分析任务

分析类型 虚拟机标签 开始时间 结束时间 持续时间
文件 (Windows) win7-sp1-x64-hpdapp01-1 2018-11-09 11:24:05 2018-11-09 11:26:57 172 秒
  • 错误信息: Task #211416: The analysis hit the critical timeout, terminating.
    请联系 support@maldun.com 取得帮助!

魔盾分数

10.0

Installcore病毒

文件详细信息

文件名 BitComet+Stable+(build+1.53.10.25)+比特彗星全功能解锁豪华版.7z
文件大小 15504703 字节
文件类型 7-zip archive data, version 0.4
MD5 c3cf018e00aeaccbc835757e50e73b6d
SHA1 f55ba1df1351ed9686fea742dacac2dd095bfba3
SHA256 74e55bd67b7752c65fed24049a493165e6eba11284c2b4c3f3703baf5fcf4dc0
SHA512 9d171bf1d03e6415edcba0e770a6b378e9f2a776eede138fd54fc9df6dbe93fe5dd0612fe2dbe90bda6ba8d7d702ac531a951a6f9a98211577094fe1d54a67c6
CRC32 964B0BD6
Ssdeep 196608:S98lR3KQd6+42Yyzybm+9UCIDzB4ZFOsYeMob2UL81yiIHLWcn5tcxzH3eDSYb:o8ly+VcpuDzB4AuLeIHLWcn50LeeYb
Yara 登录查看Yara规则
样本下载 提交误报

登录查看威胁特征

运行截图


访问主机纪录 (可点击查询WPING实时安全评级)

直接 IP 安全评级 地理位置
5.189.166.124 未知 德国
5.189.171.41 德国
67.215.246.10 美国
87.98.162.88 未知 法国

域名解析 (可点击查询WPING实时安全评级)

域名 安全评级 响应
router.bittorrent.com A 67.215.246.10
router.bittorrent.com
dht.transmissionbt.com A 212.129.33.59
A 87.98.162.88
dht.transmissionbt.com AAAA 2001:41d0:c:5ac:5::1
router.silotis.us
router.silotis.us AAAA 2604:180:3:bbb::3e82

摘要

登录查看详细行为信息
没有可用的静态分析.
N|rnZ
!6,o'
防病毒引擎/厂商 病毒名/规则匹配 病毒库日期
Bkav 未发现病毒 20181108
MicroWorld-eScan 未发现病毒 20181108
CMC 未发现病毒 20181109
CAT-QuickHeal 未发现病毒 20181108
ALYac 未发现病毒 20181109
Malwarebytes 未发现病毒 20181109
VIPRE 未发现病毒 20181109
SUPERAntiSpyware 未发现病毒 20181107
TheHacker 未发现病毒 20181108
K7GW 未发现病毒 20181108
K7AntiVirus 未发现病毒 20181108
Baidu 未发现病毒 20181108
F-Prot 未发现病毒 20181109
Symantec 未发现病毒 20181108
ESET-NOD32 未发现病毒 20181109
TrendMicro-HouseCall 未发现病毒 20181109
Avast 未发现病毒 20181109
ClamAV 未发现病毒 20181108
Kaspersky 未发现病毒 20181109
BitDefender 未发现病毒 20181108
Babable 未发现病毒 20180918
ViRobot 未发现病毒 20181108
Rising 未发现病毒 20181109
Ad-Aware 未发现病毒 20181109
Sophos 未发现病毒 20181108
F-Secure 未发现病毒 20181109
DrWeb Trojan.DownLoader27.14454 20181109
Zillya 未发现病毒 20181108
McAfee-GW-Edition 未发现病毒 20181108
Emsisoft 未发现病毒 20181109
Ikarus 未发现病毒 20181108
Cyren 未发现病毒 20181109
Jiangmin 未发现病毒 20181109
Avira 未发现病毒 20181108
Fortinet 未发现病毒 20181109
Antiy-AVL VCS[Warning]/Email.Agent.1 20181109
Kingsoft 未发现病毒 20181109
Arcabit 未发现病毒 20181109
AegisLab 未发现病毒 20181109
ZoneAlarm 未发现病毒 20181109
Avast-Mobile 未发现病毒 20181108
Microsoft PUA:Win32/InstallCore 20181109
AhnLab-V3 未发现病毒 20181108
McAfee 未发现病毒 20181109
MAX 未发现病毒 20181109
VBA32 未发现病毒 20181108
Zoner 未发现病毒 20181109
Tencent 未发现病毒 20181109
Yandex 未发现病毒 20181108
TACHYON 未发现病毒 20181109
GData 未发现病毒 20181109
AVG 未发现病毒 20181109
Panda 未发现病毒 20181108
Qihoo-360 未发现病毒 20181109

进程树


cmd.exe, PID: 2528, 上一级进程 PID: 2292
BitComet.exe, PID: 2596, 上一级进程 PID: 2528

访问主机纪录 (可点击查询WPING实时安全评级)

直接 IP 安全评级 地理位置
5.189.166.124 未知 德国
5.189.171.41 德国
67.215.246.10 美国
87.98.162.88 未知 法国

TCP

源地址 源端口 目标地址 目标端口
192.168.122.201 49164 5.189.166.124 5444
192.168.122.201 49366 5.189.166.124 5435
192.168.122.201 49374 5.189.166.124 5436
192.168.122.201 49380 5.189.166.124 5437
192.168.122.201 49388 5.189.166.124 5438
192.168.122.201 49398 5.189.166.124 5439
192.168.122.201 49404 5.189.166.124 5440
192.168.122.201 49410 5.189.166.124 5441
192.168.122.201 49419 5.189.166.124 5442
192.168.122.201 49425 5.189.166.124 5443
192.168.122.201 49433 5.189.166.124 5444
192.168.122.201 49643 5.189.166.124 5435
192.168.122.201 49651 5.189.166.124 5436
192.168.122.201 49657 5.189.166.124 5437
192.168.122.201 49663 5.189.166.124 5438
192.168.122.201 49669 5.189.166.124 5439
192.168.122.201 49675 5.189.166.124 5440
192.168.122.201 49683 5.189.166.124 5441
192.168.122.201 49691 5.189.166.124 5442
192.168.122.201 49697 5.189.166.124 5443
192.168.122.201 49705 5.189.166.124 5444
192.168.122.201 49170 5.189.171.41 5435
192.168.122.201 49178 5.189.171.41 5436
192.168.122.201 49184 5.189.171.41 5437
192.168.122.201 49190 5.189.171.41 5438
192.168.122.201 49198 5.189.171.41 5439
192.168.122.201 49206 5.189.171.41 5440
192.168.122.201 49213 5.189.171.41 5441
192.168.122.201 49221 5.189.171.41 5442
192.168.122.201 49229 5.189.171.41 5443
192.168.122.201 49439 5.189.171.41 5435
192.168.122.201 49445 5.189.171.41 5436
192.168.122.201 49453 5.189.171.41 5437
192.168.122.201 49459 5.189.171.41 5438
192.168.122.201 49467 5.189.171.41 5439
192.168.122.201 49473 5.189.171.41 5440
192.168.122.201 49481 5.189.171.41 5441
192.168.122.201 49489 5.189.171.41 5442
192.168.122.201 49497 5.189.171.41 5443
192.168.122.201 49713 5.189.171.41 5435
192.168.122.201 49719 5.189.171.41 5436
192.168.122.201 49727 5.189.171.41 5437
192.168.122.201 49733 5.189.171.41 5438
192.168.122.201 49741 5.189.171.41 5439
192.168.122.201 49747 5.189.171.41 5440
192.168.122.201 49755 5.189.171.41 5441
192.168.122.201 49761 5.189.171.41 5442
192.168.122.201 49769 5.189.171.41 5443

UDP

源地址 源端口 目标地址 目标端口
192.168.122.201 51691 192.168.122.1 53
192.168.122.201 56018 192.168.122.1 53
192.168.122.201 59076 192.168.122.1 53
192.168.122.201 60891 192.168.122.1 53
192.168.122.201 61263 192.168.122.1 53
192.168.122.201 62240 192.168.122.1 53
192.168.122.201 64363 192.168.122.1 53
192.168.122.201 22223 67.215.246.10 router.bittorrent.com 6881
192.168.122.201 22223 87.98.162.88 dht.transmissionbt.com 6881

域名解析 (可点击查询WPING实时安全评级)

域名 安全评级 响应
router.bittorrent.com A 67.215.246.10
router.bittorrent.com
dht.transmissionbt.com A 212.129.33.59
A 87.98.162.88
dht.transmissionbt.com AAAA 2001:41d0:c:5ac:5::1
router.silotis.us
router.silotis.us AAAA 2604:180:3:bbb::3e82

TCP

源地址 源端口 目标地址 目标端口
192.168.122.201 49164 5.189.166.124 5444
192.168.122.201 49366 5.189.166.124 5435
192.168.122.201 49374 5.189.166.124 5436
192.168.122.201 49380 5.189.166.124 5437
192.168.122.201 49388 5.189.166.124 5438
192.168.122.201 49398 5.189.166.124 5439
192.168.122.201 49404 5.189.166.124 5440
192.168.122.201 49410 5.189.166.124 5441
192.168.122.201 49419 5.189.166.124 5442
192.168.122.201 49425 5.189.166.124 5443
192.168.122.201 49433 5.189.166.124 5444
192.168.122.201 49643 5.189.166.124 5435
192.168.122.201 49651 5.189.166.124 5436
192.168.122.201 49657 5.189.166.124 5437
192.168.122.201 49663 5.189.166.124 5438
192.168.122.201 49669 5.189.166.124 5439
192.168.122.201 49675 5.189.166.124 5440
192.168.122.201 49683 5.189.166.124 5441
192.168.122.201 49691 5.189.166.124 5442
192.168.122.201 49697 5.189.166.124 5443
192.168.122.201 49705 5.189.166.124 5444
192.168.122.201 49170 5.189.171.41 5435
192.168.122.201 49178 5.189.171.41 5436
192.168.122.201 49184 5.189.171.41 5437
192.168.122.201 49190 5.189.171.41 5438
192.168.122.201 49198 5.189.171.41 5439
192.168.122.201 49206 5.189.171.41 5440
192.168.122.201 49213 5.189.171.41 5441
192.168.122.201 49221 5.189.171.41 5442
192.168.122.201 49229 5.189.171.41 5443
192.168.122.201 49439 5.189.171.41 5435
192.168.122.201 49445 5.189.171.41 5436
192.168.122.201 49453 5.189.171.41 5437
192.168.122.201 49459 5.189.171.41 5438
192.168.122.201 49467 5.189.171.41 5439
192.168.122.201 49473 5.189.171.41 5440
192.168.122.201 49481 5.189.171.41 5441
192.168.122.201 49489 5.189.171.41 5442
192.168.122.201 49497 5.189.171.41 5443
192.168.122.201 49713 5.189.171.41 5435
192.168.122.201 49719 5.189.171.41 5436
192.168.122.201 49727 5.189.171.41 5437
192.168.122.201 49733 5.189.171.41 5438
192.168.122.201 49741 5.189.171.41 5439
192.168.122.201 49747 5.189.171.41 5440
192.168.122.201 49755 5.189.171.41 5441
192.168.122.201 49761 5.189.171.41 5442
192.168.122.201 49769 5.189.171.41 5443

UDP

源地址 源端口 目标地址 目标端口
192.168.122.201 51691 192.168.122.1 53
192.168.122.201 56018 192.168.122.1 53
192.168.122.201 59076 192.168.122.1 53
192.168.122.201 60891 192.168.122.1 53
192.168.122.201 61263 192.168.122.1 53
192.168.122.201 62240 192.168.122.1 53
192.168.122.201 64363 192.168.122.1 53
192.168.122.201 22223 67.215.246.10 router.bittorrent.com 6881
192.168.122.201 22223 87.98.162.88 dht.transmissionbt.com 6881

HTTP 请求

未发现HTTP请求.

SMTP 流量

无SMTP流量.

IRC 流量

无IRC请求.

ICMP 流量

无ICMP流量.

CIF 报告

无 CIF 结果

网络警报

Timestamp Source IP Source Port Destination IP Destination Port Protocol SID Signature Category
2018-11-09 11:25:10.962150+0800 192.168.122.201 22223 67.215.246.10 6881 UDP 2008581 ET P2P BitTorrent DHT ping request Potential Corporate Privacy Violation

TLS

No TLS

Suricata HTTP

No Suricata HTTP

未发现网络提取文件
文件名 post_info.db-journal
相关文件
C:\Users\test\AppData\Local\Temp\7z-tmp\cache\post_info.db-journal
文件大小 512 字节
文件类型 SQLite Rollback Journal
MD5 ac9be2ea33abbbc50107c81c49bcddbb
SHA1 81f02f9df09accbae67a00d37de212b885339a00
SHA256 5a0c48da0195e9fb2b1637a68475139724755971e9476ecfab18798683cb53c0
CRC32 751F0D5F
Ssdeep 3:7FEG2l/6y/Plxll:7+/l/h/
下载提交魔盾安全分析
没有发现相似的分析.
HTML 总结报告
(需15-60分钟同步)
下载

Processing ( 52.526 seconds )

  • 18.233 NetworkAnalysis
  • 16.922 TargetInfo
  • 11.863 Suricata
  • 3.81 BehaviorAnalysis
  • 1.546 VirusTotal
  • 0.086 AnalysisInfo
  • 0.033 Debug
  • 0.021 Strings
  • 0.005 Dropped
  • 0.005 Memory
  • 0.002 Static

Signatures ( 3.094 seconds )

  • 0.7 antiav_detectreg
  • 0.245 infostealer_ftp
  • 0.24 md_bad_drop
  • 0.165 stealth_timeout
  • 0.147 antianalysis_detectreg
  • 0.14 infostealer_im
  • 0.134 api_spamming
  • 0.111 decoy_document
  • 0.081 antivm_generic_scsi
  • 0.08 infostealer_mail
  • 0.058 antidbg_windows
  • 0.043 antivm_generic_disk
  • 0.042 antiav_detectfile
  • 0.038 antivm_xen_keys
  • 0.037 kibex_behavior
  • 0.036 mimics_filetime
  • 0.036 darkcomet_regkeys
  • 0.035 antivm_parallels_keys
  • 0.031 recon_fingerprint
  • 0.03 reads_self
  • 0.03 virus
  • 0.03 md_domain_bl
  • 0.029 stealth_file
  • 0.029 geodo_banking_trojan
  • 0.029 infostealer_bitcoin
  • 0.028 betabot_behavior
  • 0.025 bootkit
  • 0.023 antivm_generic_diskreg
  • 0.022 antivm_generic_services
  • 0.02 antisandbox_productid
  • 0.019 md_url_bl
  • 0.017 hancitor_behavior
  • 0.017 antivm_vbox_files
  • 0.015 persistence_autorun
  • 0.013 antivm_vbox_keys
  • 0.013 antivm_vmware_keys
  • 0.012 packer_armadillo_regkey
  • 0.011 antivm_vbox_window
  • 0.011 antivm_xen_keys
  • 0.011 antivm_hyperv_keys
  • 0.011 antivm_vbox_acpi
  • 0.011 antivm_vpc_keys
  • 0.011 bypass_firewall
  • 0.011 recon_programs
  • 0.01 antivm_generic_bios
  • 0.01 antivm_generic_system
  • 0.008 stack_pivot
  • 0.008 injection_createremotethread
  • 0.008 kovter_behavior
  • 0.007 antisandbox_script_timer
  • 0.007 antidbg_devices
  • 0.007 ransomware_files
  • 0.006 antiemu_wine_func
  • 0.006 hawkeye_behavior
  • 0.006 injection_runpe
  • 0.006 disables_browser_warn
  • 0.006 ransomware_extensions
  • 0.005 network_tor
  • 0.005 injection_explorer
  • 0.005 infostealer_browser_password
  • 0.005 h1n1_behavior
  • 0.005 rat_pcclient
  • 0.004 rat_luminosity
  • 0.004 infostealer_browser
  • 0.004 modifies_desktop_wallpaper
  • 0.004 shifu_behavior
  • 0.004 browser_security
  • 0.004 network_torgateway
  • 0.003 rat_nanocore
  • 0.003 persistence_bootexecute
  • 0.003 tinba_behavior
  • 0.003 kazybot_behavior
  • 0.003 antivm_vbox_libs
  • 0.003 cerber_behavior
  • 0.003 antivm_vmware_files
  • 0.003 modify_proxy
  • 0.003 codelux_behavior
  • 0.002 antiav_avast_libs
  • 0.002 antisandbox_sunbelt_libs
  • 0.002 creates_largekey
  • 0.002 vawtrak_behavior
  • 0.002 antianalysis_detectfile
  • 0.002 antiemu_wine_reg
  • 0.002 browser_addon
  • 0.002 disables_system_restore
  • 0.002 modify_uac_prompt
  • 0.002 sniffer_winpcap
  • 0.002 targeted_flame
  • 0.001 antivm_vmware_libs
  • 0.001 antisandbox_sboxie_libs
  • 0.001 ipc_namedpipe
  • 0.001 antiav_bitdefender_libs
  • 0.001 exec_crash
  • 0.001 creates_nullvalue
  • 0.001 ursnif_behavior
  • 0.001 nymaim_behavior
  • 0.001 antisandbox_fortinet_files
  • 0.001 antisandbox_sunbelt_files
  • 0.001 antivm_vpc_files
  • 0.001 banker_cridex
  • 0.001 banker_zeus_mutex
  • 0.001 bot_drive
  • 0.001 bot_drive2
  • 0.001 disables_windows_defender
  • 0.001 maldun_blacklist
  • 0.001 modify_security_center_warnings
  • 0.001 network_tor_service
  • 0.001 office_security
  • 0.001 ransomware_radamant
  • 0.001 rat_spynet
  • 0.001 stealth_hiddenreg
  • 0.001 stealth_hide_notifications

Reporting ( 0.531 seconds )

  • 0.531 Malheur
Task ID 211416
Mongo ID 5be4fed02e063315c2933621
Cuckoo release 1.4-Maldun