分析任务

分析类型 虚拟机标签 开始时间 结束时间 持续时间
文件 (Windows) win7-sp1-x64-shaapp01-4 2019-05-31 21:06:01 2019-05-31 21:08:03 122 秒

魔盾分数

4.1

可疑的

文件详细信息

文件名 游戏大师9.10A.exe
文件大小 10287359 字节
文件类型 PE32 executable (GUI) Intel 80386, for MS Windows
MD5 d7d3047358e4541bcfad53402f208098
SHA1 60711e48587fe37a1947588a628c148395778f2a
SHA256 7f64178df75e754f6c1f8dc503162600c3d39e2390e636cfa71f24f2b6790587
SHA512 25b8e47f926f51ccff7836963b3c34198f6ca2e54a3bb529f9f8aa984aa43492a19e597d6420be038bfd3b40c011e1481c01ed82acd9b5f137535adc38fc6a23
CRC32 030C7DA7
Ssdeep 196608:pyeaMFB26EMa9hSm02xKy95h/pCWrhgvIh1OxaaAD16:py9MFBDEL3Sm5ZYWfh8kaY6
Yara 登录查看Yara规则
样本下载 提交漏报

登录查看威胁特征

运行截图


访问主机纪录 (可点击查询WPING实时安全评级)

无主机纪录.

域名解析 (可点击查询WPING实时安全评级)

无域名信息.


摘要

登录查看详细行为信息

PE 信息

初始地址 0x00400000
入口地址 0x01a6fe98
声明校验值 0x009de7f9
实际校验值 0x009de7f9
最低操作系统版本要求 4.0
编译时间 2019-05-31 21:01:05
载入哈希 3c817ebff4ae9101293e9091b713efc1
图标
图标精确哈希值 a435c105cd5bfa5cdf917b0d31eced11
图标相似性哈希值 9be605848816c0b52b741d5cd99f6276

PEiD 规则

[u'NsPack 2.9 -> North Star']

PE 数据组成

名称 虚拟地址 虚拟大小 原始数据大小 特征 熵(Entropy)
.nsp0 0x00001000 0x01661000 0x00000000 IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0.00
.nsp1 0x01662000 0x009d0000 0x009cf4ff IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 8.00
.nsp2 0x02032000 0x00000f0e 0x00000000 IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0.00

资源

名称 偏移量 大小 语言 子语言 熵(Entropy) 文件类型
TEXTINCLUDE 0x0165dd54 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
TEXTINCLUDE 0x0165dd54 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
TEXTINCLUDE 0x0165dd54 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0165e244 0x000000b4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0165e244 0x000000b4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0165e244 0x000000b4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_CURSOR 0x0165e244 0x000000b4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_BITMAP 0x0165f94c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_BITMAP 0x0165f94c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_BITMAP 0x0165f94c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_BITMAP 0x0165f94c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_BITMAP 0x0165f94c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_BITMAP 0x0165f94c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_BITMAP 0x0165f94c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_BITMAP 0x0165f94c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_BITMAP 0x0165f94c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_BITMAP 0x0165f94c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_BITMAP 0x0165f94c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_BITMAP 0x0165f94c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_BITMAP 0x0165f94c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_BITMAP 0x0165f94c 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_ICON 0x0166f4b8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL 2.55 GLS_BINARY_LSB_FIRST
RT_ICON 0x0166f4b8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL 2.55 GLS_BINARY_LSB_FIRST
RT_ICON 0x0166f4b8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL 2.55 GLS_BINARY_LSB_FIRST
RT_ICON 0x0166f4b8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL 2.55 GLS_BINARY_LSB_FIRST
RT_ICON 0x0166f4b8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL 2.55 GLS_BINARY_LSB_FIRST
RT_ICON 0x0166f4b8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL 2.55 GLS_BINARY_LSB_FIRST
RT_ICON 0x0166f4b8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL 2.55 GLS_BINARY_LSB_FIRST
RT_ICON 0x0166f4b8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL 2.55 GLS_BINARY_LSB_FIRST
RT_ICON 0x0166f4b8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL 2.55 GLS_BINARY_LSB_FIRST
RT_ICON 0x0166f4b8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL 2.55 GLS_BINARY_LSB_FIRST
RT_ICON 0x0166f4b8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL 2.55 GLS_BINARY_LSB_FIRST
RT_ICON 0x0166f4b8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL 2.55 GLS_BINARY_LSB_FIRST
RT_ICON 0x0166f4b8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL 2.55 GLS_BINARY_LSB_FIRST
RT_ICON 0x0166f4b8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL 2.55 GLS_BINARY_LSB_FIRST
RT_MENU 0x0165fa9c 0x00000284 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_MENU 0x0165fa9c 0x00000284 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_DIALOG 0x01660ce4 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_DIALOG 0x01660ce4 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_DIALOG 0x01660ce4 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_DIALOG 0x01660ce4 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_DIALOG 0x01660ce4 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_DIALOG 0x01660ce4 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_DIALOG 0x01660ce4 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_DIALOG 0x01660ce4 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_DIALOG 0x01660ce4 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_DIALOG 0x01660ce4 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_STRING 0x0166172c 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_STRING 0x0166172c 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_STRING 0x0166172c 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_STRING 0x0166172c 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_STRING 0x0166172c 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_STRING 0x0166172c 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_STRING 0x0166172c 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_STRING 0x0166172c 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_STRING 0x0166172c 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_STRING 0x0166172c 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_STRING 0x0166172c 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_GROUP_CURSOR 0x01661778 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_GROUP_CURSOR 0x01661778 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_GROUP_CURSOR 0x01661778 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_GROUP_ICON 0x016617b0 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_GROUP_ICON 0x016617b0 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_GROUP_ICON 0x016617b0 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 0.00 empty
RT_MANIFEST 0x01662e14 0x000002b9 LANG_NEUTRAL SUBLANG_NEUTRAL 5.02 XML 1.0 document, ASCII text, with very long lines, with no line terminators

导入

库: KERNEL32.DLL:
0x1a6f9cc LoadLibraryA
0x1a6f9d0 GetProcAddress
0x1a6f9d4 VirtualProtect
0x1a6f9d8 VirtualAlloc
0x1a6f9dc VirtualFree
0x1a6f9e0 ExitProcess
库: USER32.DLL:
0x1a6f9e8 ShowWindow
库: GDI32.DLL:
0x1a6f9f0 SelectObject
库: GDIPLUS.DLL:
0x1a6f9f8 GdipCreateFromHDC
库: OLE32.DLL:
0x1a6fa00 OleUninitialize
库: IMM32.DLL:
库: SHELL32.DLL:
0x1a6fa10 ShellExecuteA
库: SHLWAPI.DLL:
0x1a6fa18 PathFileExistsA
库: WINMM.DLL:
0x1a6fa20 PlaySoundA
库: KERNEL32.DLL:
0x1a6fa28 SetStdHandle
库: USER32.DLL:
0x1a6fa30 LoadBitmapA
库: GDI32.DLL:
0x1a6fa38 GetTextMetricsA
库: WINMM.DLL:
0x1a6fa40 midiStreamClose
库: WINSPOOL.DRV:
0x1a6fa48 ClosePrinter
库: ADVAPI32.DLL:
0x1a6fa50 RegCloseKey
库: SHELL32.DLL:
0x1a6fa58 Shell_NotifyIconA
库: OLEAUT32.DLL:
0x1a6fa60 LoadTypeLib
库: COMCTL32.DLL:
0x1a6fa68 None
库: WS2_32.DLL:
0x1a6fa70 WSACleanup
库: COMDLG32.DLL:
0x1a6fa78 GetFileTitleA

.nsp0
.nsp1
.nsp2
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity name="E.App" processorArchitecture="x86" version="5.2.0.0" type="win32"/><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"> <security> <requestedPrivileges> <requestedExecutionLevel level="requireAdministrator" uiAccess="false"/> </requestedPrivileges> </security></trustInfo></assembly>
wwwwwwp
wwwwp
wwwwp
KERNEL32.DLL
USER32.DLL
GDI32.DLL
GDIPLUS.DLL
OLE32.DLL
IMM32.DLL
SHELL32.DLL
SHLWAPI.DLL
WINMM.DLL
KERNEL32.DLL
USER32.DLL
GDI32.DLL
WINMM.DLL
WINSPOOL.DRV
ADVAPI32.DLL
SHELL32.DLL
OLEAUT32.DLL
COMCTL32.DLL
WS2_32.DLL
COMDLG32.DLL
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
ExitProcess
ShowWindow
SelectObject
GdipCreateFromHDC
OleUninitialize
ImmSetCompositionWindow
ShellExecuteA
PathFileExistsA
PlaySoundA
SetStdHandle
LoadBitmapA
GetTextMetricsA
midiStreamClose
ClosePrinter
RegCloseKey
Shell_NotifyIconA
GetFileTitleA
U.X-.]_
l3g([
"4tt4
RKeu%
3yj>P
DEFAULT_ICON
没有防病毒引擎扫描信息!

进程树


____________9.10A.exe, PID: 2760, 上一级进程 PID: 2416

访问主机纪录 (可点击查询WPING实时安全评级)

无主机纪录.

TCP

无TCP连接纪录.

UDP

无UDP连接纪录.

域名解析 (可点击查询WPING实时安全评级)

无域名信息.

TCP

无TCP连接纪录.

UDP

无UDP连接纪录.

HTTP 请求

未发现HTTP请求.

SMTP 流量

无SMTP流量.

IRC 流量

无IRC请求.

ICMP 流量

无ICMP流量.

CIF 报告

无 CIF 结果

网络警报

无警报

TLS

No TLS

Suricata HTTP

No Suricata HTTP

未发现网络提取文件
抱歉! 没有任何文件投放。
没有发现相似的分析.
HTML 总结报告
(需15-60分钟同步)
下载

Processing ( 15.992 seconds )

  • 7.681 TargetInfo
  • 5.275 Static
  • 1.925 VirusTotal
  • 0.49 BehaviorAnalysis
  • 0.357 peid
  • 0.216 NetworkAnalysis
  • 0.028 config_decoder
  • 0.009 AnalysisInfo
  • 0.009 Strings
  • 0.002 Memory

Signatures ( 0.174 seconds )

  • 0.025 api_spamming
  • 0.02 stealth_timeout
  • 0.018 stealth_decoy_document
  • 0.014 antiav_detectreg
  • 0.009 md_url_bl
  • 0.008 md_domain_bl
  • 0.007 injection_createremotethread
  • 0.006 infostealer_ftp
  • 0.005 antiemu_wine_func
  • 0.005 anomaly_persistence_autorun
  • 0.005 injection_runpe
  • 0.005 kovter_behavior
  • 0.005 antiav_detectfile
  • 0.004 infostealer_browser_password
  • 0.004 infostealer_im
  • 0.004 ransomware_files
  • 0.003 antianalysis_detectreg
  • 0.003 infostealer_bitcoin
  • 0.003 ransomware_extensions
  • 0.002 tinba_behavior
  • 0.002 antidbg_windows
  • 0.002 antivm_vbox_files
  • 0.002 disables_browser_warn
  • 0.002 infostealer_mail
  • 0.001 antivm_vbox_libs
  • 0.001 rat_nanocore
  • 0.001 betabot_behavior
  • 0.001 cerber_behavior
  • 0.001 antivm_parallels_keys
  • 0.001 geodo_banking_trojan
  • 0.001 bot_drive
  • 0.001 bot_drive2
  • 0.001 browser_security
  • 0.001 modify_proxy
  • 0.001 md_bad_drop

Reporting ( 0.451 seconds )

  • 0.428 ReportHTMLSummary
  • 0.023 Malheur
Task ID 299870
Mongo ID 5cf12746bb7d57351705ec2e
Cuckoo release 1.4-Maldun