分析任务

分析类型 虚拟机标签 开始时间 结束时间 持续时间
URL win7-sp1-x64-hpdapp01-1 2018-07-20 11:08:14 2018-07-20 11:10:57 163 秒

魔盾分数

1.25

正常的

URL详细信息


登录查看威胁特征

运行截图


访问主机纪录 (可点击查询WPING实时安全评级)

直接 IP 安全评级 地理位置
198.16.79.93 荷兰

域名解析 (可点击查询WPING实时安全评级)

域名 安全评级 响应
none-stops.com A 198.16.79.93

摘要

登录查看详细行为信息

WHOIS 信息

Name: Protection of Private Person
Country: RU
State: None
City: Moscow
ZIP Code: 123007
Address: PO box 87, REG.RU Protection Service

Orginization: None
Domain Name(s):
    NONE-STOPS.COM
Creation Date:
    2016-10-20 07:35:44
    2016-10-20 10:35:46
Updated Date:
    2016-10-20 11:59:38
Expiration Date:
    2018-10-20 07:35:44
    2018-10-20 00:00:00
Email(s):
    abuse@reg.ru
    NONE-STOPS.COM@regprivate.ru

Registrar(s):
    Registrar of domain names REG.RU LLC
Name Server(s):
    NS1.NONE-STOPS.COM
    NS2.NONE-STOPS.COM
    ns1.none-stops.com (198.16.79.93)
    ns2.none-stops.com (198.16.79.93)
Referral URL(s):
    None
没有防病毒引擎扫描信息!

进程树


iexplore.exe, PID: 2248, 上一级进程 PID: 1520
iexplore.exe, PID: 2400, 上一级进程 PID: 2248

访问主机纪录 (可点击查询WPING实时安全评级)

直接 IP 安全评级 地理位置
198.16.79.93 荷兰

TCP

源地址 源端口 目标地址 目标端口
192.168.122.201 49161 198.16.79.93 none-stops.com 80

UDP

源地址 源端口 目标地址 目标端口
192.168.122.201 57651 192.168.122.1 53
192.168.122.201 65281 192.168.122.1 53

域名解析 (可点击查询WPING实时安全评级)

域名 安全评级 响应
none-stops.com A 198.16.79.93

TCP

源地址 源端口 目标地址 目标端口
192.168.122.201 49161 198.16.79.93 none-stops.com 80

UDP

源地址 源端口 目标地址 目标端口
192.168.122.201 57651 192.168.122.1 53
192.168.122.201 65281 192.168.122.1 53

HTTP 请求

URI HTTP数据
URL专业沙箱检测 -> http://none-stops.com/wpad.dat?8a84f6cb0688f743e33420942192cfc419391134
GET /wpad.dat?8a84f6cb0688f743e33420942192cfc419391134 HTTP/1.1
Accept: */*
Referer: http://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=24&ved=0CCEQfjbGN6ak5STUN3bktvWUl5WkZvY2RC&url=http%3A%2F%2Fnone-stops.com%2Fwpad.dat%3F8a84f6cb0688f743e33420942192cfc419391134&ei=UmlaTnNsTWFxY1FM&usg=AFQjcXpndFprcmtGY0pV
Accept-Language: zh-cn
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Accept-Encoding: gzip, deflate
Host: none-stops.com
Connection: Keep-Alive

SMTP 流量

无SMTP流量.

IRC 流量

无IRC请求.

ICMP 流量

无ICMP流量.

CIF 报告

无 CIF 结果

网络警报

无警报

TLS

No TLS

Suricata HTTP

No Suricata HTTP

未发现网络提取文件
文件名 JavaDeployReg.log
相关文件
C:\Users\test\AppData\Local\Temp\JavaDeployReg.log
文件大小 1068 字节
文件类型 ASCII text, with CRLF line terminators
MD5 0e0f44f68e13a14ed6f838959c2517cb
SHA1 29580301a4f04cacb74f972590e61c9e041d7b82
SHA256 de1f5ba2a82abe1e1bddbaf602aa6b1b1fb1e264877ff9eb21ff7adcec7d1808
CRC32 B82DD8F3
Ssdeep 24:odn9LnnMm8uA8XlZQfU78Tc49PX/+1SQezReu:odn9LnnMruA8XlZQfU78Tc49PX/+A3zd
下载提交魔盾安全分析显示文本
[2017/06/01 16:29:23.649] Latest deploy version:  
[2017/06/01 16:29:23.649] 11.121.2 
[2017/06/01 16:30:14.832] Latest deploy version:  
[2017/06/01 16:30:14.832] 11.121.2 
[2017/06/01 16:40:25.052] Latest deploy version:  
[2017/06/01 16:40:25.052] 11.121.2 
[2017/06/08 18:03:28.677] Latest deploy version:  
[2017/06/08 18:03:28.677] 11.121.2 
[2017/06/08 18:15:11.176] Latest deploy version:  
[2017/06/08 18:15:11.176] 11.121.2 
[2017/06/08 18:17:04.791] Latest deploy version:  
[2017/06/08 18:17:04.791] 11.121.2 
[2017/09/01 16:11:55.188] Latest deploy version:  
[2017/09/01 16:11:55.188] 11.121.2 
[2017/09/01 20:28:25.900] Latest deploy version:  
[2017/09/01 20:28:25.900] 11.121.2 
[2017/09/01 22:02:42.198] Latest deploy version:  
[2017/09/01 22:02:42.198] 11.121.2 
[2017/09/03 00:16:45.426] Latest deploy version:  
[2017/09/03 00:16:45.426] 11.121.2 
[2017/09/03 11:22:53.307] Latest deploy version:  
[2017/09/03 11:22:53.307] 11.121.2 
[2018/07/20 19:29:41.550] Latest deploy version:  
[2018/07/20 19:29:41.565] 11.121.2 
文件名 {2A2EC924-8BCA-11E8-A5BE-5254008A4709}.dat
相关文件
C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{2A2EC924-8BCA-11E8-A5BE-5254008A4709}.dat
文件大小 4096 字节
文件类型 Composite Document File V2 Document, Cannot read section info
MD5 867303b20912e0175ef9e438f6c445f9
SHA1 0fe9969e32ef36456b6fb2d60723c62bd0da1984
SHA256 ff187e2056bb44fae75a233855fd82fa465777aeb7703f99a297c9d72423f62e
CRC32 2441CAD4
Ssdeep 12:rl0YmGFvyrEgm8GL7KF1rEgm8Gz7qPNlCgrNl26ao:rAG8FG8JNlLrNlIo
下载提交魔盾安全分析
文件名 RecoveryStore.{2A2EC923-8BCA-11E8-A5BE-5254008A4709}.dat
相关文件
C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{2A2EC923-8BCA-11E8-A5BE-5254008A4709}.dat
文件大小 5120 字节
文件类型 Composite Document File V2 Document, Cannot read section info
MD5 e337d4b4027a506b67d5c14d30326764
SHA1 f8ca781a3a9ffcf1eb620aeafa5987eeedca0bda
SHA256 1abbd7fc82e3752380ae0734b870cc513d28eb1c9f165fe43f817845171c4920
CRC32 4B2C7181
Ssdeep 12:rl0oGF2bEETrEgmZ+IaCrI0CIc8GbiF2barEg5+IaCrI0CI7uoeMiqI77vNlTqom:rLbEETG5/k8yba5/OMkNlWoBrQNlWoB
下载提交魔盾安全分析
文件名 index.dat
相关文件
C:\Users\test\AppData\Local\Microsoft\Feeds Cache\index.dat
文件大小 32768 字节
文件类型 Internet Explorer cache file version Ver 5.2
MD5 0aee387ca0a52dcdd8f8a29ea76edb42
SHA1 5df81547dcadb2a7b8bc689da8e1383ba1a84cb9
SHA256 c31bc37e102b70a472837d530ec80bdaea28b0fefda3e9aa8c8cda98c4200c4e
CRC32 B451CA0B
Ssdeep 12:qjtSaFpbZli3zIoYDPO7em4GZj03W/cKYDPOCG5A30WUsOXQDG9YRm4GZ5:qj4avEIoYTCebGZ7ZYTlEJ0oQQ4bGZ
魔盾安全分析结果 2.0分析时间:2016-11-06 20:10:20查看分析报告
下载提交魔盾安全分析
文件名 frameiconcache.dat
相关文件
C:\Users\test\AppData\Local\Microsoft\Internet Explorer\frameiconcache.dat
文件大小 9148 字节
文件类型 data
MD5 e68c4bec159f7493a13d86b7d9074df5
SHA1 725c8ce3ba9bebc2a0844d61750794ba04c92746
SHA256 aff960513d890aaca6cfc7cf215538b734388dbdebdc8deb7743297d03311f62
CRC32 E0D01FBC
Ssdeep 12:vc6l1QF6vEMXAt+prwMk6IJFJy8JTX8JHK8JKcFn8J8YHK8Z6A1JoRyUZdpwpGeq:RqcEMXIgrARicaAVrrU
魔盾安全分析结果 2.0分析时间:2016-11-17 08:00:32查看分析报告
下载提交魔盾安全分析
文件名 index.dat
相关文件
C:\Users\test\AppData\Roaming\Microsoft\Windows\IECompatCache\index.dat
文件大小 65536 字节
文件类型 Internet Explorer cache file version Ver 5.2
MD5 0ee0d92f5ad9cd4d354a120734ae8e5e
SHA1 a3d2338356b933a1240f053b89efe7f1b5e63353
SHA256 bd15c1573c53ac40e26c307c00be243ace57eb5fd0d2879349b24832d2e7a771
CRC32 36F430F7
Ssdeep 384:wEEG/+oo0M7hPfdoW7QRyUEZeluUFyvp64PBhqNLguX3/5YSHYjitk9t7sub/2Iw:wEEG/+Rg
下载提交魔盾安全分析
HTML 总结报告
(需15-60分钟同步)
下载

Processing ( 28.2 seconds )

  • 12.932 Suricata
  • 6.564 NetworkAnalysis
  • 5.126 BehaviorAnalysis
  • 1.562 Static
  • 1.312 VirusTotal
  • 0.442 AnalysisInfo
  • 0.199 Debug
  • 0.059 Dropped
  • 0.004 Memory

Signatures ( 7.372 seconds )

  • 2.013 md_url_bl
  • 1.683 antiav_detectreg
  • 0.574 infostealer_ftp
  • 0.428 md_bad_drop
  • 0.351 antianalysis_detectreg
  • 0.323 infostealer_im
  • 0.24 stealth_timeout
  • 0.185 antivm_generic_scsi
  • 0.181 infostealer_mail
  • 0.175 api_spamming
  • 0.132 antivm_generic_services
  • 0.09 antivm_parallels_keys
  • 0.09 darkcomet_regkeys
  • 0.088 antivm_xen_keys
  • 0.086 kibex_behavior
  • 0.065 geodo_banking_trojan
  • 0.061 betabot_behavior
  • 0.059 antivm_generic_diskreg
  • 0.032 stealth_file
  • 0.032 antivm_vbox_keys
  • 0.032 antivm_vmware_keys
  • 0.03 antivm_vbox_acpi
  • 0.029 antivm_xen_keys
  • 0.029 antivm_hyperv_keys
  • 0.029 antivm_vpc_keys
  • 0.029 bypass_firewall
  • 0.029 packer_armadillo_regkey
  • 0.027 antivm_generic_disk
  • 0.02 mimics_filetime
  • 0.018 virus
  • 0.016 bootkit
  • 0.013 antiav_detectfile
  • 0.01 persistence_autorun
  • 0.009 infostealer_bitcoin
  • 0.009 md_domain_bl
  • 0.008 hancitor_behavior
  • 0.007 antiemu_wine_func
  • 0.007 antivm_vbox_files
  • 0.007 ransomware_files
  • 0.006 stack_pivot
  • 0.006 antidbg_windows
  • 0.006 kovter_behavior
  • 0.006 ransomware_extensions
  • 0.005 infostealer_browser_password
  • 0.005 antiemu_wine_reg
  • 0.005 recon_fingerprint
  • 0.004 antivm_vbox_libs
  • 0.004 disables_browser_warn
  • 0.003 tinba_behavior
  • 0.003 rat_nanocore
  • 0.003 antiav_avast_libs
  • 0.003 injection_createremotethread
  • 0.003 ransomware_message
  • 0.003 antisandbox_productid
  • 0.003 browser_security
  • 0.003 network_torgateway
  • 0.002 rat_luminosity
  • 0.002 dridex_behavior
  • 0.002 antisandbox_sunbelt_libs
  • 0.002 exec_crash
  • 0.002 vawtrak_behavior
  • 0.002 cerber_behavior
  • 0.002 injection_runpe
  • 0.002 antidbg_devices
  • 0.002 antivm_generic_bios
  • 0.002 antivm_generic_system
  • 0.002 recon_programs
  • 0.001 hawkeye_behavior
  • 0.001 network_tor
  • 0.001 persistence_bootexecute
  • 0.001 antivm_vmware_libs
  • 0.001 antivm_vbox_window
  • 0.001 modifies_desktop_wallpaper
  • 0.001 Locky_behavior
  • 0.001 kazybot_behavior
  • 0.001 antisandbox_sboxie_libs
  • 0.001 antiav_bitdefender_libs
  • 0.001 shifu_behavior
  • 0.001 ursnif_behavior
  • 0.001 antianalysis_detectfile
  • 0.001 antivm_generic_cpu
  • 0.001 antivm_vmware_files
  • 0.001 antivm_vmware_mutexes
  • 0.001 banker_zeus_mutex
  • 0.001 bot_drive
  • 0.001 bot_drive2
  • 0.001 browser_addon
  • 0.001 codelux_behavior
  • 0.001 disables_system_restore
  • 0.001 disables_windows_defender
  • 0.001 ie_martian_children
  • 0.001 modify_security_center_warnings
  • 0.001 modify_uac_prompt
  • 0.001 office_security
  • 0.001 rat_pcclient
  • 0.001 rat_spynet
  • 0.001 stealth_hiddenreg
  • 0.001 stealth_hide_notifications
  • 0.001 targeted_flame
  • 0.001 whois_create

Reporting ( 0.65 seconds )

  • 0.65 ReportHTMLSummary
Task ID 171191
Mongo ID 5b5152fa2e063307e1339600
Cuckoo release 1.4-Maldun