文件名 |
收集.rar |
文件大小 |
980136 字节 |
文件类型 |
PE32 executable (GUI) Intel 80386, for MS Windows |
CRC32 |
9FE45805 |
MD5 |
984c52ea41ef44f6118371fc9279fefd |
SHA1 |
645684f915c983815637c55426b91627bedd2ac5 |
SHA256 |
25e4d0c3a3c2d128ae989253e783505f9096f38180b5fe71f1469530123d6124 |
SHA512 |
78e64ba639abb0395f2b0eca2dcc98ca0623896185ea7c2bf1a6e93a14335942b95d2fbec28eab46b832a1d90d21c86210ead29e291f9eaa83530b47739fbb60 |
Ssdeep |
24576:QSLVMvggggM969kI3j/QmxfDLnMcTiJYJix8YZFqh87uI:QqVqggggMRI3j/QwLMWiJYJix8YZFqhA |
PEiD |
无匹配
|
Yara |
- CRC32_poly_Constant (Look for CRC32 [poly])
- MD5_Constants (Look for MD5 constants)
- DES_sbox (Look for DES [sbox])
- BASE64_table (Look for Base64 table)
- with_urls (Detected the presence of an or several urls)
- IsPE32 (Detected a 32bit PE sample)
- IsWindowsGUI (Detected a Windows GUI sample)
- HasOverlay (Detected Overlay signature)
- HasDigitalSignature (Detected Digital Signature)
- HasDebugData (Detected Debug Data)
- HasRichSignature (Detected Rich Signature)
- DebuggerCheck__QueryInfo ()
- DebuggerTiming__PerformanceCounter ()
- DebuggerTiming__Ticks (Detected timing ticks function)
- DebuggerException__SetConsoleCtrl ()
- Check_OutputDebugStringA_iat (Detect in IAT OutputDebugstringA)
- anti_dbg (Detected self protection if being debugged)
- win_mutex (Create or check mutex)
- create_process (Detection function for creating a new process)
- escalate_priv (Detected escalate priviledges function)
- win_registry (Detected system registries modification function)
- win_token (Affect system token)
- win_files_operation (Affect private profile)
- Maldun_Anomoly_Combined_Activities_7 (Spotted potential malicious behaviors from a small size target, like process manipultion, privilege, token and files)
|
VirusTotal |
VirusTotal链接
VirusTotal扫描时间: 2020-10-27 07:07:00
扫描结果: 1/70
|