分析类型 | 开始时间 | 结束时间 | 持续时间 | 分析引擎版本 |
---|---|---|---|---|
FILE | 2020-07-05 22:38:43 | 2020-07-05 22:41:40 | 177 秒 | 1.4-Maldun |
虚拟机机器名 | 标签 | 虚拟机管理 | 开机时间 | 关机时间 |
---|---|---|---|---|
win7-sp1-x64-hpdapp01-2 | win7-sp1-x64-hpdapp01-2 | KVM | 2020-07-05 22:39:14 | 2020-07-05 22:41:41 |
魔盾分数 |
---|
10.0恶意的 |
文件名 | lantern.exe |
---|---|
文件大小 | 23872288 字节 |
文件类型 | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
CRC32 | 186C1A85 |
MD5 | db5089885374b97fab7b37aa553019a9 |
SHA1 | 5c0beead2a472fcb092bd84f127d59ebfc8732be |
SHA256 | 58b97866fc899efa16a3cdd27cf609424a608b6e127f9d350ee936da00990017 |
SHA512 | 37e9f730f83a47d00e87b49debe6091326201811079cb2727c23cf45ac1b87c9333e1e7ec5883a1d1f80acb3fcb53843b60ff183be3089ab63b953bbcdd80077 |
Ssdeep | 393216:54YDp64DRwZMEy/ovR9wpWj3VRfwlHoRfuTP66NT7OfX8TEPJV:5qvRJrPJV |
PEiD | 无匹配 |
Yara |
|
VirusTotal |
VirusTotal链接 VirusTotal扫描时间: 2020-07-03 12:46:27 扫描结果: 2/68 |
域名 | 响应 |
---|---|
certificates.godaddy.com |
CNAME gdcrl.godaddy.com.akadns.net
A 192.124.249.36 A 192.124.249.41 A 192.124.249.31 |
raw.githubusercontent.com |
CNAME github.map.fastly.net
A 151.101.108.133 |
ssl.google-analytics.com |
A 203.208.39.233
CNAME ssl-google-analytics.l.google.com |
globalconfig.flashlightproxy.com |
A 172.67.201.157
A 104.18.45.99 A 104.18.44.99 |
www.google-analytics.com |
CNAME www-google-analytics.l.google.com
A 203.208.50.65 |
s3.amazonaws.com |
CNAME s3-1.amazonaws.com
A 52.217.15.22 |
IP地址 | 端口 |
---|---|
13.224.0.13 | 443 |
13.224.0.179 | 443 |
13.224.2.97 | 443 |
13.224.5.215 | 443 |
13.224.5.239 | 443 |
13.224.6.235 | 443 |
13.249.4.69 | 443 |
13.249.5.153 | 443 |
13.249.6.25 | 443 |
13.249.6.29 | 443 |
13.249.6.32 | 443 |
13.249.6.42 | 443 |
13.249.6.69 | 443 |
13.35.1.223 | 443 |
13.35.2.171 | 443 |
13.35.2.198 | 443 |
13.35.3.125 | 443 |
13.35.4.185 | 443 |
13.35.4.222 | 443 |
13.35.5.194 | 443 |
13.35.6.167 | 443 |
143.204.2.28 | 443 |
143.204.5.190 | 443 |
143.204.5.24 | 443 |
143.204.6.25 | 443 |
151.101.108.133 | 443 |
173.223.11.13 | 443 |
184.87.194.13 | 443 |
192.124.249.41 | 80 |
2.21.34.13 | 443 |
2.21.34.136 | 443 |
2.21.34.157 | 443 |
2.21.34.235 | 443 |
20.194.3.251 | 443 |
20.194.3.251 | 443 |
205.251.212.172 | 443 |
23.43.59.157 | 443 |
23.50.53.165 | 443 |
23.50.53.165 | 443 |
23.50.53.165 | 443 |
23.55.161.153 | 443 |
23.55.163.81 | 443 |
23.60.68.106 | 443 |
23.60.68.47 | 443 |
52.217.15.22 | 443 |
52.222.129.229 | 443 |
52.222.129.6 | 443 |
52.222.130.134 | 443 |
52.222.131.187 | 443 |
52.222.131.210 | 443 |
52.222.131.223 | 443 |
54.182.2.116 | 443 |
54.182.3.194 | 443 |
54.182.3.206 | 443 |
95.100.252.125 | 443 |
96.17.68.70 | 443 |
96.17.68.77 | 443 |
99.84.3.16 | 443 |
99.86.1.126 | 443 |
99.86.3.14 | 443 |
99.86.3.7 | 443 |
99.86.5.135 | 443 |
99.86.6.79 | 443 |
IP地址 | 端口 |
---|---|
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
URL | HTTP数据 |
---|---|
http://certificates.godaddy.com/repository/gdig2.crt | GET /repository/gdig2.crt HTTP/1.1 Connection: Keep-Alive Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: certificates.godaddy.com |
初始地址 | 0x00400000 |
---|---|
入口地址 | 0x004014c0 |
声明校验值 | 0x016cecb4 |
最低操作系统版本要求 | 6.1 |
编译时间 | 2020-06-11 23:48:56 |
载入哈希 | 422cbadedb4d7aff942890ec0e83886f |
名称 | 虚拟地址 | 虚拟大小 | 原始数据大小 | 特征 | 熵(Entropy) |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0078d184 | 0x0078d200 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_32BYTES | 6.08 |
.data | 0x0078f000 | 0x00551b8c | 0x00551c00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_32BYTES | 7.08 |
.rdata | 0x00ce1000 | 0x009e26e0 | 0x009e2800 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_32BYTES | 6.08 |
.bss | 0x016c4000 | 0x0001de68 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_32BYTES | 0.00 |
.idata | 0x016e2000 | 0x00000d70 | 0x00000e00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES | 5.26 |
.CRT | 0x016e3000 | 0x00000034 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES | 0.28 |
.tls | 0x016e4000 | 0x00000020 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES | 0.27 |
.rsrc | 0x016e5000 | 0x000003b9 | 0x00000400 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE|IMAGE_SCN_ALIGN_4BYTES | 4.97 |