f7b70 ??0CharReader@Json@@QAE@ABV01@@Z
2 0x4f7b80 ??0CharReader@Json@@QAE@XZ
3 0x4f7b90 ??0CharReaderBuilder@Json@@QAE@ABV01@@Z
4 0x4f7bc0 ??0CharReaderBuilder@Json@@QAE@XZ
5 0x4ee600 ??0Exception@Json@@QAE@ABV01@@Z
6 0x508770 ??0Exception@Json@@QAE@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
7 0x4f7c20 ??0Factory@CharReader@Json@@QAE@ABV012@@Z
8 0x4f7c30 ??0Factory@CharReader@Json@@QAE@XZ
9 0x4ee680 ??0Factory@StreamWriter@Json@@QAE@ABV012@@Z
10 0x4ee690 ??0Factory@StreamWriter@Json@@QAE@XZ
11 0x4ee6a0 ??0FastWriter@Json@@QAE@ABV01@@Z
12 0x4ee710 ??0FastWriter@Json@@QAE@XZ
13 0x4f7c40 ??0Features@Json@@QAE@XZ
14 0x4ee740 ??0LogicError@Json@@QAE@$$QAV01@@Z
15 0x4ee7c0 ??0LogicError@Json@@QAE@ABV01@@Z
16 0x5087b0 ??0LogicError@Json@@QAE@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
17 0x4ee840 ??0Path@Json@@QAE@$$QAV01@@Z
18 0x4ee890 ??0Path@Json@@QAE@ABV01@@Z
19 0x508800 ??0Path@Json@@QAE@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@ABVPathArgument@1@1111@Z
20 0x4ee920 ??0PathArgument@Json@@QAE@$$QAV01@@Z
21 0x4ee970 ??0PathArgument@Json@@QAE@ABV01@@Z
22 0x508990 ??0PathArgument@Json@@QAE@I@Z
23 0x5089c0 ??0PathArgument@Json@@QAE@PBD@Z
24 0x508a10 ??0PathArgument@Json@@QAE@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
25 0x508a50 ??0PathArgument@Json@@QAE@XZ
26 0x4f7d80 ??0Reader@Json@@QAE@$$QAV01@@Z
27 0x4f7f70 ??0Reader@Json@@QAE@ABV01@@Z
28 0x4f8240 ??0Reader@Json@@QAE@ABVFeatures@1@@Z
29 0x4f8350 ??0Reader@Json@@QAE@XZ
30 0x4ee9a0 ??0RuntimeError@Json@@QAE@$$QAV01@@Z
31 0x4eea20 ??0RuntimeError@Json@@QAE@ABV01@@Z
32 0x508a80 ??0RuntimeError@Json@@QAE@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
33 0x4eeaa0 ??0StaticString@Json@@QAE@PBD@Z
34 0x4eeab0 ??0StreamWriter@Json@@QAE@ABV01@@Z
35 0x4eead0 ??0StreamWriter@Json@@QAE@XZ
36 0x4eeae0 ??0StreamWriterBuilder@Json@@QAE@ABV01@@Z
37 0x4eeb40 ??0StreamWriterBuilder@Json@@QAE@XZ
38 0x4eebb0 ??0StyledStreamWriter@Json@@QAE@ABV01@@Z
39 0x4eec40 ??0StyledStreamWriter@Json@@QAE@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
40 0x4eecb0 ??0StyledWriter@Json@@QAE@ABV01@@Z
41 0x4eed40 ??0StyledWriter@Json@@QAE@XZ
42 0x508ad0 ??0Value@Json@@QAE@$$QAV01@@Z
43 0x508b30 ??0Value@Json@@QAE@ABV01@@Z
44 0x508b90 ??0Value@Json@@QAE@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
45 0x508c00 ??0Value@Json@@QAE@ABVStaticString@1@@Z
46 0x508c60 ??0Value@Json@@QAE@H@Z
47 0x508cc0 ??0Value@Json@@QAE@I@Z
48 0x508d20 ??0Value@Json@@QAE@N@Z
49 0x508d80 ??0Value@Json@@QAE@PBD0@Z
50 0x508df0 ??0Value@Json@@QAE@PBD@Z
51 0x508ec0 ??0Value@Json@@QAE@W4ValueType@1@@Z
52 0x508fb0 ??0Value@Json@@QAE@_J@Z
53 0x509010 ??0Value@Json@@QAE@_K@Z
54 0x509070 ??0Value@Json@@QAE@_N@Z
55 0x5090d0 ??0ValueConstIterator@Json@@AAE@ABV?$_Tree_iterator@V?$_Tree_val@U?$_Tree_simple_types@U?$pair@$$CBVCZString@Value@Json@@V23@@std@@@std@@@std@@@std@@@Z
56 0x5090f0 ??0ValueConstIterator@Json@@QAE@ABVValueIterator@1@@Z
57 0x509110 ??0ValueConstIterator@Json@@QAE@XZ
58 0x509120 ??0ValueIterator@Json@@AAE@ABV?$_Tree_iterator@V?$_Tree_val@U?$_Tree_simple_types@U?$pair@$$CBVCZString@Value@Json@@V23@@std@@@std@@@std@@@std@@@Z
59 0x509140 ??0ValueIterator@Json@@QAE@ABV01@@Z
60 0x509160 ??0ValueIterator@Json@@QAE@ABVValueConstIterator@1@@Z
61 0x5091c0 ??0ValueIterator@Json@@QAE@XZ
62 0x5091d0 ??0ValueIteratorBase@Json@@QAE@ABV?$_Tree_iterator@V?$_Tree_val@U?$_Tree_simple_types@U?$pair@$$CBVCZString@Value@Json@@V23@@std@@@std@@@std@@@std@@@Z
63 0x5091f0 ??0ValueIteratorBase@Json@@QAE@XZ
64 0x4eeda0 ??0Writer@Json@@QAE@ABV01@@Z
65 0x4eedb0 ??0Writer@Json@@QAE@XZ
66 0x4f8630 ??1CharReader@Json@@UAE@XZ
67 0x4f8640 ??1CharReaderBuilder@Json@@UAE@XZ
68 0x5094d0 ??1Exception@Json@@UAE@XZ
69 0x4f86a0 ??1Factory@CharReader@Json@@UAE@XZ
70 0x4ef100 ??1Factory@StreamWriter@Json@@UAE@XZ
71 0x40f531 ??1FastWriter@Json@@UAE@XZ
72 0x4ef110 ??1LogicError@Json@@UAE@XZ
73 0x4ef120 ??1Path@Json@@QAE@XZ
74 0x4ef130 ??1PathArgument@Json@@QAE@XZ
75 0x4167b6 ??1Reader@Json@@QAE@XZ
76 0x4ef180 ??1RuntimeError@Json@@UAE@XZ
77 0x4ef190 ??1StreamWriter@Json@@UAE@XZ
78 0x4ef1a0 ??1StreamWriterBuilder@Json@@UAE@XZ
79 0x4ef1c0 ??1StyledStreamWriter@Json@@QAE@XZ
80 0x4ef260 ??1StyledWriter@Json@@UAE@XZ
81 0x509540 ??1Value@Json@@QAE@XZ
82 0x4ef300 ??1Writer@Json@@UAE@XZ
83 0x4f8820 ??4CharReader@Json@@QAEAAV01@ABV01@@Z
84 0x4f8830 ??4CharReaderBuilder@Json@@QAEAAV01@ABV01@@Z
85 0x4ef310 ??4Exception@Json@@QAEAAV01@ABV01@@Z
86 0x4f8850 ??4Factory@CharReader@Json@@QAEAAV012@ABV012@@Z
87 0x4ef360 ??4Factory@StreamWriter@Json@@QAEAAV012@ABV012@@Z
88 0x4ef370 ??4FastWriter@Json@@QAEAAV01@ABV01@@Z
89 0x4f8860 ??4Features@Json@@QAEAAV01@$$QAV01@@Z
90 0x4f8890 ??4Features@Json@@QAEAAV01@ABV01@@Z
91 0x4ef3c0 ??4LogicError@Json@@QAEAAV01@$$QAV01@@Z
92 0x4ef410 ??4LogicError@Json@@QAEAAV01@ABV01@@Z
93 0x4ef460 ??4Path@Json@@QAEAAV01@$$QAV01@@Z
94 0x4ef4a0 ??4Path@Json@@QAEAAV01@ABV01@@Z
95 0x4ef4d0 ??4PathArgument@Json@@QAEAAV01@$$QAV01@@Z
96 0x4ef560 ??4PathArgument@Json@@QAEAAV01@ABV01@@Z
97 0x4f88a0 ??4Reader@Json@@QAEAAV01@$$QAV01@@Z
98 0x4f89b0 ??4Reader@Json@@QAEAAV01@ABV01@@Z
99 0x4ef5a0 ??4RuntimeError@Json@@QAEAAV01@$$QAV01@@Z
100 0x4ef5f0 ??4RuntimeError@Json@@QAEAAV01@ABV01@@Z
101 0x4ef640 ??4StaticString@Json@@QAEAAV01@$$QAV01@@Z
102 0x4ef650 ??4StaticString@Json@@QAEAAV01@ABV01@@Z
103 0x4ef660 ??4StreamWriter@Json@@QAEAAV01@ABV01@@Z
104 0x4ef680 ??4StreamWriterBuilder@Json@@QAEAAV01@ABV01@@Z
105 0x4ef6a0 ??4StyledStreamWriter@Json@@QAEAAV01@ABV01@@Z
106 0x4ef730 ??4StyledWriter@Json@@QAEAAV01@ABV01@@Z
107 0x509770 ??4Value@Json@@QAEAAV01@$$QAV01@@Z
108 0x509790 ??4Value@Json@@QAEAAV01@ABV01@@Z
109 0x4ef7b0 ??4ValueConstIterator@Json@@QAEAAV01@$$QAV01@@Z
110 0x4ef7d0 ??4ValueConstIterator@Json@@QAEAAV01@ABV01@@Z
111 0x509880 ??4ValueConstIterator@Json@@QAEAAV01@ABVValueIteratorBase@1@@Z
112 0x5098a0 ??4ValueIterator@Json@@QAEAAV01@ABV01@@Z
113 0x4ef7f0 ??4ValueIteratorBase@Json@@QAEAAV01@$$QAV01@@Z
114 0x4ef810 ??4ValueIteratorBase@Json@@QAEAAV01@ABV01@@Z
115 0x4ef830 ??4Writer@Json@@QAEAAV01@ABV01@@Z
116 0x4f8a60 ??5Json@@YAAAV?$basic_istream@DU?$char_traits@D@std@@@std@@AAV12@AAVValue@0@@Z
117 0x4ef840 ??6Json@@YAAAV?$basic_ostream@DU?$char_traits@D@std@@@std@@AAV12@ABVValue@0@@Z
118 0x5099b0 ??8Value@Json@@QBE_NABV01@@Z
119 0x4ef8e0 ??8ValueIteratorBase@Json@@QBE_NABV01@@Z
120 0x509c70 ??9Value@Json@@QBE_NABV01@@Z
121 0x4ef8f0 ??9ValueIteratorBase@Json@@QBE_NABV01@@Z
122 0x4f8e10 ??ACharReaderBuilder@Json@@QAEAAVValue@1@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
123 0x4ef910 ??AStreamWriterBuilder@Json@@QAEAAVValue@1@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
124 0x509c90 ??AValue@Json@@QAEAAV01@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
125 0x509cc0 ??AValue@Json@@QAEAAV01@ABVStaticString@1@@Z
126 0x509ce0 ??AValue@Json@@QAEAAV01@H@Z
127 0x509d80 ??AValue@Json@@QAEAAV01@I@Z
128 0x50a060 ??AValue@Json@@QAEAAV01@PBD@Z
129 0x50a090 ??AValue@Json@@QBEABV01@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
130 0x50a0d0 ??AValue@Json@@QBEABV01@H@Z
131 0x50a170 ??AValue@Json@@QBEABV01@I@Z
132 0x50a260 ??AValue@Json@@QBEABV01@PBD@Z
133 0x4ef920 ??BStaticString@Json@@QBEPBDXZ
134 0x50a2a0 ??BValue@Json@@QBE_NXZ
135 0x4ef930 ??CValueConstIterator@Json@@QBEPBVValue@1@XZ
136 0x4ef940 ??CValueIterator@Json@@QAEPAVValue@1@XZ
137 0x4ef950 ??DValueConstIterator@Json@@QBEABVValue@1@XZ
138 0x4ef960 ??DValueIterator@Json@@QAEAAVValue@1@XZ
139 0x4ef970 ??EValueConstIterator@Json@@QAE?AV01@H@Z
140 0x4ef990 ??EValueConstIterator@Json@@QAEAAV01@XZ
141 0x4ef9a0 ??EValueIterator@Json@@QAE?AV01@H@Z
142 0x4ef9c0 ??EValueIterator@Json@@QAEAAV01@XZ
143 0x4ef9d0 ??FValueConstIterator@Json@@QAE?AV01@H@Z
144 0x4ef9f0 ??FValueConstIterator@Json@@QAEAAV01@XZ
145 0x4efa00 ??FValueIterator@Json@@QAE?AV01@H@Z
146 0x4efa20 ??FValueIterator@Json@@QAEAAV01@XZ
147 0x4efa30 ??GValueIteratorBase@Json@@QBEHABV01@@Z
148 0x50a4a0 ??MValue@Json@@QBE_NABV01@@Z
149 0x50a750 ??NValue@Json@@QBE_NABV01@@Z
150 0x50a770 ??OValue@Json@@QBE_NABV01@@Z
151 0x50a780 ??PValue@Json@@QBE_NABV01@@Z
152 0x6046f8 ??_7CharReader@Json@@6B@
153 0x604704 ??_7CharReaderBuilder@Json@@6B@
154 0x604438 ??_7Exception@Json@@6B@
155 0x6046ec ??_7Factory@CharReader@Json@@6B@
156 0x60445c ??_7Factory@StreamWriter@Json@@6B@
157 0x60448c ??_7FastWriter@Json@@6B@
158 0x604450 ??_7LogicError@Json@@6B@
159 0x604444 ??_7RuntimeError@Json@@6B@
160 0x604468 ??_7StreamWriter@Json@@6B@
161 0x604474 ??_7StreamWriterBuilder@Json@@6B@
162 0x604498 ??_7StyledWriter@Json@@6B@
163 0x604480 ??_7Writer@Json@@6B@
164 0x4f0090 ??_FStyledStreamWriter@Json@@QAEXXZ
165 0x4f0110 ??_FValue@Json@@QAEXXZ
166 0x4fcb40 ?addComment@Reader@Json@@AAEXPBD0W4CommentPlacement@2@@Z
167 0x4fce00 ?addError@Reader@Json@@AAE_NABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAVToken@12@PBD@Z
168 0x4fcf10 ?addErrorAndRecover@Reader@Json@@AAE_NABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAVToken@12@W4TokenType@12@@Z
169 0x50afb0 ?addPathInArg@Path@Json@@AAEXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@ABV?$vector@PBVPathArgument@Json@@V?$allocator@PBVPathArgument@Json@@@std@@@4@AAV?$_Vector_const_iterator@V?$_Vector_val@U?$_Simple_types@PBVPathArgument@Json@@@std@@@std@@@4@W4Kind@PathArgument@2@@Z
170 0x4fcf40 ?all@Features@Json@@SA?AV12@XZ
171 0x50b0d0 ?append@Value@Json@@QAEAAV12@$$QAV12@@Z
172 0x50b370 ?append@Value@Json@@QAEAAV12@ABV12@@Z
173 0x50b470 ?asBool@Value@Json@@QBE_NXZ
174 0x50b550 ?asCString@Value@Json@@QBEPBDXZ
175 0x50b600 ?asDouble@Value@Json@@QBENXZ
176 0x50b710 ?asFloat@Value@Json@@QBEMXZ
177 0x50b820 ?asInt64@Value@Json@@QBE_JXZ
178 0x50b9c0 ?asInt@Value@Json@@QBEHXZ
179 0x50bba0 ?asLargestInt@Value@Json@@QBE_JXZ
180 0x50bbb0 ?asLargestUInt@Value@Json@@QBE_KXZ
181 0x50bbc0 ?asString@Value@Json@@QBE?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@XZ
182 0x50bd20 ?asUInt64@Value@Json@@QBE_KXZ
183 0x50bec0 ?asUInt@Value@Json@@QBEIXZ
184 0x50c0a0 ?begin@Value@Json@@QAE?AVValueIterator@2@XZ
185 0x50c0e0 ?begin@Value@Json@@QBE?AVValueConstIterator@2@XZ
186 0x4f0780 ?c_str@StaticString@Json@@QBEPBDXZ
187 0x50c120 ?clear@Value@Json@@QAEXXZ
188 0x50c200 ?compare@Value@Json@@QBEHABV12@@Z
189 0x50c240 ?computeDistance@ValueIteratorBase@Json@@IBEHABV12@@Z
190 0x4fd3e0 ?containsNewLine@Reader@Json@@CA_NPBD0@Z
191 0x50c290 ?copy@Value@Json@@QAEXABV12@@Z
192 0x50c2b0 ?copy@ValueIteratorBase@Json@@IAEXABV12@@Z
193 0x50c2d0 ?copyPayload@Value@Json@@QAEXABV12@@Z
194 0x4fd440 ?currentValue@Reader@Json@@AAEAAVValue@2@XZ
195 0x4fd8a0 ?decodeDouble@Reader@Json@@AAE_NAAVToken@12@@Z
196 0x4fd9a0 ?decodeDouble@Reader@Json@@AAE_NAAVToken@12@AAVValue@2@@Z
197 0x4fdfc0 ?decodeNumber@Reader@Json@@AAE_NAAVToken@12@@Z
198 0x4fe0c0 ?decodeNumber@Reader@Json@@AAE_NAAVToken@12@AAVValue@2@@Z
199 0x4fe820 ?decodeString@Reader@Json@@AAE_NAAVToken@12@@Z
200 0x4fe970 ?decodeString@Reader@Json@@AAE_NAAVToken@12@AAV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
201 0x4fef00 ?decodeUnicodeCodePoint@Reader@Json@@AAE_NAAVToken@12@AAPBDPBDAAI@Z
202 0x4ff330 ?decodeUnicodeEscapeSequence@Reader@Json@@AAE_NAAVToken@12@AAPBDPBDAAI@Z
203 0x50c3e0 ?decrement@ValueIteratorBase@Json@@IAEXXZ
204 0x604318 ?defaultRealPrecision@Value@Json@@2IB
205 0x50c3f0 ?demand@Value@Json@@QAEPAV12@PBD0@Z
206 0x50c4a0 ?deref@ValueIteratorBase@Json@@IAEAAVValue@2@XZ
207 0x50c4b0 ?deref@ValueIteratorBase@Json@@IBEABVValue@2@XZ
208 0x4f0790 ?dropNullPlaceholders@FastWriter@Json@@QAEXXZ
209 0x50c4c0 ?dupMeta@Value@Json@@AAEXABV12@@Z
210 0x50c590 ?dupPayload@Value@Json@@AAEXABV12@@Z
211 0x50c840 ?empty@Value@Json@@QBE_NXZ
212 0x4f07a0 ?enableYAMLCompatibility@FastWriter@Json@@QAEXXZ
213 0x50c870 ?end@Value@Json@@QAE?AVValueIterator@2@XZ
214 0x50c8b0 ?end@Value@Json@@QBE?AVValueConstIterator@2@XZ
215 0x50cae0 ?find@Value@Json@@QBEPBV12@PBD0@Z
216 0x50cc50 ?get@Value@Json@@QBE?AV12@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@ABV12@@Z
217 0x50cce0 ?get@Value@Json@@QBE?AV12@IABV12@@Z
218 0x50cd50 ?get@Value@Json@@QBE?AV12@PBD0ABV12@@Z
219 0x50cdc0 ?get@Value@Json@@QBE?AV12@PBDABV12@@Z
220 0x50ce50 ?getComment@Value@Json@@QBE?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@W4CommentPlacement@2@@Z
221 0x5006f0 ?getFormatedErrorMessages@Reader@Json@@QBE?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@XZ
222 0x500c40 ?getFormattedErrorMessages@Reader@Json@@QBE?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@XZ
223 0x501390 ?getLocationLineAndColumn@Reader@Json@@ABE?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@PBD@Z
224 0x501410 ?getLocationLineAndColumn@Reader@Json@@ABEXPBDAAH1@Z
225 0x50ce90 ?getMemberNames@Value@Json@@QBE?AV?$vector@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$allocator@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@std@@XZ
226 0x501490 ?getNextChar@Reader@Json@@AAEDXZ
227 0x50d080 ?getOffsetLimit@Value@Json@@QBEHXZ
228 0x50d090 ?getOffsetStart@Value@Json@@QBEHXZ
229 0x50d0a0 ?getString@Value@Json@@QBE_NPAPBD0@Z
230 0x5016f0 ?getStructuredErrors@Reader@Json@@QBE?AV?$vector@UStructuredError@Reader@Json@@V?$allocator@UStructuredError@Reader@Json@@@std@@@std@@XZ
231 0x501930 ?good@Reader@Json@@QBE_NXZ
232 0x50d130 ?hasComment@Value@Json@@QBE_NW4CommentPlacement@2@@Z
233 0x4f0890 ?hasCommentForValue@StyledStreamWriter@Json@@CA_NABVValue@2@@Z
234 0x4f08d0 ?hasCommentForValue@StyledWriter@Json@@CA_NABVValue@2@@Z
235 0x50d160 ?increment@ValueIteratorBase@Json@@IAEXXZ
236 0x4f0930 ?indent@StyledStreamWriter@Json@@AAEXXZ
237 0x4f0950 ?indent@StyledWriter@Json@@AAEXXZ
238 0x50d180 ?index@ValueIteratorBase@Json@@QBEIXZ
239 0x50d1c0 ?initBasic@Value@Json@@AAEXW4ValueType@2@_N@Z
240 0x50d260 ?insert@Value@Json@@QAE_NI$$QAV12@@Z
241 0x50d360 ?insert@Value@Json@@QAE_NIABV12@@Z
242 0x50d460 ?invalidPath@Path@Json@@CAXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@H@Z
243 0x4f0be0 ?isAllocated@Value@Json@@ABE_NXZ
244 0x50d470 ?isArray@Value@Json@@QBE_NXZ
245 0x50d480 ?isBool@Value@Json@@QBE_NXZ
246 0x50d490 ?isConvertibleTo@Value@Json@@QBE_NW4ValueType@2@@Z
247 0x50d690 ?isDouble@Value@Json@@QBE_NXZ
248 0x50d6b0 ?isEqual@ValueIteratorBase@Json@@IBE_NABV12@@Z
249 0x50d6d0 ?isInt64@Value@Json@@QBE_NXZ
250 0x50d730 ?isInt@Value@Json@@QBE_NXZ
251 0x50d7b0 ?isIntegral@Value@Json@@QBE_NXZ
252 0x50d800 ?isMember@Value@Json@@QBE_NABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
253 0x50d840 ?isMember@Value@Json@@QBE_NPBD0@Z
254 0x50d860 ?isMember@Value@Json@@QBE_NPBD@Z
255 0x4f0d70 ?isMultilineArray@StyledStreamWriter@Json@@AAE_NABVValue@2@@Z
256 0x4f0ef0 ?isMultilineArray@StyledWriter@Json@@AAE_NABVValue@2@@Z
257 0x50d890 ?isNull@Value@Json@@QBE_NXZ
258 0x50d8a0 ?isNumeric@Value@Json@@QBE_NXZ
259 0x50d8c0 ?isObject@Value@Json@@QBE_NXZ
260 0x50d8e0 ?isString@Value@Json@@QBE_NXZ
261 0x50d8f0 ?isUInt64@Value@Json@@QBE_NXZ
262 0x50d950 ?isUInt@Value@Json@@QBE_NXZ
263 0x50d9c0 ?isValidIndex@Value@Json@@QBE_NI@Z
264 0x50d9e0 ?key@ValueIteratorBase@Json@@QBE?AVValue@2@XZ
265 0x50dae0 ?make@Path@Json@@QBEAAVValue@2@AAV32@@Z
266 0x50db40 ?makePath@Path@Json@@AAEXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@ABV?$vector@PBVPathArgument@Json@@V?$allocator@PBVPathArgument@Json@@@std@@@4@@Z
267 0x501990 ?match@Reader@Json@@AAE_NPBDH@Z
268 0x604308 ?maxInt64@Value@Json@@2_JB
269 0x6042f4 ?maxInt@Value@Json@@2HB
270 0x6042e0 ?maxLargestInt@Value@Json@@2_JB
271 0x6042e8 ?maxLargestUInt@Value@Json@@2_KB
272 0x604310 ?maxUInt64@Value@Json@@2_KB
273 0x604320 ?maxUInt64AsDouble@Value@Json@@2NB
274 0x6042f8 ?maxUInt@Value@Json@@2IB
275 0x50de60 ?memberName@ValueIteratorBase@Json@@QBEPBDPAPBD@Z
276 0x50de90 ?memberName@ValueIteratorBase@Json@@QBEPBDXZ
277 0x604300 ?minInt64@Value@Json@@2_JB
278 0x6042f0 ?minInt@Value@Json@@2HB
279 0x6042d8 ?minLargestInt@Value@Json@@2_JB
280 0x50dea0 ?name@ValueIteratorBase@Json@@QBE?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@XZ
281 0x5019e0 ?newCharReader@CharReaderBuilder@Json@@UBEPAVCharReader@2@XZ
282 0x4f1180 ?newStreamWriter@StreamWriterBuilder@Json@@UBEPAVStreamWriter@2@XZ
283 0x501f70 ?normalizeEOL@Reader@Json@@CA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@PBD0@Z
284 0x66a1cc ?null@Value@Json@@2ABV12@B
285 0x66a1d0 ?nullRef@Value@Json@@2ABV12@B
286 0x50df00 ?nullSingleton@Value@Json@@SAABV12@XZ
287 0x4f18c0 ?omitEndingLineFeed@FastWriter@Json@@QAEXXZ
288 0x502610 ?parse@Reader@Json@@QAE_NAAV?$basic_istream@DU?$char_traits@D@std@@@std@@AAVValue@2@_N@Z
289 0x5026f0 ?parse@Reader@Json@@QAE_NABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAVValue@2@_N@Z
290 0x502750 ?parse@Reader@Json@@QAE_NPBD0AAVValue@2@_N@Z
291 0x502940 ?parseFromStream@Json@@YA_NABVFactory@CharReader@1@AAV?$basic_istream@DU?$char_traits@D@std@@@std@@PAVValue@1@PAV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@5@@Z
292 0x502bf0 ?pushError@Reader@Json@@QAE_NABVValue@2@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@0@Z
293 0x502d10 ?pushError@Reader@Json@@QAE_NABVValue@2@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
294 0x4f1af0 ?pushValue@StyledStreamWriter@Json@@AAEXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
295 0x4f1b50 ?pushValue@StyledWriter@Json@@AAEXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
296 0x5031a0 ?readArray@Reader@Json@@AAE_NAAVToken@12@@Z
297 0x503510 ?readCStyleComment@Reader@Json@@AAE_NXZ
298 0x503730 ?readComment@Reader@Json@@AAE_NXZ
299 0x503810 ?readCppStyleComment@Reader@Json@@AAE_NXZ
300 0x503940 ?readNumber@Reader@Json@@AAEXXZ
301 0x5041b0 ?readObject@Reader@Json@@AAE_NAAVToken@12@@Z
302 0x5047c0 ?readString@Reader@Json@@AAE_NXZ
303 0x504b90 ?readToken@Reader@Json@@AAE_NAAVToken@12@@Z
304 0x505280 ?readValue@Reader@Json@@AAE_NXZ
305 0x505760 ?recoverFromError@Reader@Json@@AAE_NW4TokenType@12@@Z
306 0x50e010 ?releasePayload@Value@Json@@AAEXXZ
307 0x50e060 ?removeIndex@Value@Json@@QAE_NIPAV12@@Z
308 0x50e320 ?removeMember@Value@Json@@QAEXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
309 0x50e340 ?removeMember@Value@Json@@QAEXPBD@Z
310 0x50e410 ?removeMember@Value@Json@@QAE_NABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@PAV12@@Z
311 0x50e450 ?removeMember@Value@Json@@QAE_NPBD0PAV12@@Z
312 0x50e540 ?removeMember@Value@Json@@QAE_NPBDPAV12@@Z
313 0x50e570 ?resize@Value@Json@@QAEXI@Z
314 0x50e7f0 ?resolve@Path@Json@@QBE?AVValue@2@ABV32@0@Z
315 0x50e940 ?resolve@Path@Json@@QBEABVValue@2@ABV32@@Z
316 0x50e9e0 ?resolveReference@Value@Json@@AAEAAV12@PBD0@Z
317 0x50ecc0 ?resolveReference@Value@Json@@AAEAAV12@PBD@Z
318 0x4f1e10 ?setComment@Value@Json@@QAEXPBDIW4CommentPlacement@2@@Z
319 0x4f1e50 ?setComment@Value@Json@@QAEXPBDW4CommentPlacement@2@@Z
320 0x50f0e0 ?setComment@Value@Json@@QAEXV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@W4CommentPlacement@2@@Z
321 0x505bf0 ?setDefaults@CharReaderBuilder@Json@@SAXPAVValue@2@@Z
322 0x4f1ea0 ?setDefaults@StreamWriterBuilder@Json@@SAXPAVValue@2@@Z
323 0x4f20a0 ?setIsAllocated@Value@Json@@AAEX_N@Z
324 0x50f340 ?setOffsetLimit@Value@Json@@QAEXH@Z
325 0x50f350 ?setOffsetStart@Value@Json@@QAEXH@Z
326 0x4f20c0 ?setType@Value@Json@@AAEXW4ValueType@2@@Z
327 0x50f360 ?size@Value@Json@@QBEIXZ
328 0x5062a0 ?skipCommentTokens@Reader@Json@@AAEXAAVToken@12@@Z
329 0x506550 ?skipSpaces@Reader@Json@@AAEXXZ
330 0x506580 ?strictMode@CharReaderBuilder@Json@@SAXPAVValue@2@@Z
331 0x506820 ?strictMode@Features@Json@@SA?AV12@XZ
332 0x50f4c0 ?swap@Value@Json@@QAEXAAV12@@Z
333 0x50f5e0 ?swapPayload@Value@Json@@QAEXAAV12@@Z
334 0x50f670 ?toStyledString@Value@Json@@QBE?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@XZ
335 0x50f880 ?type@Value@Json@@QBE?AW4ValueType@2@XZ
336 0x4f2210 ?unindent@StyledStreamWriter@Json@@AAEXXZ
337 0x4f2230 ?unindent@StyledWriter@Json@@AAEXXZ
338 0x506830 ?validate@CharReaderBuilder@Json@@QBE_NPAVValue@2@@Z
339 0x4f2250 ?validate@StreamWriterBuilder@Json@@QBE_NPAVValue@2@@Z
340 0x4f2890 ?valueToQuotedString@Json@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@PBD@Z
341 0x4f2fe0 ?valueToString@Json@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@H@Z
342 0x4f3000 ?valueToString@Json@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@I@Z
343 0x4f3070 ?valueToString@Json@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@NIW4PrecisionType@1@@Z
344 0x4f30a0 ?valueToString@Json@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@_J@Z
345 0x4f3170 ?valueToString@Json@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@_K@Z
346 0x4f31f0 ?valueToString@Json@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@_N@Z
347 0x50f890 ?what@Exception@Json@@UBEPBDXZ
348 0x4f3310 ?write@FastWriter@Json@@UAE?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@ABVValue@2@@Z
349 0x4f3360 ?write@StyledStreamWriter@Json@@QAEXAAV?$basic_ostream@DU?$char_traits@D@std@@@std@@ABVValue@2@@Z
350 0x4f3400 ?write@StyledWriter@Json@@UAE?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@ABVValue@2@@Z
351 0x4f38e0 ?writeArrayValue@StyledStreamWriter@Json@@AAEXABVValue@2@@Z
352 0x4f3d10 ?writeArrayValue@StyledWriter@Json@@AAEXABVValue@2@@Z
353 0x4f4380 ?writeCommentAfterValueOnSameLine@StyledStreamWriter@Json@@AAEXABVValue@2@@Z
354 0x4f4500 ?writeCommentAfterValueOnSameLine@StyledWriter@Json@@AAEXABVValue@2@@Z
355 0x4f47f0 ?writeCommentBeforeValue@StyledStreamWriter@Json@@AAEXABVValue@2@@Z
356 0x4f4940 ?writeCommentBeforeValue@StyledWriter@Json@@AAEXABVValue@2@@Z
357 0x4f4c60 ?writeIndent@StyledStreamWriter@Json@@AAEXXZ
358 0x4f4c90 ?writeIndent@StyledWriter@Json@@AAEXXZ
359 0x4f4ce0 ?writeString@Json@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@ABVFactory@StreamWriter@1@ABVValue@1@@Z
360 0x4f5390 ?writeValue@FastWriter@Json@@AAEXABVValue@2@@Z
361 0x4f56a0 ?writeValue@StyledStreamWriter@Json@@AAEXABVValue@2@@Z
362 0x4f5b10 ?writeValue@StyledWriter@Json@@AAEXABVValue@2@@Z
363 0x4f5fe0 ?writeWithIndent@StyledStreamWriter@Json@@AAEXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
364 0x4f6040 ?writeWithIndent@StyledWriter@Json@@AAEXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
.rsrc
.data
Hnf.tY
V|Z~j]=
N4`WA
1K?Dj
没有防病毒引擎扫描信息!

进程树


steamworks.exe, PID: 2628, 上一级进程 PID: 2240

访问主机纪录 (可点击查询WPING实时安全评级)

直接 IP 安全评级 地理位置
104.18.38.233 美国

TCP

源地址 源端口 目标地址 目标端口
192.168.122.201 49158 104.18.38.233 crt.usertrust.com 80
192.168.122.201 49161 23.209.84.17 80

UDP

源地址 源端口 目标地址 目标端口
192.168.122.201 53118 192.168.122.1 53
192.168.122.201 57526 192.168.122.1 53
192.168.122.201 63246 192.168.122.1 53

域名解析 (可点击查询WPING实时安全评级)

域名 安全评级 响应
crt.usertrust.com 未知 A 104.18.38.233
CNAME crt.comodoca.com
A 172.64.149.23
CNAME crt.comodoca.com.cdn.cloudflare.net
steamgogo.gtx3080ti.cc 未知 A 106.52.235.100

TCP

源地址 源端口 目标地址 目标端口
192.168.122.201 49158 104.18.38.233 crt.usertrust.com 80
192.168.122.201 49161 23.209.84.17 80

UDP

源地址 源端口 目标地址 目标端口
192.168.122.201 53118 192.168.122.1 53
192.168.122.201 57526 192.168.122.1 53
192.168.122.201 63246 192.168.122.1 53

HTTP 请求

URI HTTP数据
URL专业沙箱检测 -> http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt
GET /USERTrustRSAAddTrustCA.crt HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crt.usertrust.com

URL专业沙箱检测 -> http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip
GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1
Accept: */*
If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT
User-Agent: IPM
Host: acroipm.adobe.com
Connection: Keep-Alive
Cache-Control: no-cache

SMTP 流量

无SMTP流量.

IRC 流量

无IRC请求.

ICMP 流量

无ICMP流量.

CIF 报告

无 CIF 结果

网络警报

无警报

TLS

No TLS

Suricata HTTP

No Suricata HTTP

未发现网络提取文件
抱歉! 没有任何文件投放。
没有发现相似的分析.
HTML 总结报告
(需15-60分钟同步)
下载

Processing ( 43.366 seconds )

  • 12.832 NetworkAnalysis
  • 11.457 Suricata
  • 9.939 Static
  • 7.188 VirusTotal
  • 0.982 TargetInfo
  • 0.623 BehaviorAnalysis
  • 0.31 peid
  • 0.011 AnalysisInfo
  • 0.011 config_decoder
  • 0.011 Strings
  • 0.002 Memory

Signatures ( 6.861 seconds )

  • 5.256 network_http
  • 1.343 proprietary_url_bl
  • 0.033 api_spamming
  • 0.025 stealth_timeout
  • 0.023 stealth_decoy_document
  • 0.02 antiav_detectreg
  • 0.015 kovter_behavior
  • 0.014 antiemu_wine_func
  • 0.013 infostealer_browser_password
  • 0.012 proprietary_domain_bl
  • 0.011 injection_createremotethread
  • 0.009 infostealer_ftp
  • 0.007 injection_runpe
  • 0.006 antiav_detectfile
  • 0.005 anomaly_persistence_autorun
  • 0.005 infostealer_im
  • 0.004 antianalysis_detectreg
  • 0.004 geodo_banking_trojan
  • 0.004 infostealer_bitcoin
  • 0.004 ransomware_extensions
  • 0.004 ransomware_files
  • 0.003 infostealer_mail
  • 0.002 tinba_behavior
  • 0.002 rat_nanocore
  • 0.002 antiav_avast_libs
  • 0.002 mimics_filetime
  • 0.002 betabot_behavior
  • 0.002 reads_self
  • 0.002 antisandbox_sunbelt_libs
  • 0.002 antivm_vbox_files
  • 0.002 disables_browser_warn
  • 0.002 network_torgateway
  • 0.001 bootkit
  • 0.001 stealth_file
  • 0.001 antisandbox_sboxie_libs
  • 0.001 antiav_bitdefender_libs
  • 0.001 kibex_behavior
  • 0.001 antivm_generic_scsi
  • 0.001 antivm_generic_disk
  • 0.001 cerber_behavior
  • 0.001 virus
  • 0.001 hancitor_behavior
  • 0.001 antivm_parallels_keys
  • 0.001 antivm_xen_keys
  • 0.001 banker_zeus_mutex
  • 0.001 bot_drive
  • 0.001 bot_drive2
  • 0.001 browser_security
  • 0.001 modify_proxy
  • 0.001 disables_windows_defender
  • 0.001 proprietary_malicious_drop_executable_file_to_temp_folder
  • 0.001 proprietary_bad_drop
  • 0.001 network_cnc_http

Reporting ( 0.595 seconds )

  • 0.491 ReportHTMLSummary
  • 0.104 Malheur
Task ID 744461
Mongo ID 662f8f8edc327b46c0811184
Cuckoo release 1.4-Maldun