分析类型 | 虚拟机标签 | 开始时间 | 结束时间 | 持续时间 |
---|---|---|---|---|
文件 (Windows) | win7-sp1-x64-shaapp02-1 | 2024-04-26 09:46:12 | 2024-04-26 09:48:23 | 131 秒 |
文件名 | winsharedutils64.dll |
---|---|
文件大小 | 115200 字节 |
文件类型 | PE32+ executable (DLL) (console) x86-64, for MS Windows |
MD5 | e378c5e23a8066f0fb9971c59eed51d5 |
SHA1 | fcc390772ae140da49587bc082f53b3bb343f533 |
SHA256 | 0128b8b83d9ac20b194b6319987968b2b64b239c7308db7bbe25b56872eddcaa |
SHA512 | 36c88cd2654b2895e8240764345a03fbc8bbca5d491820aa76ca9bc9dd8125763bee523a146aa1fd6da1e488d781a5b40c5b6d8ee692b222e24ab03b550f9523 |
CRC32 | 97B1D6EC |
Ssdeep | 3072:E3cC5UIdAurYS+/Or0OPwOVSo2iRnSVrWfr24Ru:E3cC/dAusS90OPrV+iRnsWtR |
Yara | 登录查看Yara规则 |
找不到该样本 提交漏报 |
无主机纪录.
无域名信息.
初始地址 | 0x180000000 |
---|---|
入口地址 | 0x180008ba4 |
声明校验值 | 0x00000000 |
实际校验值 | 0x0002b583 |
最低操作系统版本要求 | 6.0 |
编译时间 | 2024-04-26 07:40:22 |
载入哈希 | d404dd21218d9e6c6b73f277e6c778ff |
导出DLL库名称 | \x31\x31\x31\x31\x31\x39\x31\x31\x31\x31\x31\x31\x31\x31\x35\x35\x34\x31\x31\x31 |
名称 | 虚拟地址 | 虚拟大小 | 原始数据大小 | 特征 | 熵(Entropy) |
---|---|---|---|---|---|
.text | 0x00001000 | 0x00011fd8 | 0x00012000 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ | 6.35 |
.rdata | 0x00013000 | 0x00007a36 | 0x00007c00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 4.79 |
.data | 0x0001b000 | 0x000010c0 | 0x00000600 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 3.04 |
.pdata | 0x0001d000 | 0x00001434 | 0x00001600 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 4.70 |
.rsrc | 0x0001f000 | 0x000001e0 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 4.72 |
.reloc | 0x00020000 | 0x00000250 | 0x00000400 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ | 3.87 |
序列 | 地址 | 名称 |
---|---|---|
1 | 0x180003560 | GetLnkTargetPath |
2 | 0x180003d30 | GetProcessMute |
3 | 0x1800010e0 | Is64bit |
4 | 0x180004d30 | SAPI_List |
5 | 0x180004e70 | SAPI_Speak |
6 | 0x180003f50 | SetProcessMute |
7 | 0x180002d60 | WriteMemoryCallback |
8 | 0x180002e00 | WriteMemoryToQueue |
9 | 0x180001800 | _SetTheme |
10 | 0x180002ec0 | c_free |
11 | 0x1800033a0 | clipboard_get |
12 | 0x180003490 | clipboard_set |
13 | 0x180007e60 | endmaglistener |
14 | 0x180007850 | extracticon2data |
15 | 0x180002ed0 | free_all |
16 | 0x180002ee0 | freestringlist |
17 | 0x180002f40 | freewstringlist |
18 | 0x180001160 | getpidhwndfirst |
19 | 0x180005d20 | html_navigate |
20 | 0x180005d30 | html_new |
21 | 0x180005fb0 | html_release |
22 | 0x180005fc0 | html_resize |
23 | 0x1800019a0 | isDark |
24 | 0x180001190 | letfullscreen |
25 | 0x180003b40 | levenshtein_distance |
26 | 0x180003b60 | levenshtein_ratio |
27 | 0x180002fa0 | lockedqueuecreate |
28 | 0x180003050 | lockedqueueempty |
29 | 0x1800030b0 | lockedqueuefree |
30 | 0x180003110 | lockedqueueget |
31 | 0x1800032b0 | lockedqueuepush |
32 | 0x180005590 | mecab_end |
33 | 0x1800055b0 | mecab_init |
34 | 0x1800058b0 | mecab_parse |
35 | 0x180002350 | otsu_binary |
36 | 0x180001280 | pid_running |
37 | 0x180001c10 | queryversion |
38 | 0x1800012d0 | recoverwindow |
39 | 0x180001360 | showintab |
40 | 0x180001650 | startdarklistener |
41 | 0x180007e90 | startmaglistener |
无主机纪录.
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 49160 | 23.213.161.8 | 80 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 63246 | 192.168.122.1 | 53 |
无域名信息.
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 49160 | 23.213.161.8 | 80 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 63246 | 192.168.122.1 | 53 |
URI | HTTP数据 |
---|---|
URL专业沙箱检测 -> http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip | GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1 Accept: */* If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT User-Agent: IPM Host: acroipm.adobe.com Connection: Keep-Alive Cache-Control: no-cache |
无SMTP流量.
无IRC请求.
无ICMP流量.
无 CIF 结果
无警报
No TLS
No Suricata HTTP
HTML 总结报告 (需15-60分钟同步) |
下载 |
---|
Task ID | 744328 |
---|---|
Mongo ID | 662b0821dc327b93ab415c7e |
Cuckoo release | 1.4-Maldun |