分析任务

分析类型 虚拟机标签 开始时间 结束时间 持续时间
URL win7-sp1-x64-hpdapp01-1 2018-03-19 12:36:09 2018-03-19 12:38:39 150 秒

魔盾分数

0.05

正常的

URL详细信息

URL
URL专业沙箱检测 -> http://flare.jisusaiche.biz

登录查看威胁特征

运行截图


访问主机纪录 (可点击查询WPING实时安全评级)

直接 IP 安全评级 地理位置
104.28.20.78 美国
122.224.45.50 中国

域名解析 (可点击查询WPING实时安全评级)

域名 安全评级 响应
flare.jisusaiche.biz A 104.28.20.78
A 104.28.21.78
www.microsoft.com CNAME e13678.ca.s.tl88.net
A 122.224.45.50
CNAME www.microsoft.com-c-3.edgekey.net.globalredir.akadns.net
CNAME www.microsoft.com-c-3.edgekey.net

摘要

登录查看详细行为信息

WHOIS 信息

Name: None
Country: None
State: None
City: None
ZIP Code: None
Address: None

Orginization: None
Domain Name(s):
    jisusaiche.biz
    JISUSAICHE.BIZ
Creation Date:
    None
Updated Date:
    None
Expiration Date:
    None
Email(s):
    None

Registrar(s):
    None
Name Server(s):
    dana.ns.cloudflare.com
    beau.ns.cloudflare.com
    BEAU.NS.CLOUDFLARE.COM
    DANA.NS.CLOUDFLARE.COM
Referral URL(s):
    None
防病毒引擎/厂商 网站安全分析
CLEAN MX Clean Site
DNS8 Clean Site
VX Vault Clean Site
ZDB Zeus Clean Site
Tencent Clean Site
Netcraft Unrated Site
desenmascara_me Clean Site
Dr_Web Clean Site
PhishLabs Unrated Site
Zerofox Clean Site
K7AntiVirus Clean Site
Virusdie External Site Scan Clean Site
SCUMWARE_org Clean Site
Quttera Clean Site
AegisLab WebGuard Clean Site
MalwareDomainList Clean Site
ZeusTracker Clean Site
zvelo Clean Site
Google Safebrowsing Clean Site
Kaspersky Clean Site
BitDefender Clean Site
Certly Clean Site
G-Data Clean Site
C-SIRT Clean Site
OpenPhish Clean Site
Malware Domain Blocklist Clean Site
MalwarePatrol Clean Site
Webutation Clean Site
Trustwave Clean Site
Web Security Guard Clean Site
CyRadar Clean Site
ADMINUSLabs Clean Site
Malwarebytes hpHosts Clean Site
Opera Clean Site
AlienVault Clean Site
Emsisoft Clean Site
Malc0de Database Clean Site
Spam404 Clean Site
Phishtank Clean Site
Malwared Clean Site
Avira Clean Site
NotMining Unrated Site
CyberCrime Clean Site
Antiy-AVL Clean Site
Forcepoint ThreatSeeker Clean Site
FraudSense Clean Site
malwares_com URL checker Clean Site
Comodo Site Inspector Clean Site
Malekal Clean Site
ESET Clean Site
Sophos Unrated Site
Yandex Safebrowsing Clean Site
SecureBrain Clean Site
Nucleon Clean Site
Sucuri SiteCheck Clean Site
Blueliv Clean Site
ZCloudsec Clean Site
AutoShun Unrated Site
ThreatHive Clean Site
FraudScore Clean Site
Rising Clean Site
URLQuery Unrated Site
StopBadware Unrated Site
Fortinet Clean Site
ZeroCERT Clean Site
Baidu-International Clean Site
securolytics Clean Site

进程树


iexplore.exe, PID: 2232, 上一级进程 PID: 1236
iexplore.exe, PID: 2380, 上一级进程 PID: 2232

访问主机纪录 (可点击查询WPING实时安全评级)

直接 IP 安全评级 地理位置
104.28.20.78 美国
122.224.45.50 中国

TCP

源地址 源端口 目标地址 目标端口
192.168.122.201 49160 104.28.20.78 flare.jisusaiche.biz 80
192.168.122.201 49161 104.28.20.78 flare.jisusaiche.biz 80
192.168.122.201 49163 122.224.45.50 www.microsoft.com 80

UDP

源地址 源端口 目标地址 目标端口
192.168.122.201 55816 192.168.122.1 53
192.168.122.201 63248 192.168.122.1 53
192.168.122.201 64412 192.168.122.1 53

域名解析 (可点击查询WPING实时安全评级)

域名 安全评级 响应
flare.jisusaiche.biz A 104.28.20.78
A 104.28.21.78
www.microsoft.com CNAME e13678.ca.s.tl88.net
A 122.224.45.50
CNAME www.microsoft.com-c-3.edgekey.net.globalredir.akadns.net
CNAME www.microsoft.com-c-3.edgekey.net

TCP

源地址 源端口 目标地址 目标端口
192.168.122.201 49160 104.28.20.78 flare.jisusaiche.biz 80
192.168.122.201 49161 104.28.20.78 flare.jisusaiche.biz 80
192.168.122.201 49163 122.224.45.50 www.microsoft.com 80

UDP

源地址 源端口 目标地址 目标端口
192.168.122.201 55816 192.168.122.1 53
192.168.122.201 63248 192.168.122.1 53
192.168.122.201 64412 192.168.122.1 53

HTTP 请求

URI HTTP数据
URL专业沙箱检测 -> http://flare.jisusaiche.biz/
GET / HTTP/1.1
Accept: */*
Referer: http://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=17&ved=0CCEQfjUU56UWl2VXhpcXNibVN3eldMRnhO&url=http%3A%2F%2Fflare.jisusaiche.biz&ei=UEVSalNtSVl6SEd3&usg=AFQjRFdrY0FveHhnUEtP
Accept-Language: zh-cn
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Accept-Encoding: gzip, deflate
Host: flare.jisusaiche.biz
Connection: Keep-Alive

URL专业沙箱检测 -> http://flare.jisusaiche.biz/favicon.ico
GET /favicon.ico HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Host: flare.jisusaiche.biz
Connection: Keep-Alive
Cookie: __cfduid=d07c72d9727b67aac8c1db01610658cb61521434197

URL专业沙箱检测 -> http://www.microsoft.com/
GET / HTTP/1.1
Host: www.microsoft.com
Connection: Close

SMTP 流量

无SMTP流量.

IRC 流量

无IRC请求.

ICMP 流量

无ICMP流量.

CIF 报告

无 CIF 结果

网络警报

Timestamp Source IP Source Port Destination IP Destination Port Protocol SID Signature Category
2018-03-19 12:37:17.771298+0800 122.224.45.50 80 192.168.122.201 49163 TCP 2012692 ET POLICY Microsoft user-agent automated process response to automated request A Network Trojan was detected

TLS

No TLS

Suricata HTTP

No Suricata HTTP

未发现网络提取文件
文件名 {0EDE0244-2B2F-11E8-AB96-52540022444F}.dat
相关文件
C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0EDE0244-2B2F-11E8-AB96-52540022444F}.dat
文件大小 4608 字节
文件类型 Composite Document File V2 Document, Cannot read section info
MD5 c87157318151d61cf8b4ce79852aa9b0
SHA1 a0b3318f072a0850569d60097a725172ab3e40ba
SHA256 bf4e3f2d6440f876f1949dae0680acf5204ace3c14331b9743594c3857d97da7
CRC32 54E7E936
Ssdeep 12:rlfFQhrEgmfR16FJrEgmf91qjNlYfOo3+/Nlk89oxMZklp:rAGsGwNljowNlk8oKZk
下载提交魔盾安全分析
文件名 favicon[1].ico
相关文件
C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\favicon[1].ico
文件大小 1150 字节
文件类型 MS Windows icon resource - 1 icon, 16x16
MD5 eea497b7602f3f6a8764df09b0f28222
SHA1 7bae94a7e1a9faad916afff4335b95b1c7db56c5
SHA256 72f15faa8814bf2dba9bf5823120f602145ba5ecc59da412ea59d528861a2055
CRC32 98BA455E
Ssdeep 24:1QlO1Sp4Utxhg4gCde6jLraQoHIaV3Sc+FVq:W41G4Utzg4g8XqQra4jq
下载提交魔盾安全分析
文件名 index.dat
相关文件
C:\Users\test\AppData\Local\Microsoft\Feeds Cache\index.dat
文件大小 32768 字节
文件类型 Internet Explorer cache file version Ver 5.2
MD5 0aee387ca0a52dcdd8f8a29ea76edb42
SHA1 5df81547dcadb2a7b8bc689da8e1383ba1a84cb9
SHA256 c31bc37e102b70a472837d530ec80bdaea28b0fefda3e9aa8c8cda98c4200c4e
CRC32 B451CA0B
Ssdeep 12:qjtSaFpbZli3zIoYDPO7em4GZj03W/cKYDPOCG5A30WUsOXQDG9YRm4GZ5:qj4avEIoYTCebGZ7ZYTlEJ0oQQ4bGZ
魔盾安全分析结果 2.0分析时间:2016-11-06 20:10:20查看分析报告
下载提交魔盾安全分析
文件名 index.dat
相关文件
C:\Users\test\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012018031920180320\index.dat
文件大小 32768 字节
文件类型 Internet Explorer cache file version Ver 5.2
MD5 2e432e265c61a22c459c7d8cb2638334
SHA1 241542a75e73bfe18024f7c9efb29ca2839bfdba
SHA256 9a56ea493609b1a27aaf8f7c04b7ddd8397accc4ab212e11e9725522e19eae2e
CRC32 65A7CCD3
Ssdeep 6:qjyxXKCSBQ37kO4eFHT4WlN+XssfU37kO2XFHT4Wlz+Xssf:qjRpQ37V1kiN+rs37V2Vkiz+r
下载提交魔盾安全分析
文件名 RecoveryStore.{0EDE0243-2B2F-11E8-AB96-52540022444F}.dat
相关文件
C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{0EDE0243-2B2F-11E8-AB96-52540022444F}.dat
文件大小 3584 字节
文件类型 Composite Document File V2 Document, Cannot read section info
MD5 f185e059b7ad070f543a0e471875e62a
SHA1 a8577eb985076e4d230073ffc01d0f5f8d44da30
SHA256 e8040e6115031229d6662dbceb8d9751580a395db2430c082731658bb84c4a3f
CRC32 9876A84B
Ssdeep 12:rl0YmGF2arEg5+IaCrI017+FTDrEgmf+IaCy8qgQNlTqo7K2qi2yl:rIa5/cGv/TQNlWoxf2m
下载提交魔盾安全分析
文件名 test@jisusaiche[1].txt
相关文件
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\test@jisusaiche[1].txt
文件大小 116 字节
文件类型 ASCII text
MD5 a33f5c4323f303f65c88137840b782f6
SHA1 f043f3a0826b3e54c377d629ac6fefe9fa41396f
SHA256 5465d7e5a53d9a68df34e23787fa471ddd02cbc58240486793d334ca49df61f5
CRC32 AF2821A2
Ssdeep 3:GmM/57vEYHsMTsQ4WF7WtsfGsOCQo7VIQoPv:XM/VEhUpWtsf1Qo2zX
下载提交魔盾安全分析显示文本
__cfduid
d07c72d9727b67aac8c1db01610658cb61521434197
jisusaiche.biz/
9216
1453471872
30727693
3740959392
30654323
*
文件名 index.dat
相关文件
C:\Users\test\AppData\Roaming\Microsoft\Windows\IECompatCache\index.dat
文件大小 65536 字节
文件类型 Internet Explorer cache file version Ver 5.2
MD5 191d3d20f356bf520a7d1ed07b1bc08b
SHA1 bdba37ad96d8801e8d2c9e30e68afaf3822b0e4a
SHA256 d2eae7eeb07f08972ec78e59eaf73b6cfa48e92121748f61a394a28e33e36788
CRC32 BFF870C9
Ssdeep 384:wEEG/+oBMgfh3+EIOTcxi8kB+JuE1uPFykblh2F/0mjv3Bw2LI/u1sVdvM2zLOY4:wEEG/+xo
下载提交魔盾安全分析
HTML 总结报告
(需15-60分钟同步)
下载

Processing ( 28.944 seconds )

  • 12.871 Suricata
  • 10.857 NetworkAnalysis
  • 2.257 Static
  • 1.464 BehaviorAnalysis
  • 1.169 VirusTotal
  • 0.234 AnalysisInfo
  • 0.05 Dropped
  • 0.037 Debug
  • 0.005 Memory

Signatures ( 3.6 seconds )

  • 2.182 md_url_bl
  • 0.369 md_bad_drop
  • 0.222 antiav_detectreg
  • 0.084 stealth_timeout
  • 0.082 infostealer_ftp
  • 0.061 api_spamming
  • 0.049 antivm_generic_scsi
  • 0.048 infostealer_im
  • 0.046 antianalysis_detectreg
  • 0.028 infostealer_mail
  • 0.025 stealth_file
  • 0.024 antivm_generic_services
  • 0.019 md_domain_bl
  • 0.014 antivm_generic_disk
  • 0.014 antiav_detectfile
  • 0.014 geodo_banking_trojan
  • 0.013 persistence_autorun
  • 0.012 betabot_behavior
  • 0.012 mimics_filetime
  • 0.012 vawtrak_behavior
  • 0.011 kibex_behavior
  • 0.011 antivm_parallels_keys
  • 0.011 antivm_xen_keys
  • 0.011 darkcomet_regkeys
  • 0.01 virus
  • 0.009 bootkit
  • 0.009 infostealer_bitcoin
  • 0.007 antiemu_wine_func
  • 0.007 antivm_generic_diskreg
  • 0.007 ransomware_files
  • 0.007 recon_fingerprint
  • 0.006 andromeda_behavior
  • 0.006 hancitor_behavior
  • 0.006 infostealer_browser_password
  • 0.006 antidbg_windows
  • 0.006 kovter_behavior
  • 0.006 antivm_vbox_files
  • 0.006 ransomware_extensions
  • 0.005 disables_browser_warn
  • 0.004 dridex_behavior
  • 0.004 injection_createremotethread
  • 0.004 Locky_behavior
  • 0.004 antisandbox_productid
  • 0.004 antivm_vbox_keys
  • 0.004 antivm_vmware_keys
  • 0.003 tinba_behavior
  • 0.003 rat_nanocore
  • 0.003 antivm_vbox_libs
  • 0.003 antivm_vmware_events
  • 0.003 injection_runpe
  • 0.003 cryptowall_behavior
  • 0.003 antivm_xen_keys
  • 0.003 antivm_hyperv_keys
  • 0.003 antivm_vbox_acpi
  • 0.003 antivm_vpc_keys
  • 0.003 browser_security
  • 0.003 bypass_firewall
  • 0.003 network_torgateway
  • 0.003 packer_armadillo_regkey
  • 0.002 antiav_avast_libs
  • 0.002 stack_pivot
  • 0.002 antisandbox_sunbelt_libs
  • 0.002 dyre_behavior
  • 0.002 shifu_behavior
  • 0.002 cerber_behavior
  • 0.002 antidbg_devices
  • 0.002 antivm_generic_bios
  • 0.002 antivm_generic_cpu
  • 0.002 antivm_generic_system
  • 0.002 ie_martian_children
  • 0.002 recon_programs
  • 0.001 hawkeye_behavior
  • 0.001 network_tor
  • 0.001 persistence_bootexecute
  • 0.001 rat_luminosity
  • 0.001 antivm_vmware_libs
  • 0.001 antivm_vbox_window
  • 0.001 injection_explorer
  • 0.001 stealth_network
  • 0.001 modifies_desktop_wallpaper
  • 0.001 kazybot_behavior
  • 0.001 antisandbox_sboxie_libs
  • 0.001 antiav_bitdefender_libs
  • 0.001 chimera_behavior
  • 0.001 exec_crash
  • 0.001 ursnif_behavior
  • 0.001 ispy_behavior
  • 0.001 antianalysis_detectfile
  • 0.001 antivm_vmware_files
  • 0.001 banker_zeus_mutex
  • 0.001 bot_drive
  • 0.001 bot_drive2
  • 0.001 browser_addon
  • 0.001 codelux_behavior
  • 0.001 disables_system_restore
  • 0.001 disables_windows_defender
  • 0.001 modify_security_center_warnings
  • 0.001 modify_uac_prompt
  • 0.001 office_security
  • 0.001 rat_pcclient
  • 0.001 rat_spynet
  • 0.001 stealth_hiddenreg
  • 0.001 stealth_hide_notifications
  • 0.001 targeted_flame

Reporting ( 0.551 seconds )

  • 0.551 ReportHTMLSummary
Task ID 139120
Mongo ID 5aaf3ef82e06336c471e79aa
Cuckoo release 1.4-Maldun