分析类型 | 开始时间 | 结束时间 | 持续时间 | 分析引擎版本 |
---|---|---|---|---|
FILE | 2021-04-21 19:39:29 | 2021-04-21 19:41:33 | 124 秒 | 1.4-Maldun |
虚拟机机器名 | 标签 | 虚拟机管理 | 开机时间 | 关机时间 |
---|---|---|---|---|
win7-sp1-x64-shaapp03-1 | win7-sp1-x64-shaapp03-1 | KVM | 2021-04-21 19:39:29 | 2021-04-21 19:41:34 |
魔盾分数 |
---|
10.0Malicious |
文件名 | Steam一键上号V3.2.exe |
---|---|
文件大小 | 1519616 字节 |
文件类型 | PE32 executable (GUI) Intel 80386, for MS Windows |
CRC32 | C7B7624F |
MD5 | a517789a09f26f330e498f10508176dd |
SHA1 | 8265172b269fec69e2a6fc52dd553219135862ba |
SHA256 | 5b2225e438cc32515e060cdfb0cf7e09e4b3acf43ee4e73d92bf88e6763b4208 |
SHA512 | bf628f009f41bae6fe792cae823266d327628e8e0c7bcf85a3fccc2db8e7fe1c9422a5e9f02fd8e30100a0389af530a84dca1c9cbeb82d4c272b699c381fcd6c |
Ssdeep | 24576:QMYmc/0puetykeaVLgVlXY9+G3U1fLJOOqTLnRyAjbDMO7QCC9+kXwjpXGks4VPv:QM9c/Su0ygLgTIJIfdEngo7QCCMpXGkr |
PEiD | 无匹配 |
Yara |
|
VirusTotal |
VirusTotal链接 VirusTotal扫描时间: 2021-02-16 21:04:33 扫描结果: 46/71 |
域名 | 响应 |
---|---|
acroipm.adobe.com |
CNAME a1983.dscd.akamai.net
CNAME acroipm.adobe.com.edgesuite.net A 23.63.74.41 A 23.63.74.64 |
meun-1300764759.cos.ap-nanjing.myqcloud.com |
CNAME cos.ap-nanjing.myqcloud.com
A 58.217.250.93 A 58.217.246.14 A 58.217.250.92 |
IP地址 | 端口 |
---|---|
23.63.74.41 | 80 |
58.217.250.93 | 443 |
IP地址 | 端口 |
---|---|
192.168.122.1 | 53 |
192.168.122.1 | 53 |
URL | HTTP数据 |
---|---|
http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip | GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1 Accept: */* If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT User-Agent: IPM Host: acroipm.adobe.com Connection: Keep-Alive Cache-Control: no-cache |
初始地址 | 0x00400000 |
---|---|
入口地址 | 0x00621f61 |
声明校验值 | 0x00173cac |
实际校验值 | 0x00173cac |
最低操作系统版本要求 | 4.0 |
编译时间 | 2021-01-29 00:40:31 |
载入哈希 | b59603bc2546704db6802e1f0558b2a4 |
图标 | |
图标精确哈希值 | 9d1b3a7ede4c8ee146dd19f802a3e5f8 |
图标相似性哈希值 | dc4ae2ec7c3a24a5627ca70e6bda914f |
LegalCopyright: | \xe4\xe8\xe7\xe6\xe6\xe6 \xe8\xe5\xe9\xe5\xe4\xe7\xe6\xe7 |
FileVersion: | 3.2.0.0 |
Comments: | \xe6\xe7\xe5\xe4\xe7\xe6\xe8\xe8\xe7\xe5(http://www.dywt.com.cn) |
ProductName: | \xe6\xe8\xe8\xe7\xe5 |
ProductVersion: | 3.2.0.0 |
FileDescription: | \xe6\xe8\xe8\xe7\xe5 |
Translation: | 0x0804 0x04b0 |
名称 | 虚拟地址 | 虚拟大小 | 原始数据大小 | 特征 | 熵(Entropy) |
---|---|---|---|---|---|
.text | 0x00001000 | 0x00129000 | 0x00072000 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 8.00 |
.sedata | 0x0012a000 | 0x000fa000 | 0x000fa000 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 7.50 |
.idata | 0x00224000 | 0x00001000 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 1.50 |
.rsrc | 0x00225000 | 0x00004000 | 0x00004000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 2.68 |
.sedata | 0x00229000 | 0x00001000 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 7.98 |
名称 | 偏移量 | 大小 | 语言 | 子语言 | 熵(Entropy) | 文件类型 |
---|---|---|---|---|---|---|
RT_ICON | 0x00226d30 | 0x000010a8 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 2.79 | data |
RT_ICON | 0x00226d30 | 0x000010a8 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 2.79 | data |
RT_ICON | 0x00226d30 | 0x000010a8 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 2.79 | data |
RT_ICON | 0x00226d30 | 0x000010a8 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 2.79 | data |
RT_ICON | 0x00226d30 | 0x000010a8 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 2.79 | data |
RT_ICON | 0x00226d30 | 0x000010a8 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 2.79 | data |
RT_ICON | 0x00226d30 | 0x000010a8 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 2.79 | data |
RT_ICON | 0x00226d30 | 0x000010a8 | LANG_NEUTRAL | SUBLANG_NEUTRAL | 2.79 | data |
RT_GROUP_ICON | 0x00227e64 | 0x00000014 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 2.02 | MS Windows icon resource - 1 icon, 16x16, 16 colors |
RT_GROUP_ICON | 0x00227e64 | 0x00000014 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 2.02 | MS Windows icon resource - 1 icon, 16x16, 16 colors |
RT_GROUP_ICON | 0x00227e64 | 0x00000014 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 2.02 | MS Windows icon resource - 1 icon, 16x16, 16 colors |
RT_VERSION | 0x00227e78 | 0x00000244 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 3.87 | data |