分析类型 | 虚拟机标签 | 开始时间 | 结束时间 | 持续时间 |
---|---|---|---|---|
文件 (Windows) | win7-sp1-x64-shaapp03-1 | 2024-04-25 18:18:52 | 2024-04-25 18:19:50 | 58 秒 |
文件名 | 查询电脑端001.exe |
---|---|
文件大小 | 670208 字节 |
文件类型 | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
MD5 | 362b61ee9adc0f7c8583ebf06d20a0e8 |
SHA1 | 5699171720e84738fcd3968639490a628fb9979d |
SHA256 | 947d371313978526863fec807e991bf4b31a7f1f1d8d081769068ffe27ee899b |
SHA512 | edbb111f4d09460ba594fec65cc98c3cc34724e87e548713844670df959d643509a68e419adbc018f6df4ca0e210746f09ac6c6433cdcf91bd91b2dbc4fab6cd |
CRC32 | 39D8CE3E |
Ssdeep | 3072:91I2NxfpUdddddwddR4ccaZbuJjjUouU9LIe3HsS3r7L5s55ROhFYyFtj:1fnqjKU9LjHsS3r7u55RO/YyFt |
Yara | 登录查看Yara规则 |
找不到该样本 提交漏报 |
直接 | IP | 安全评级 | 地理位置 |
---|---|---|---|
否 | 183.66.100.32 | 中国 |
域名 | 安全评级 | 响应 |
---|---|---|
jkjkdll3-1323575486.cos.ap-chengdu.myqcloud.com | 未知 |
A 183.66.100.32 CNAME cd.file.myqcloud.com A 183.66.100.19 |
初始地址 | 0x00400000 |
---|---|
入口地址 | 0x00434a4e |
声明校验值 | 0x00000000 |
实际校验值 | 0x000acc94 |
最低操作系统版本要求 | 4.0 |
编译时间 | 2072-08-28 11:05:22 |
载入哈希 | f34d5f2d4577ed6d9ceec516c1f5a744 |
图标 | |
图标精确哈希值 | 11d725c5772cd0d0425f76bddad3a344 |
图标相似性哈希值 | 5f52dcee58fa8c0f73f7151bb8eb066a |
Translation | |
---|---|
LegalCopyright | |
Assembly Version | |
InternalName | |
FileVersion | |
CompanyName | |
LegalTrademarks | |
Comments | |
ProductName | |
ProductVersion | |
FileDescription | |
OriginalFilename |
名称 | 虚拟地址 | 虚拟大小 | 原始数据大小 | 特征 | 熵(Entropy) |
---|---|---|---|---|---|
.text | 0x00002000 | 0x00032a54 | 0x00032c00 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ | 2.78 |
.rsrc | 0x00036000 | 0x00070858 | 0x00070a00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 5.69 |
.reloc | 0x000a8000 | 0x0000000c | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ | 0.10 |
名称 | 偏移量 | 大小 | 语言 | 子语言 | 熵(Entropy) | 文件类型 |
---|---|---|---|---|---|---|
RT_ICON | 0x000a5e18 | 0x00000468 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 5.77 | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000a5e18 | 0x00000468 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 5.77 | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000a5e18 | 0x00000468 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 5.77 | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000a5e18 | 0x00000468 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 5.77 | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000a5e18 | 0x00000468 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 5.77 | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000a5e18 | 0x00000468 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 5.77 | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000a5e18 | 0x00000468 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 5.77 | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000a5e18 | 0x00000468 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 5.77 | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000a5e18 | 0x00000468 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 5.77 | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000a5e18 | 0x00000468 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 5.77 | GLS_BINARY_LSB_FIRST |
RT_GROUP_ICON | 0x000a6290 | 0x00000092 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 3.10 | MS Windows icon resource - 10 icons, 256x256 |
RT_VERSION | 0x000a6334 | 0x00000324 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 3.27 | data |
RT_MANIFEST | 0x000a6668 | 0x000001ea | LANG_NEUTRAL | SUBLANG_NEUTRAL | 5.00 | XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators |
名称 | APP |
---|---|
版本 | 6.0.0.0 |
名称 | 版本 |
---|---|
mscorlib | 4.0.0.0 |
System | 4.0.0.0 |
System.Drawing | 4.0.0.0 |
System.Windows.Forms | 4.0.0.0 |
System.Management.Automation | 3.0.0.0 |
类型 | 名称 | 值 |
---|---|---|
Assembly | [mscorlib]System.Reflection.AssemblyTitleAttribute | TKRevi |
Assembly | [mscorlib]System.Reflection.AssemblyDescriptionAttribute | TKRevi |
Assembly | [mscorlib]System.Reflection.AssemblyCompanyAttribute | TKRevi |
Assembly | [mscorlib]System.Reflection.AssemblyProductAttribute | TKRevi |
Assembly | [mscorlib]System.Reflection.AssemblyCopyrightAttribute | TKRevi |
Assembly | [mscorlib]System.Reflection.AssemblyTrademarkAttribute | TKRevi |
Assembly | [mscorlib]System.Runtime.InteropServices.GuidAttribute | d33062c9-bea7-4656-b395-77b7014fb2 |
Assembly | [mscorlib]System.Reflection.AssemblyFileVersionAttribute | 6.0.0 |
装载 | 类型名称 |
---|---|
System | System.CodeDom.Compiler.GeneratedCodeAttribute |
System | System.ComponentModel.Container |
System | System.ComponentModel.EditorBrowsableAttribute |
System | System.ComponentModel.EditorBrowsableState |
System | System.ComponentModel.IContainer |
System | System.Configuration.ApplicationSettingsBase |
System | System.Configuration.SettingsBase |
System | System.Diagnostics.Process |
System | System.Diagnostics.ProcessStartInfo |
System | System.Net.WebClient |
System.Drawing | System.Drawing.Icon |
System.Drawing | System.Drawing.Size |
System.Drawing | System.Drawing.SizeF |
System.Management.Automation | System.Management.Automation.PSObject |
System.Management.Automation | System.Management.Automation.Runspaces.CommandCollection |
System.Management.Automation | System.Management.Automation.Runspaces.Pipeline |
System.Management.Automation | System.Management.Automation.Runspaces.Runspace |
System.Management.Automation | System.Management.Automation.Runspaces.RunspaceFactory |
System.Windows.Forms | System.Windows.Forms.Application |
System.Windows.Forms | System.Windows.Forms.AutoScaleMode |
System.Windows.Forms | System.Windows.Forms.ContainerControl |
System.Windows.Forms | System.Windows.Forms.ContextMenuStrip |
System.Windows.Forms | System.Windows.Forms.Control |
System.Windows.Forms | System.Windows.Forms.Form |
mscorlib | System.Byte |
mscorlib | System.Collections.Generic.IEnumerator`1 |
mscorlib | System.Collections.IEnumerator |
mscorlib | System.Collections.ObjectModel.Collection`1 |
mscorlib | System.Console |
mscorlib | System.Convert |
mscorlib | System.Diagnostics.DebuggableAttribute |
mscorlib | System.Diagnostics.DebuggableAttribute/DebuggingModes |
mscorlib | System.Diagnostics.DebuggerNonUserCodeAttribute |
mscorlib | System.Environment |
mscorlib | System.EventArgs |
mscorlib | System.EventHandler |
mscorlib | System.Exception |
mscorlib | System.Globalization.CultureInfo |
mscorlib | System.IDisposable |
mscorlib | System.IO.Directory |
mscorlib | System.IO.DirectoryInfo |
mscorlib | System.IO.File |
mscorlib | System.IO.Stream |
mscorlib | System.Object |
mscorlib | System.OperatingSystem |
mscorlib | System.Reflection.Assembly |
mscorlib | System.Reflection.AssemblyCompanyAttribute |
mscorlib | System.Reflection.AssemblyConfigurationAttribute |
mscorlib | System.Reflection.AssemblyCopyrightAttribute |
mscorlib | System.Reflection.AssemblyDescriptionAttribute |
mscorlib | System.Reflection.AssemblyFileVersionAttribute |
mscorlib | System.Reflection.AssemblyProductAttribute |
mscorlib | System.Reflection.AssemblyTitleAttribute |
mscorlib | System.Reflection.AssemblyTrademarkAttribute |
mscorlib | System.Resources.ResourceManager |
mscorlib | System.Runtime.CompilerServices.CompilationRelaxationsAttribute |
mscorlib | System.Runtime.CompilerServices.CompilerGeneratedAttribute |
mscorlib | System.Runtime.CompilerServices.RuntimeCompatibilityAttribute |
mscorlib | System.Runtime.InteropServices.ComVisibleAttribute |
mscorlib | System.Runtime.InteropServices.GuidAttribute |
mscorlib | System.Runtime.Versioning.TargetFrameworkAttribute |
mscorlib | System.RuntimeTypeHandle |
mscorlib | System.STAThreadAttribute |
mscorlib | System.Security.Principal.WindowsBuiltInRole |
mscorlib | System.Security.Principal.WindowsIdentity |
mscorlib | System.Security.Principal.WindowsPrincipal |
mscorlib | System.String |
mscorlib | System.Text.Encoding |
mscorlib | System.Text.StringBuilder |
mscorlib | System.Threading.Thread |
mscorlib | System.Type |
mscorlib | System.Version |
直接 | IP | 安全评级 | 地理位置 |
---|---|---|---|
否 | 183.66.100.32 | 中国 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 49161 | 183.66.100.32 jkjkdll3-1323575486.cos.ap-chengdu.myqcloud.com | 443 |
192.168.122.201 | 49160 | 23.15.196.139 | 80 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 56270 | 192.168.122.1 | 53 |
192.168.122.201 | 59401 | 192.168.122.1 | 53 |
192.168.122.201 | 59906 | 192.168.122.1 | 53 |
域名 | 安全评级 | 响应 |
---|---|---|
jkjkdll3-1323575486.cos.ap-chengdu.myqcloud.com | 未知 |
A 183.66.100.32 CNAME cd.file.myqcloud.com A 183.66.100.19 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 49161 | 183.66.100.32 jkjkdll3-1323575486.cos.ap-chengdu.myqcloud.com | 443 |
192.168.122.201 | 49160 | 23.15.196.139 | 80 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 56270 | 192.168.122.1 | 53 |
192.168.122.201 | 59401 | 192.168.122.1 | 53 |
192.168.122.201 | 59906 | 192.168.122.1 | 53 |
URI | HTTP数据 |
---|---|
URL专业沙箱检测 -> http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip | GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1 Accept: */* If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT User-Agent: IPM Host: acroipm.adobe.com Connection: Keep-Alive Cache-Control: no-cache |
无SMTP流量.
无IRC请求.
无ICMP流量.
无 CIF 结果
无警报
Timestamp | Source IP | Source Port | Destination IP | Destination Port | Version | Issuer | Subject | Fingerprint |
---|---|---|---|---|---|---|---|---|
2024-04-25 18:19:29.534314+0800 | 192.168.122.201 | 49161 | 183.66.100.32 | 443 | TLS 1.2 | C=BE, O=GlobalSign nv-sa, CN=GlobalSign Organization Validation CA - SHA256 - G3 | C=CN, ST=Guangdong, L=Shenzhen, O=Shenzhen Tencent Computer Systems Company Limited, CN=*.cos.ap-chengdu.myqcloud.com | aa:f6:6a:f6:b5:ea:9f:c6:e8:7b:d5:98:a3:39:06:39:b2:65:c2:7d |
No Suricata HTTP
HTML 总结报告 (需15-60分钟同步) |
下载 |
---|
Task ID | 744310 |
---|---|
Mongo ID | 662a2e927e769a5b6bbf311c |
Cuckoo release | 1.4-Maldun |