分析类型 | 虚拟机标签 | 开始时间 | 结束时间 | 持续时间 |
---|---|---|---|---|
文件 (Windows) | win7-sp1-x64-shaapp01-1 | 2018-05-22 11:38:48 | 2018-05-22 11:41:05 | 137 秒 |
文件名 | winspool.drv |
---|---|
文件大小 | 150016 字节 |
文件类型 | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows |
MD5 | 9f5eee5fb93bd84e50c34b052641772d |
SHA1 | 286160bc2db9448fa7adf9c1b0638cfc024a9141 |
SHA256 | 246730b6019d9bde8dfa9f5592cc9499838a321fa68afcbdefcbfe8251252fa7 |
SHA512 | 03d690cf1bcb9a26475a858b815ac5f6572b62c8f4ee2297e76c69646313e3de658f9499d661f3e40d6e6ce2c78fb2adb2125f84965b71d980f7d20e804b2260 |
CRC32 | 15777F51 |
Ssdeep | 3072:J92N8kNEd1C4SdplwNGsI0n3wcskhMDgA8FfYuAbkiN:JMbQ1CRp2p3wcsO4gAWYuq1 |
Yara | 登录查看Yara规则 |
样本下载 提交漏报 |
无主机纪录.
无域名信息.
初始地址 | 0x72f40000 |
---|---|
入口地址 | 0x72f41445 |
声明校验值 | 0x00028886 |
实际校验值 | 0x00028886 |
最低操作系统版本要求 | 5.2 |
PDB路径 | winspool.pdb |
编译时间 | 2007-02-17 23:32:05 |
载入哈希 | 1bb98a0d72f46be3503f55ba5bc72e82 |
导出DLL库名称 | WINSPOOL.DRV |
LegalCopyright | |
---|---|
InternalName | |
FileVersion | |
CompanyName | |
ProductName | |
ProductVersion | |
FileDescription | |
OriginalFilename | |
Translation |
[u'MS Visual C++ v.8 DLL (h-small sig2)'] |
名称 | 虚拟地址 | 虚拟大小 | 原始数据大小 | 特征 | 熵(Entropy) |
---|---|---|---|---|---|
.text | 0x00001000 | 0x00020f79 | 0x00021000 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ | 6.37 |
.data | 0x00022000 | 0x000019e4 | 0x00001800 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 1.59 |
.rsrc | 0x00024000 | 0x000007a4 | 0x00000800 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 4.38 |
.reloc | 0x00025000 | 0x000015a0 | 0x00001600 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ | 6.72 |
名称 | 偏移量 | 大小 | 语言 | 子语言 | 熵(Entropy) | 文件类型 |
---|---|---|---|---|---|---|
RT_DIALOG | 0x00024160 | 0x000000d4 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 3.46 | data |
RT_STRING | 0x0002429c | 0x00000088 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 4.80 | data |
RT_STRING | 0x0002429c | 0x00000088 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 4.80 | data |
RT_MESSAGETABLE | 0x00024324 | 0x000000d0 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 4.98 | data |
RT_VERSION | 0x000243f4 | 0x000003b0 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 3.55 | data |
序列 | 地址 | 名称 |
---|---|---|
107 | 0x72f57794 | ADVANCEDSETUPDIALOG |
108 | 0x72f52709 | AbortPrinter |
109 | 0x72f55f83 | AddFormA |
110 | 0x72f4e711 | AddFormW |
111 | 0x72f56e9c | AddJobA |
112 | 0x72f48dd5 | AddJobW |
113 | 0x72f561d4 | AddMonitorA |
114 | 0x72f51301 | AddMonitorW |
115 | 0x72f5606b | AddPortA |
116 | 0x72f56497 | AddPortExA |
117 | 0x72f4f69c | AddPortExW |
118 | 0x72f53c39 | AddPortW |
119 | 0x72f55750 | AddPrintProcessorA |
120 | 0x72f50bc1 | AddPrintProcessorW |
121 | 0x72f56351 | AddPrintProvidorA |
122 | 0x72f4f35e | AddPrintProvidorW |
123 | 0x72f5509e | AddPrinterA |
124 | 0x72f5515f | AddPrinterConnectionA |
125 | 0x72f53060 | AddPrinterConnectionW |
126 | 0x72f5554f | AddPrinterDriverA |
127 | 0x72f55415 | AddPrinterDriverExA |
128 | 0x72f50596 | AddPrinterDriverExW |
129 | 0x72f50a3d | AddPrinterDriverW |
130 | 0x72f52d13 | AddPrinterW |
131 | 0x72f576a3 | AdvancedDocumentPropertiesA |
132 | 0x72f53829 | AdvancedDocumentPropertiesW |
133 | 0x72f57794 | AdvancedSetupDialog |
134 | 0x72f4525d | ClosePrinter |
135 | 0x72f4df11 | CloseSpoolFileHandle |
136 | 0x72f4de21 | CommitSpoolData |
137 | 0x72f560c3 | ConfigurePortA |
138 | 0x72f53ed9 | ConfigurePortW |
139 | 0x72f4fc0b | ConnectToPrinterDlg |
140 | 0x72f54e44 | ConvertAnsiDevModeToUnicodeDevmode |
141 | 0x72f569fe | ConvertUnicodeDevModeToAnsiDevmode |
142 | 0x72f4f0a6 | CreatePrinterIC |
143 | 0x72f46d79 | DEVICECAPABILITIES |
144 | 0x72f55e27 | DEVICEMODE |
145 | 0x72f55fcb | DeleteFormA |
146 | 0x72f4e811 | DeleteFormW |
147 | 0x72f56251 | DeleteMonitorA |
148 | 0x72f513d1 | DeleteMonitorW |
149 | 0x72f5611b | DeletePortA |
150 | 0x72f54131 | DeletePortW |
151 | 0x72f562c8 | DeletePrintProcessorA |
152 | 0x72f51481 | DeletePrintProcessorW |
153 | 0x72f56420 | DeletePrintProvidorA |
154 | 0x72f51531 | DeletePrintProvidorW |
155 | 0x72f503c9 | DeletePrinter |
156 | 0x72f55195 | DeletePrinterConnectionA |
157 | 0x72f53119 | DeletePrinterConnectionW |
158 | 0x72f5586b | DeletePrinterDataA |
159 | 0x72f558a5 | DeletePrinterDataExA |
160 | 0x72f4e371 | DeletePrinterDataExW |
161 | 0x72f4e2c1 | DeletePrinterDataW |
162 | 0x72f555ea | DeletePrinterDriverA |
163 | 0x72f5556d | DeletePrinterDriverExA |
164 | 0x72f50a5b | DeletePrinterDriverExW |
165 | 0x72f50b11 | DeletePrinterDriverW |
166 | 0x72f4f249 | DeletePrinterIC |
167 | 0x72f558fd | DeletePrinterKeyA |
168 | 0x72f4e429 | DeletePrinterKeyW |
169 | 0x72f51869 | DevQueryPrint |
170 | 0x72f51901 | DevQueryPrintEx |
171 | 0x72f46d79 | DeviceCapabilities |
172 | 0x72f46d79 | DeviceCapabilitiesA |
173 | 0x72f46e56 | DeviceCapabilitiesW |
174 | 0x72f55e27 | DeviceMode |
175 | 0x72f4c8da | DevicePropertySheets |
176 | 0x72f42cc9 | DocumentEvent |
177 | 0x72f46c78 | DocumentPropertiesA |
178 | 0x72f46509 | DocumentPropertiesW |
179 | 0x72f465dd | DocumentPropertySheets |
180 | 0x72f4c301 | EXTDEVICEMODE |
181 | 0x72f4875c | EndDocPrinter |
182 | 0x72f49217 | EndPagePrinter |
183 | 0x72f57847 | EnumFormsA |
184 | 0x72f468b1 | EnumFormsW |
185 | 0x72f56b2a | EnumJobsA |
186 | 0x72f5025d | EnumJobsW |
187 | 0x72f5794e | EnumMonitorsA |
188 | 0x72f4ec19 | EnumMonitorsW |
189 | 0x72f578aa | EnumPortsA |
190 | 0x72f4eb29 | EnumPortsW |
191 | 0x72f56df9 | EnumPrintProcessorDatatypesA |
192 | 0x72f4db21 | EnumPrintProcessorDatatypesW |
193 | 0x72f56cdd | EnumPrintProcessorsA |
194 | 0x72f50c81 | EnumPrintProcessorsW |
195 | 0x72f57479 | EnumPrinterDataA |
196 | 0x72f57573 | EnumPrinterDataExA |
197 | 0x72f4e0d1 | EnumPrinterDataExW |
198 | 0x72f4dfc9 | EnumPrinterDataW |
199 | 0x72f4c632 | EnumPrinterDriversA |
200 | 0x72f4984d | EnumPrinterDriversW |
225 | 0x72f56888 | EnumPrinterKeyA |
233 | 0x72f4e1e9 | EnumPrinterKeyW |
234 | 0x72f4c536 | EnumPrintersA |
235 | 0x72f4822f | EnumPrintersW |
236 | 0x72f4c301 | ExtDeviceMode |
237 | 0x72f47958 | FindClosePrinterChangeNotification |
238 | 0x72f47ee4 | FindFirstPrinterChangeNotification |
239 | 0x72f47ba8 | FindNextPrinterChangeNotification |
240 | 0x72f4dbe9 | FlushPrinter |
241 | 0x72f47e56 | FreePrinterNotifyInfo |
201 | 0x72f57aef | GetDefaultPrinterA |
203 | 0x72f48399 | GetDefaultPrinterW |
242 | 0x72f577da | GetFormA |
243 | 0x72f4e8f1 | GetFormW |
244 | 0x72f56a9c | GetJobA |
245 | 0x72f48a5a | GetJobW |
246 | 0x72f56d80 | GetPrintProcessorDirectoryA |
247 | 0x72f50d61 | GetPrintProcessorDirectoryW |
248 | 0x72f47737 | GetPrinterA |
249 | 0x72f56eed | GetPrinterDataA |
250 | 0x72f57181 | GetPrinterDataExA |
251 | 0x72f49739 | GetPrinterDataExW |
252 | 0x72f453c7 | GetPrinterDataW |
253 | 0x72f47616 | GetPrinterDriverA |
254 | 0x72f56be7 | GetPrinterDriverDirectoryA |
255 | 0x72f467e9 | GetPrinterDriverDirectoryW |
256 | 0x72f46206 | GetPrinterDriverW |
257 | 0x72f45d7c | GetPrinterW |
258 | 0x72f4dd51 | GetSpoolFileHandle |
259 | 0x72f56661 | IsValidDevmodeA |
260 | 0x72f495cc | IsValidDevmodeW |
261 | 0x72f4741a | OpenPrinterA |
262 | 0x72f45862 | OpenPrinterW |
104 | 0x72f5f1d0 | PerfClose |
105 | 0x72f5f0c7 | PerfCollect |
106 | 0x72f5efb0 | PerfOpen |
263 | 0x72f4f1b9 | PlayGdiScriptOnPrinterIC |
264 | 0x72f56173 | PrinterMessageBoxA |
265 | 0x72f4f353 | PrinterMessageBoxW |
266 | 0x72f534d9 | PrinterProperties |
267 | 0x72f49667 | QueryColorProfile |
268 | 0x72f4f2d1 | QueryRemoteFonts |
269 | 0x72f4f86b | QuerySpoolMode |
270 | 0x72f49413 | ReadPrinter |
271 | 0x72f54f05 | ResetPrinterA |
272 | 0x72f47a5f | ResetPrinterW |
273 | 0x72f4888c | ScheduleJob |
274 | 0x72f4896b | SeekPrinter |
275 | 0x72f4f771 | SetAllocFailCount |
202 | 0x72f56680 | SetDefaultPrinterA |
204 | 0x72f58d83 | SetDefaultPrinterW |
276 | 0x72f56004 | SetFormA |
277 | 0x72f4ea29 | SetFormW |
278 | 0x72f54fb4 | SetJobA |
279 | 0x72f49129 | SetJobW |
280 | 0x72f565c7 | SetPortA |
281 | 0x72f4f961 | SetPortW |
282 | 0x72f551cb | SetPrinterA |
283 | 0x72f55937 | SetPrinterDataA |
284 | 0x72f559be | SetPrinterDataExA |
285 | 0x72f4e591 | SetPrinterDataExW |
286 | 0x72f4e4d9 | SetPrinterDataW |
287 | 0x72f4d51d | SetPrinterW |
288 | 0x72f4e661 | SplDriverUnloadComplete |
289 | 0x72f52ac1 | SpoolerDevQueryPrintW |
290 | 0x72f49add | SpoolerInit |
291 | 0x72f53041 | SpoolerPrinterEvent |
292 | 0x72f579f2 | StartDocDlgA |
293 | 0x72f515c9 | StartDocDlgW |
294 | 0x72f55807 | StartDocPrinterA |
295 | 0x72f48bd0 | StartDocPrinterW |
296 | 0x72f49368 | StartPagePrinter |
297 | 0x72f58690 | WaitForPrinterChange |
298 | 0x72f48514 | WritePrinter |
299 | 0x72f4fa31 | XcvDataW |
100 | 0x72f4f859 | |
101 | 0x72f587e1 | |
102 | 0x72f588fd | |
103 | 0x72f58999 | |
205 | 0x72f492cb | |
206 | 0x72f55661 | |
207 | 0x72f4d919 | |
208 | 0x72f556fb | |
209 | 0x72f4d9d1 | |
210 | 0x72f56c71 | |
211 | 0x72f4da69 | |
212 | 0x72f4646f | |
213 | 0x72f463a6 | |
214 | 0x72f46336 | |
215 | 0x72f50f9a | |
216 | 0x72f57b62 | |
217 | 0x72f5ba49 | |
218 | 0x72f50182 | |
219 | 0x72f54211 | |
220 | 0x72f54309 | |
221 | 0x72f54401 | |
222 | 0x72f4fc69 | |
223 | 0x72f57d96 | |
224 | 0x72f52c95 | |
226 | 0x72f5e471 | |
227 | 0x72f5e495 | |
228 | 0x72f5e5d2 | |
229 | 0x72f54759 | |
230 | 0x72f544f9 | |
231 | 0x72f54661 | |
232 | 0x72f4d7c9 |
防病毒引擎/厂商 | 病毒名/规则匹配 | 病毒库日期 |
---|---|---|
MicroWorld-eScan | 未发现病毒 | 20170928 |
nProtect | 未发现病毒 | 20170928 |
CMC | 未发现病毒 | 20170928 |
CAT-QuickHeal | 未发现病毒 | 20170928 |
McAfee | 未发现病毒 | 20170928 |
Cylance | 未发现病毒 | 20170928 |
Zillya | 未发现病毒 | 20170928 |
TheHacker | 未发现病毒 | 20170928 |
K7GW | 未发现病毒 | 20170928 |
K7AntiVirus | 未发现病毒 | 20170928 |
TrendMicro | 未发现病毒 | 20170928 |
Baidu | 未发现病毒 | 20170928 |
F-Prot | 未发现病毒 | 20170928 |
Symantec | 未发现病毒 | 20170928 |
TotalDefense | 未发现病毒 | 20170928 |
TrendMicro-HouseCall | 未发现病毒 | 20170928 |
Paloalto | 未发现病毒 | 20170928 |
ClamAV | 未发现病毒 | 20170928 |
Kaspersky | 未发现病毒 | 20170928 |
BitDefender | 未发现病毒 | 20170928 |
NANO-Antivirus | 未发现病毒 | 20170928 |
ViRobot | 未发现病毒 | 20170928 |
SUPERAntiSpyware | 未发现病毒 | 20170928 |
Rising | 未发现病毒 | 20170928 |
Ad-Aware | 未发现病毒 | 20170928 |
Sophos | 未发现病毒 | 20170928 |
Comodo | 未发现病毒 | 20170928 |
F-Secure | 未发现病毒 | 20170928 |
DrWeb | 未发现病毒 | 20170928 |
VIPRE | 未发现病毒 | 20170928 |
Invincea | 未发现病毒 | 20170914 |
McAfee-GW-Edition | 未发现病毒 | 20170928 |
Emsisoft | 未发现病毒 | 20170928 |
SentinelOne | 未发现病毒 | 20170806 |
Cyren | 未发现病毒 | 20170928 |
Jiangmin | 未发现病毒 | 20170928 |
Webroot | 未发现病毒 | 20170928 |
Avira | 未发现病毒 | 20170928 |
Fortinet | 未发现病毒 | 20170928 |
Antiy-AVL | 未发现病毒 | 20170928 |
Kingsoft | 未发现病毒 | 20170928 |
Endgame | 未发现病毒 | 20170821 |
Arcabit | 未发现病毒 | 20170928 |
AegisLab | 未发现病毒 | 20170928 |
ZoneAlarm | 未发现病毒 | 20170928 |
Avast-Mobile | 未发现病毒 | 20170928 |
Microsoft | 未发现病毒 | 20170928 |
AhnLab-V3 | 未发现病毒 | 20170928 |
ALYac | 未发现病毒 | 20170928 |
AVware | 未发现病毒 | 20170928 |
MAX | 未发现病毒 | 20170928 |
VBA32 | 未发现病毒 | 20170928 |
Malwarebytes | 未发现病毒 | 20170928 |
WhiteArmor | 未发现病毒 | 20170927 |
Panda | 未发现病毒 | 20170928 |
Zoner | 未发现病毒 | 20170928 |
ESET-NOD32 | 未发现病毒 | 20170928 |
Tencent | 未发现病毒 | 20170928 |
Yandex | 未发现病毒 | 20170908 |
Ikarus | 未发现病毒 | 20170928 |
GData | 未发现病毒 | 20170928 |
AVG | 未发现病毒 | 20170928 |
Avast | 未发现病毒 | 20170928 |
CrowdStrike | 未发现病毒 | 20170804 |
Qihoo-360 | 未发现病毒 | 20170928 |
无主机纪录.
无TCP连接纪录.
无UDP连接纪录.
无域名信息.
无TCP连接纪录.
无UDP连接纪录.
未发现HTTP请求.
无SMTP流量.
无IRC请求.
无ICMP流量.
无 CIF 结果
无警报
No TLS
No Suricata HTTP
HTML 总结报告 (需15-60分钟同步) |
下载 |
---|
Task ID | 162439 |
---|---|
Mongo ID | 5b03915fbb7d574503ff41a7 |
Cuckoo release | 1.4-Maldun |