分析类型 | 虚拟机标签 | 开始时间 | 结束时间 | 持续时间 |
---|---|---|---|---|
文件 (Windows) | win7-sp1-x64-hpdapp01-1 | 2018-11-09 11:24:05 | 2018-11-09 11:26:57 | 172 秒 |
文件名 | BitComet+Stable+(build+1.53.10.25)+比特彗星全功能解锁豪华版.7z |
---|---|
文件大小 | 15504703 字节 |
文件类型 | 7-zip archive data, version 0.4 |
MD5 | c3cf018e00aeaccbc835757e50e73b6d |
SHA1 | f55ba1df1351ed9686fea742dacac2dd095bfba3 |
SHA256 | 74e55bd67b7752c65fed24049a493165e6eba11284c2b4c3f3703baf5fcf4dc0 |
SHA512 | 9d171bf1d03e6415edcba0e770a6b378e9f2a776eede138fd54fc9df6dbe93fe5dd0612fe2dbe90bda6ba8d7d702ac531a951a6f9a98211577094fe1d54a67c6 |
CRC32 | 964B0BD6 |
Ssdeep | 196608:S98lR3KQd6+42Yyzybm+9UCIDzB4ZFOsYeMob2UL81yiIHLWcn5tcxzH3eDSYb:o8ly+VcpuDzB4AuLeIHLWcn50LeeYb |
Yara | 登录查看Yara规则 |
样本下载 提交误报 |
直接 | IP | 安全评级 | 地理位置 |
---|---|---|---|
是 | 5.189.166.124 | 未知 | 德国 |
是 | 5.189.171.41 | 德国 | |
否 | 67.215.246.10 | 美国 | |
否 | 87.98.162.88 | 未知 | 法国 |
防病毒引擎/厂商 | 病毒名/规则匹配 | 病毒库日期 |
---|---|---|
Bkav | 未发现病毒 | 20181108 |
MicroWorld-eScan | 未发现病毒 | 20181108 |
CMC | 未发现病毒 | 20181109 |
CAT-QuickHeal | 未发现病毒 | 20181108 |
ALYac | 未发现病毒 | 20181109 |
Malwarebytes | 未发现病毒 | 20181109 |
VIPRE | 未发现病毒 | 20181109 |
SUPERAntiSpyware | 未发现病毒 | 20181107 |
TheHacker | 未发现病毒 | 20181108 |
K7GW | 未发现病毒 | 20181108 |
K7AntiVirus | 未发现病毒 | 20181108 |
Baidu | 未发现病毒 | 20181108 |
F-Prot | 未发现病毒 | 20181109 |
Symantec | 未发现病毒 | 20181108 |
ESET-NOD32 | 未发现病毒 | 20181109 |
TrendMicro-HouseCall | 未发现病毒 | 20181109 |
Avast | 未发现病毒 | 20181109 |
ClamAV | 未发现病毒 | 20181108 |
Kaspersky | 未发现病毒 | 20181109 |
BitDefender | 未发现病毒 | 20181108 |
Babable | 未发现病毒 | 20180918 |
ViRobot | 未发现病毒 | 20181108 |
Rising | 未发现病毒 | 20181109 |
Ad-Aware | 未发现病毒 | 20181109 |
Sophos | 未发现病毒 | 20181108 |
F-Secure | 未发现病毒 | 20181109 |
DrWeb | Trojan.DownLoader27.14454 | 20181109 |
Zillya | 未发现病毒 | 20181108 |
McAfee-GW-Edition | 未发现病毒 | 20181108 |
Emsisoft | 未发现病毒 | 20181109 |
Ikarus | 未发现病毒 | 20181108 |
Cyren | 未发现病毒 | 20181109 |
Jiangmin | 未发现病毒 | 20181109 |
Avira | 未发现病毒 | 20181108 |
Fortinet | 未发现病毒 | 20181109 |
Antiy-AVL | VCS[Warning]/Email.Agent.1 | 20181109 |
Kingsoft | 未发现病毒 | 20181109 |
Arcabit | 未发现病毒 | 20181109 |
AegisLab | 未发现病毒 | 20181109 |
ZoneAlarm | 未发现病毒 | 20181109 |
Avast-Mobile | 未发现病毒 | 20181108 |
Microsoft | PUA:Win32/InstallCore | 20181109 |
AhnLab-V3 | 未发现病毒 | 20181108 |
McAfee | 未发现病毒 | 20181109 |
MAX | 未发现病毒 | 20181109 |
VBA32 | 未发现病毒 | 20181108 |
Zoner | 未发现病毒 | 20181109 |
Tencent | 未发现病毒 | 20181109 |
Yandex | 未发现病毒 | 20181108 |
TACHYON | 未发现病毒 | 20181109 |
GData | 未发现病毒 | 20181109 |
AVG | 未发现病毒 | 20181109 |
Panda | 未发现病毒 | 20181108 |
Qihoo-360 | 未发现病毒 | 20181109 |
直接 | IP | 安全评级 | 地理位置 |
---|---|---|---|
是 | 5.189.166.124 | 未知 | 德国 |
是 | 5.189.171.41 | 德国 | |
否 | 67.215.246.10 | 美国 | |
否 | 87.98.162.88 | 未知 | 法国 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 49164 | 5.189.166.124 | 5444 |
192.168.122.201 | 49366 | 5.189.166.124 | 5435 |
192.168.122.201 | 49374 | 5.189.166.124 | 5436 |
192.168.122.201 | 49380 | 5.189.166.124 | 5437 |
192.168.122.201 | 49388 | 5.189.166.124 | 5438 |
192.168.122.201 | 49398 | 5.189.166.124 | 5439 |
192.168.122.201 | 49404 | 5.189.166.124 | 5440 |
192.168.122.201 | 49410 | 5.189.166.124 | 5441 |
192.168.122.201 | 49419 | 5.189.166.124 | 5442 |
192.168.122.201 | 49425 | 5.189.166.124 | 5443 |
192.168.122.201 | 49433 | 5.189.166.124 | 5444 |
192.168.122.201 | 49643 | 5.189.166.124 | 5435 |
192.168.122.201 | 49651 | 5.189.166.124 | 5436 |
192.168.122.201 | 49657 | 5.189.166.124 | 5437 |
192.168.122.201 | 49663 | 5.189.166.124 | 5438 |
192.168.122.201 | 49669 | 5.189.166.124 | 5439 |
192.168.122.201 | 49675 | 5.189.166.124 | 5440 |
192.168.122.201 | 49683 | 5.189.166.124 | 5441 |
192.168.122.201 | 49691 | 5.189.166.124 | 5442 |
192.168.122.201 | 49697 | 5.189.166.124 | 5443 |
192.168.122.201 | 49705 | 5.189.166.124 | 5444 |
192.168.122.201 | 49170 | 5.189.171.41 | 5435 |
192.168.122.201 | 49178 | 5.189.171.41 | 5436 |
192.168.122.201 | 49184 | 5.189.171.41 | 5437 |
192.168.122.201 | 49190 | 5.189.171.41 | 5438 |
192.168.122.201 | 49198 | 5.189.171.41 | 5439 |
192.168.122.201 | 49206 | 5.189.171.41 | 5440 |
192.168.122.201 | 49213 | 5.189.171.41 | 5441 |
192.168.122.201 | 49221 | 5.189.171.41 | 5442 |
192.168.122.201 | 49229 | 5.189.171.41 | 5443 |
192.168.122.201 | 49439 | 5.189.171.41 | 5435 |
192.168.122.201 | 49445 | 5.189.171.41 | 5436 |
192.168.122.201 | 49453 | 5.189.171.41 | 5437 |
192.168.122.201 | 49459 | 5.189.171.41 | 5438 |
192.168.122.201 | 49467 | 5.189.171.41 | 5439 |
192.168.122.201 | 49473 | 5.189.171.41 | 5440 |
192.168.122.201 | 49481 | 5.189.171.41 | 5441 |
192.168.122.201 | 49489 | 5.189.171.41 | 5442 |
192.168.122.201 | 49497 | 5.189.171.41 | 5443 |
192.168.122.201 | 49713 | 5.189.171.41 | 5435 |
192.168.122.201 | 49719 | 5.189.171.41 | 5436 |
192.168.122.201 | 49727 | 5.189.171.41 | 5437 |
192.168.122.201 | 49733 | 5.189.171.41 | 5438 |
192.168.122.201 | 49741 | 5.189.171.41 | 5439 |
192.168.122.201 | 49747 | 5.189.171.41 | 5440 |
192.168.122.201 | 49755 | 5.189.171.41 | 5441 |
192.168.122.201 | 49761 | 5.189.171.41 | 5442 |
192.168.122.201 | 49769 | 5.189.171.41 | 5443 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 51691 | 192.168.122.1 | 53 |
192.168.122.201 | 56018 | 192.168.122.1 | 53 |
192.168.122.201 | 59076 | 192.168.122.1 | 53 |
192.168.122.201 | 60891 | 192.168.122.1 | 53 |
192.168.122.201 | 61263 | 192.168.122.1 | 53 |
192.168.122.201 | 62240 | 192.168.122.1 | 53 |
192.168.122.201 | 64363 | 192.168.122.1 | 53 |
192.168.122.201 | 22223 | 67.215.246.10 router.bittorrent.com | 6881 |
192.168.122.201 | 22223 | 87.98.162.88 dht.transmissionbt.com | 6881 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 49164 | 5.189.166.124 | 5444 |
192.168.122.201 | 49366 | 5.189.166.124 | 5435 |
192.168.122.201 | 49374 | 5.189.166.124 | 5436 |
192.168.122.201 | 49380 | 5.189.166.124 | 5437 |
192.168.122.201 | 49388 | 5.189.166.124 | 5438 |
192.168.122.201 | 49398 | 5.189.166.124 | 5439 |
192.168.122.201 | 49404 | 5.189.166.124 | 5440 |
192.168.122.201 | 49410 | 5.189.166.124 | 5441 |
192.168.122.201 | 49419 | 5.189.166.124 | 5442 |
192.168.122.201 | 49425 | 5.189.166.124 | 5443 |
192.168.122.201 | 49433 | 5.189.166.124 | 5444 |
192.168.122.201 | 49643 | 5.189.166.124 | 5435 |
192.168.122.201 | 49651 | 5.189.166.124 | 5436 |
192.168.122.201 | 49657 | 5.189.166.124 | 5437 |
192.168.122.201 | 49663 | 5.189.166.124 | 5438 |
192.168.122.201 | 49669 | 5.189.166.124 | 5439 |
192.168.122.201 | 49675 | 5.189.166.124 | 5440 |
192.168.122.201 | 49683 | 5.189.166.124 | 5441 |
192.168.122.201 | 49691 | 5.189.166.124 | 5442 |
192.168.122.201 | 49697 | 5.189.166.124 | 5443 |
192.168.122.201 | 49705 | 5.189.166.124 | 5444 |
192.168.122.201 | 49170 | 5.189.171.41 | 5435 |
192.168.122.201 | 49178 | 5.189.171.41 | 5436 |
192.168.122.201 | 49184 | 5.189.171.41 | 5437 |
192.168.122.201 | 49190 | 5.189.171.41 | 5438 |
192.168.122.201 | 49198 | 5.189.171.41 | 5439 |
192.168.122.201 | 49206 | 5.189.171.41 | 5440 |
192.168.122.201 | 49213 | 5.189.171.41 | 5441 |
192.168.122.201 | 49221 | 5.189.171.41 | 5442 |
192.168.122.201 | 49229 | 5.189.171.41 | 5443 |
192.168.122.201 | 49439 | 5.189.171.41 | 5435 |
192.168.122.201 | 49445 | 5.189.171.41 | 5436 |
192.168.122.201 | 49453 | 5.189.171.41 | 5437 |
192.168.122.201 | 49459 | 5.189.171.41 | 5438 |
192.168.122.201 | 49467 | 5.189.171.41 | 5439 |
192.168.122.201 | 49473 | 5.189.171.41 | 5440 |
192.168.122.201 | 49481 | 5.189.171.41 | 5441 |
192.168.122.201 | 49489 | 5.189.171.41 | 5442 |
192.168.122.201 | 49497 | 5.189.171.41 | 5443 |
192.168.122.201 | 49713 | 5.189.171.41 | 5435 |
192.168.122.201 | 49719 | 5.189.171.41 | 5436 |
192.168.122.201 | 49727 | 5.189.171.41 | 5437 |
192.168.122.201 | 49733 | 5.189.171.41 | 5438 |
192.168.122.201 | 49741 | 5.189.171.41 | 5439 |
192.168.122.201 | 49747 | 5.189.171.41 | 5440 |
192.168.122.201 | 49755 | 5.189.171.41 | 5441 |
192.168.122.201 | 49761 | 5.189.171.41 | 5442 |
192.168.122.201 | 49769 | 5.189.171.41 | 5443 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 51691 | 192.168.122.1 | 53 |
192.168.122.201 | 56018 | 192.168.122.1 | 53 |
192.168.122.201 | 59076 | 192.168.122.1 | 53 |
192.168.122.201 | 60891 | 192.168.122.1 | 53 |
192.168.122.201 | 61263 | 192.168.122.1 | 53 |
192.168.122.201 | 62240 | 192.168.122.1 | 53 |
192.168.122.201 | 64363 | 192.168.122.1 | 53 |
192.168.122.201 | 22223 | 67.215.246.10 router.bittorrent.com | 6881 |
192.168.122.201 | 22223 | 87.98.162.88 dht.transmissionbt.com | 6881 |
未发现HTTP请求.
无SMTP流量.
无IRC请求.
无ICMP流量.
无 CIF 结果
Timestamp | Source IP | Source Port | Destination IP | Destination Port | Protocol | SID | Signature | Category |
---|---|---|---|---|---|---|---|---|
2018-11-09 11:25:10.962150+0800 | 192.168.122.201 | 22223 | 67.215.246.10 | 6881 | UDP | 2008581 | ET P2P BitTorrent DHT ping request | Potential Corporate Privacy Violation |
No TLS
No Suricata HTTP
文件名 | post_info.db-journal |
---|---|
相关文件 |
C:\Users\test\AppData\Local\Temp\7z-tmp\cache\post_info.db-journal
|
文件大小 | 512 字节 |
文件类型 | SQLite Rollback Journal |
MD5 | ac9be2ea33abbbc50107c81c49bcddbb |
SHA1 | 81f02f9df09accbae67a00d37de212b885339a00 |
SHA256 | 5a0c48da0195e9fb2b1637a68475139724755971e9476ecfab18798683cb53c0 |
CRC32 | 751F0D5F |
Ssdeep | 3:7FEG2l/6y/Plxll:7+/l/h/ |
下载 提交魔盾安全分析 |
HTML 总结报告 (需15-60分钟同步) |
下载 |
---|
Task ID | 211416 |
---|---|
Mongo ID | 5be4fed02e063315c2933621 |
Cuckoo release | 1.4-Maldun |