二进制文件可能包含加密或压缩数据
section: name: UPX1, entropy: 7.94, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00159400, virtual_size: 0x0015a000
魔盾安全Yara规则检测结果 - 安全告警
Critical: Spotted potential malicious behaviors from a small size target, like process manipultion, privilege, token and files
Warning: Detected UPX. Commonly used by RAT!
可执行文件被使用UPX压缩
section: name: UPX0, entropy: 0.00, characteristics: IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00000000, virtual_size: 0x003bb000
可疑的样本异常终止
检测到样本尝试模糊或欺骗文件类型
网络分析
TCP连接
IP地址 |
端口 |
23.195.105.154 |
80 |
HTTP请求
URL |
HTTP数据 |
http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip |
GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1
Accept: */*
If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT
User-Agent: IPM
Host: acroipm.adobe.com
Connection: Keep-Alive
Cache-Control: no-cache
|
静态分析
版本信息
LegalCopyright: |
\u94a2\u4e1d \u7248\u6743\u6240\u6709 |
FileVersion: |
4.92.0.0 |
CompanyName: |
\u94a2\u4e1d |
Comments: |
\u672c\u7a0b\u5e8f\u4f7f\u7528\u6613\u8bed\u8a00\u7f16\u5199(http://www.eyuyan.com) |
ProductName: |
\u9f99\u5934\u590d\u76d8\u795e\u5668 |
ProductVersion: |
4.92.0.0 |
FileDescription: |
\u4f5c\u8005\u5fae\u4fe1\uff1agsMACD
|
Translation: |
0x0804 0x04b0 |
PE数据组成
名称 |
虚拟地址 |
虚拟大小 |
原始数据大小 |
特征 |
熵(Entropy) |
UPX0 |
0x00001000 |
0x003bb000 |
0x00000000 |
IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE |
0.00 |
UPX1 |
0x003bc000 |
0x0015a000 |
0x00159400 |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE |
7.94 |
.rsrc |
0x00516000 |
0x00003000 |
0x00003000 |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE |
3.60 |
导入
库 advapi32.dll:
• 0x918c78 - RegCloseKey
库 avifil32.dll:
• 0x918c80 - AVIStreamInfoA
库 comctl32.dll:
• 0x918c88 - ImageList_Draw
库 comdlg32.dll:
• 0x918c90 - PrintDlgA
库 gdi32.dll:
• 0x918c98 - Pie
库 KERNEL32.DLL:
• 0x918ca0 - LoadLibraryA
• 0x918ca4 - ExitProcess
• 0x918ca8 - GetProcAddress
• 0x918cac - VirtualProtect
库 msimg32.dll:
• 0x918cb4 - GradientFill
库 msvfw32.dll:
• 0x918cbc - DrawDibDraw
库 ole32.dll:
• 0x918cc4 - OleRun
库 oleaut32.dll:
• 0x918ccc - VariantCopy
库 oledlg.dll:
• 0x918cd4 - OleUIBusyA
库 rasapi32.dll:
• 0x918cdc - RasHangUpA
库 shell32.dll:
• 0x918ce4 - ShellExecuteA
库 user32.dll:
• 0x918cec - GetDC
库 wininet.dll:
• 0x918cf4 - InternetOpenA
库 winmm.dll:
• 0x918cfc - PlaySoundA
库 winspool.drv:
• 0x918d04 - OpenPrinterA
库 ws2_32.dll:
• 0x918d0c - send