分析类型 | 虚拟机标签 | 开始时间 | 结束时间 | 持续时间 |
---|---|---|---|---|
文件 (Windows) | win7-sp1-x64-shaapp01-2 | 2018-05-22 11:22:11 | 2018-05-22 11:24:30 | 139 秒 |
文件名 | QQKLB-SSZanV3.0.2_Goyt.exe |
---|---|
文件大小 | 692224 字节 |
文件类型 | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
MD5 | 214ed0d4a0fd128cb55acba877346c21 |
SHA1 | ad11a61ad286904f474f1d87063913dcfcddc86d |
SHA256 | ee54d9305b034b9d7c7971cf6a7a3c48a5f7dc69dff9db88ad47b1fc6e82b944 |
SHA512 | db3accfb52e5e5e8c207557e1409a44d7f3175d6b9c391901e578e3c603d69911e6321a6dc9e7cc5bdf88729366770de3f253fa841da569559b6e265d7fb8692 |
CRC32 | 5CC8E600 |
Ssdeep | 12288:6fjA9nedi8CA4WEwFU+L5kUVBY9wYmX7YIuuRR08uK6NqiJ49zSBH3UHHlat:0Zdi8hEwRka3rsIP8dfJ2THFat |
Yara | 登录查看Yara规则 |
样本下载 提交漏报 |
无主机纪录.
无域名信息.
初始地址 | 0x00400000 |
---|---|
入口地址 | 0x0055bdf0 |
声明校验值 | 0x00000000 |
实际校验值 | 0x000af99e |
最低操作系统版本要求 | 4.0 |
编译时间 | 2018-05-20 18:07:36 |
载入哈希 | d7788f694e460ee640647c815cc9694a |
图标 | |
图标精确哈希值 | 0007c3863acc809fc67aa5dd365b3068 |
图标相似性哈希值 | 3e57078a4652784411938be757acdf10 |
LegalCopyright | |
---|---|
FileVersion | |
Comments | |
ProductName | |
ProductVersion | |
FileDescription | |
Translation |
名称 | 虚拟地址 | 虚拟大小 | 原始数据大小 | 特征 | 熵(Entropy) |
---|---|---|---|---|---|
UPX0 | 0x00001000 | 0x000c4000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 0.00 |
UPX1 | 0x000c5000 | 0x00097000 | 0x00097000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 7.89 |
.rsrc | 0x0015c000 | 0x00012000 | 0x00011c00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 3.92 |
名称 | 偏移量 | 大小 | 语言 | 子语言 | 熵(Entropy) | 文件类型 |
---|---|---|---|---|---|---|
TEXTINCLUDE | 0x00143c18 | 0x00000151 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.16 | data |
TEXTINCLUDE | 0x00143c18 | 0x00000151 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.16 | data |
TEXTINCLUDE | 0x00143c18 | 0x00000151 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.16 | data |
RT_CURSOR | 0x00144108 | 0x000000b4 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 6.52 | data |
RT_CURSOR | 0x00144108 | 0x000000b4 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 6.52 | data |
RT_CURSOR | 0x00144108 | 0x000000b4 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 6.52 | data |
RT_CURSOR | 0x00144108 | 0x000000b4 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 6.52 | data |
RT_BITMAP | 0x0014597c | 0x00000144 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.05 | data |
RT_BITMAP | 0x0014597c | 0x00000144 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.05 | data |
RT_BITMAP | 0x0014597c | 0x00000144 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.05 | data |
RT_BITMAP | 0x0014597c | 0x00000144 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.05 | data |
RT_BITMAP | 0x0014597c | 0x00000144 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.05 | data |
RT_BITMAP | 0x0014597c | 0x00000144 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.05 | data |
RT_BITMAP | 0x0014597c | 0x00000144 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.05 | data |
RT_BITMAP | 0x0014597c | 0x00000144 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.05 | data |
RT_BITMAP | 0x0014597c | 0x00000144 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.05 | data |
RT_BITMAP | 0x0014597c | 0x00000144 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.05 | data |
RT_BITMAP | 0x0014597c | 0x00000144 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.05 | data |
RT_BITMAP | 0x0014597c | 0x00000144 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.05 | data |
RT_BITMAP | 0x0014597c | 0x00000144 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.05 | data |
RT_BITMAP | 0x0014597c | 0x00000144 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.05 | data |
RT_BITMAP | 0x0014597c | 0x00000144 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.05 | data |
RT_ICON | 0x0015cbf8 | 0x00010828 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 3.64 | data |
RT_ICON | 0x0015cbf8 | 0x00010828 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 3.64 | data |
RT_ICON | 0x0015cbf8 | 0x00010828 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 3.64 | data |
RT_MENU | 0x00156704 | 0x00000284 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.18 | data |
RT_MENU | 0x00156704 | 0x00000284 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.18 | data |
RT_DIALOG | 0x0015794c | 0x0000018c | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.07 | data |
RT_DIALOG | 0x0015794c | 0x0000018c | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.07 | data |
RT_DIALOG | 0x0015794c | 0x0000018c | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.07 | data |
RT_DIALOG | 0x0015794c | 0x0000018c | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.07 | data |
RT_DIALOG | 0x0015794c | 0x0000018c | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.07 | data |
RT_DIALOG | 0x0015794c | 0x0000018c | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.07 | data |
RT_DIALOG | 0x0015794c | 0x0000018c | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.07 | data |
RT_DIALOG | 0x0015794c | 0x0000018c | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.07 | data |
RT_DIALOG | 0x0015794c | 0x0000018c | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.07 | data |
RT_DIALOG | 0x0015794c | 0x0000018c | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 7.07 | data |
RT_STRING | 0x00158394 | 0x00000024 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 5.06 | data |
RT_STRING | 0x00158394 | 0x00000024 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 5.06 | data |
RT_STRING | 0x00158394 | 0x00000024 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 5.06 | data |
RT_STRING | 0x00158394 | 0x00000024 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 5.06 | data |
RT_STRING | 0x00158394 | 0x00000024 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 5.06 | data |
RT_STRING | 0x00158394 | 0x00000024 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 5.06 | data |
RT_STRING | 0x00158394 | 0x00000024 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 5.06 | data |
RT_STRING | 0x00158394 | 0x00000024 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 5.06 | data |
RT_STRING | 0x00158394 | 0x00000024 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 5.06 | data |
RT_STRING | 0x00158394 | 0x00000024 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 5.06 | data |
RT_STRING | 0x00158394 | 0x00000024 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 5.06 | data |
RT_GROUP_CURSOR | 0x001583e0 | 0x00000022 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 4.83 | data |
RT_GROUP_CURSOR | 0x001583e0 | 0x00000022 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 4.83 | data |
RT_GROUP_CURSOR | 0x001583e0 | 0x00000022 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 4.83 | data |
RT_GROUP_ICON | 0x0015842c | 0x00000014 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 4.32 | data |
RT_GROUP_ICON | 0x0015842c | 0x00000014 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 4.32 | data |
RT_GROUP_ICON | 0x0015842c | 0x00000014 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 4.32 | data |
RT_VERSION | 0x0016d43c | 0x00000238 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 3.88 | data |
RT_MANIFEST | 0x0016d678 | 0x000001cd | LANG_NEUTRAL | SUBLANG_NEUTRAL | 5.08 | XML 1.0 document, ASCII text, with very long lines, with no line terminators |
无主机纪录.
无TCP连接纪录.
无UDP连接纪录.
无域名信息.
无TCP连接纪录.
无UDP连接纪录.
未发现HTTP请求.
无SMTP流量.
无IRC请求.
无ICMP流量.
无 CIF 结果
无警报
No TLS
No Suricata HTTP
HTML 总结报告 (需15-60分钟同步) |
下载 |
---|
Task ID | 162436 |
---|---|
Mongo ID | 5b038d7fbb7d574501ff4319 |
Cuckoo release | 1.4-Maldun |