分析类型 | 开始时间 | 结束时间 | 持续时间 | 分析引擎版本 |
---|---|---|---|---|
FILE | 2020-11-30 10:34:20 | 2020-11-30 10:36:26 | 126 秒 | 1.4-Maldun |
虚拟机机器名 | 标签 | 虚拟机管理 | 开机时间 | 关机时间 |
---|---|---|---|---|
win7-sp1-x64-shaapp03-1 | win7-sp1-x64-shaapp03-1 | KVM | 2020-11-30 10:34:20 | 2020-11-30 10:36:27 |
魔盾分数 |
---|
10.0Trik |
文件名 | 123.exe |
---|---|
文件大小 | 198656 字节 |
文件类型 | PE32 executable (GUI) Intel 80386, for MS Windows |
CRC32 | 3F01637A |
MD5 | 6286813e23f3d047d8fb7038c9191990 |
SHA1 | a2f0c6c05225e4b10afc2c92ca24ab86df81d776 |
SHA256 | c16b53acd39eec526698c8e4e90956880b1cdd30554d08086fe94b833ee3a5b3 |
SHA512 | 7c3e17211c2cd1c46f76deea2fffc05a6356a2ce37c987a78e1308970d1d000acfc9e556005e387aab1eb24d27e2be23ec72236b0e1d7058e7af2bdc57cdf7f6 |
Ssdeep | 3072:JARzrYec4BUlCKpwwza0u4BNSAx1n5ez+x6k:25ce7SCKpRwgrOCkk |
PEiD | 无匹配 |
Yara |
|
VirusTotal |
VirusTotal链接 VirusTotal扫描时间: 2020-09-23 18:52:20 扫描结果: 64/71 |
域名 | 响应 |
---|---|
acroipm.adobe.com |
CNAME acroipm.adobe.com.edgesuite.net
A 104.123.71.146 CNAME a1983.dscd.akamai.net A 104.123.71.144 |
ofhhusrugsrhgurhf.su | NXDOMAIN |
usifusurfbbuguruf.su | |
ohsufsiuesiuhuhgf.su | |
bafaejidjaiehfgsf.su | |
gaeuhaiuhfihehfsf.su | |
gaeifiuheiuhauhdf.su | |
gnnaneieaojoagisf.su | |
iaefiazefgizagdgf.su | |
agnediuaeuidhegsf.su | |
aehfiaheifuedhgsf.su | |
nfbaeiudhaiedhhgf.su | |
ofhhusrugsrhgurhg.su | |
usifusurfbbugurug.su | |
ohsufsiuesiuhuhgg.su | |
bafaejidjaiehfgsg.su | |
gaeuhaiuhfihehfsg.su | |
gaeifiuheiuhauhdg.su | |
gnnaneieaojoagisg.su | |
iaefiazefgizagdgg.su | |
agnediuaeuidhegsg.su | |
aehfiaheifuedhgsg.su | |
ofhhusrugsrhgurho.su | |
usifusurfbbuguruo.su | |
ohsufsiuesiuhuhgo.su | |
bafaejidjaiehfgso.su | |
gaeuhaiuhfihehfso.su | |
gaeifiuheiuhauhdo.su | |
gnnaneieaojoagiso.su | |
iaefiazefgizagdgo.su | |
agnediuaeuidhegso.su | |
aehfiaheifuedhgso.su | |
ofhhusrugsrhgurhx.su | |
usifusurfbbugurux.su | |
ohsufsiuesiuhuhgx.su | |
bafaejidjaiehfgsx.su | |
gaeuhaiuhfihehfsx.su | |
gaeifiuheiuhauhdx.su | |
gnnaneieaojoagisx.su | |
iaefiazefgizagdgx.su | |
agnediuaeuidhegsx.su |
IP地址 | 端口 |
---|---|
104.123.71.144 | 80 |
IP地址 | 端口 |
---|---|
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
URL | HTTP数据 |
---|---|
http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip | GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1 Accept: */* If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT User-Agent: IPM Host: acroipm.adobe.com Connection: Keep-Alive Cache-Control: no-cache |
源地址 | 目标地址 | ICMP类型 | ICMP数据 |
---|---|---|---|
95.81.1.43 | 192.168.122.201 | 3 |
初始地址 | 0x00400000 |
---|---|
入口地址 | 0x00404d3d |
声明校验值 | 0x00031b52 |
实际校验值 | 0x00031b52 |
最低操作系统版本要求 | 5.0 |
编译时间 | 2018-03-23 17:38:04 |
载入哈希 | 5b00d590482218bc14b27f2e39c85e2c |
图标 | |
图标精确哈希值 | f31cb7ab73a020bb48c60bc27a08415a |
图标相似性哈希值 | 9726c6f81782494b62c96defde1f1d66 |
LegalCopyright: | Copyright (C) 2019, zfgdhg |
InternalName: | twugga6o.uxe |
ProductVersion: | 1.0.2.13 |
Translation: | 0x00c9 0x00a6 |
名称 | 虚拟地址 | 虚拟大小 | 原始数据大小 | 特征 | 熵(Entropy) |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0001a0a2 | 0x0001a200 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ | 6.98 |
.rdata | 0x0001c000 | 0x00005cec | 0x00005e00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 6.03 |
.data | 0x00022000 | 0x02bff7e0 | 0x00002600 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 2.74 |
.rsrc | 0x02c22000 | 0x00002e30 | 0x00003000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 5.37 |
.reloc | 0x02c25000 | 0x0000ac50 | 0x0000ae00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ | 1.20 |
名称 | 偏移量 | 大小 | 语言 | 子语言 | 熵(Entropy) | 文件类型 |
---|---|---|---|---|---|---|
AFX_DIALOG_LAYOUT | 0x02c24c78 | 0x00000002 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 1.00 | data |
FASANOMOVEGISOVUCI | 0x02c24398 | 0x000008d0 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 4.58 | ASCII text, with very long lines, with no line terminators |
RT_ICON | 0x02c239e0 | 0x00000988 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 4.84 | dBase III DBT, version number 0, next free block index 40 |
RT_ICON | 0x02c239e0 | 0x00000988 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 4.84 | dBase III DBT, version number 0, next free block index 40 |
RT_ICON | 0x02c239e0 | 0x00000988 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 4.84 | dBase III DBT, version number 0, next free block index 40 |
RT_GROUP_ICON | 0x02c24368 | 0x00000030 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 2.55 | MS Windows icon resource - 3 icons, 24x24 |
RT_VERSION | 0x02c24c80 | 0x000001b0 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 3.33 | data |
None | 0x02c24c68 | 0x0000000a | LANG_NEUTRAL | SUBLANG_NEUTRAL | 2.32 | data |