分析类型 | 开始时间 | 结束时间 | 持续时间 | 分析引擎版本 |
---|---|---|---|---|
FILE | 2022-08-19 11:32:54 | 2022-08-19 11:35:08 | 134 秒 | 1.4-Maldun |
虚拟机机器名 | 标签 | 虚拟机管理 | 开机时间 | 关机时间 |
---|---|---|---|---|
win7-sp1-x64-shaapp02-1 | win7-sp1-x64-shaapp02-1 | KVM | 2022-08-19 11:32:55 | 2022-08-19 11:35:09 |
魔盾分数 |
---|
10.0恶意的 |
文件名 | 生死狙击爱尚辅助V15.5.rar |
---|---|
文件大小 | 8671232 字节 |
文件类型 | PE32 executable (GUI) Intel 80386, for MS Windows |
CRC32 | F154A0DF |
MD5 | 08aa277b506b594bf4212933cbc56a7b |
SHA1 | f18d1ecd31314366a2c59c34d1ed83c839549419 |
SHA256 | 67cb55e2c29506b1df035eafb09412449753a63932f1363f208756d440e20d57 |
SHA512 | 17e3d360a8b2e331961f95759ec34c457b7b13f776324c42cabadf20ef02b04209495a4f8cdbc1321f97acbef40b400d9f77dd3ed2b457657ce90d0c5831673e |
Ssdeep | 98304:udF5ZqlG4082zfokp8prJB45SbWf+YFC2t7TZMtW1ywPZpHCZkdNcw:uDrzAlHB4Qaf+HQT2Wcasg |
PEiD | 无匹配 |
Yara |
|
VirusTotal | VirusTotal查询失败 |
直接访问 | IP地址 | 国家名 |
---|---|---|
否 | 115.223.11.149 | China |
否 | 150.138.101.76 | China |
否 | 220.181.135.250 | China |
否 | 43.129.88.15 | Japan |
否 | 59.54.253.95 | China |
域名 | 响应 |
---|---|
asdata.ui10.net | A 43.129.88.15 |
my.4399.com |
A 49.71.74.18
A 150.138.101.76 CNAME my.4399.com.lxdns.com A 49.71.73.132 CNAME my.4399api.net |
s1.img4399.com |
A 115.223.11.149
CNAME s1.img4399.com.wscdns.com A 61.147.211.209 A 49.71.75.15 |
ptlogin.3304399.net |
A 59.54.253.95
A 101.227.98.111 CNAME ptlogin.3304399.net.lxdns.com |
s19.cnzz.com |
A 220.181.135.250
CNAME all.cnzz.com.danuoyi.tbcache.com CNAME c.cnzz.com |
s23.cnzz.com |
IP地址 | 端口 |
---|---|
115.223.11.149 | 80 |
115.223.11.149 | 80 |
150.138.101.76 | 80 |
150.138.101.76 | 80 |
150.138.101.76 | 443 |
220.181.135.250 | 443 |
220.181.135.250 | 443 |
23.33.32.227 | 80 |
43.129.88.15 | 80 |
43.129.88.15 | 80 |
43.129.88.15 | 80 |
43.129.88.15 | 80 |
43.129.88.15 | 80 |
59.54.253.95 | 80 |
59.54.253.95 | 80 |
IP地址 | 端口 |
---|---|
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
URL | HTTP数据 |
---|---|
http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip | GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1 Accept: */* If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT User-Agent: IPM Host: acroipm.adobe.com Connection: Keep-Alive Cache-Control: no-cache |
http://my.4399.com/yxssjj/?from=news&newsrefer= | GET /yxssjj/?from=news&newsrefer= HTTP/1.1 Accept: */* Accept-Language: zh-cn Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: my.4399.com Connection: Keep-Alive |
http://ptlogin.3304399.net/resource/css/base.css?v=2 | GET /resource/css/base.css?v=2 HTTP/1.1 Accept: */* Referer: http://my.4399.com/yxssjj/?from=news&newsrefer= Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: ptlogin.3304399.net Connection: Keep-Alive |
http://s1.img4399.com/base/js/jquery.min.1.7.2.js?20a4607 | GET /base/js/jquery.min.1.7.2.js?20a4607 HTTP/1.1 Accept: */* Referer: http://my.4399.com/yxssjj/?from=news&newsrefer= Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: s1.img4399.com Connection: Keep-Alive |
http://s1.img4399.com/base/css/KS.css?20a4607 | GET /base/css/KS.css?20a4607 HTTP/1.1 Accept: */* Referer: http://my.4399.com/yxssjj/?from=news&newsrefer= Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: s1.img4399.com Connection: Keep-Alive |
http://s1.img4399.com/base/css/ptunlogin.css | GET /base/css/ptunlogin.css HTTP/1.1 Accept: */* Referer: http://my.4399.com/yxssjj/?from=news&newsrefer= Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: s1.img4399.com Connection: Keep-Alive |
http://s1.img4399.com/merge/?file=webgame%2Fhome%2Fcss%2Fglobal_server%2Cglobal_oserver%2Cglobal_footer%2Cglobal_sprite%2CageLimitDialog%3Bwebgame%2Fssjj%2Fnews%2Fcss%2Fptlogin%3Bwebgame%2Fhome%2Ffcm%2Fgame%2FwebFcmStyle.css&v=128cf2e | GET /merge/?file=webgame%2Fhome%2Fcss%2Fglobal_server%2Cglobal_oserver%2Cglobal_footer%2Cglobal_sprite%2CageLimitDialog%3Bwebgame%2Fssjj%2Fnews%2Fcss%2Fptlogin%3Bwebgame%2Fhome%2Ffcm%2Fgame%2FwebFcmStyle.css&v=128cf2e HTTP/1.1 Accept: */* Referer: http://my.4399.com/yxssjj/?from=news&newsrefer= Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: s1.img4399.com Connection: Keep-Alive |
http://asdata.ui10.net//asjjdata/cs.txt | GET //asjjdata/cs.txt HTTP/1.1 User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0) Accept: */* Host: asdata.ui10.net Cache-Control: no-cache |
http://asdata.ui10.net/asjjdata/gonggao/zxgg.html | GET /asjjdata/gonggao/zxgg.html HTTP/1.1 Accept: */* Accept-Language: zh-cn Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: asdata.ui10.net Connection: Keep-Alive |
http://s1.img4399.com/webgame/home/js/init/PageWebTools.js?128cf2e | GET /webgame/home/js/init/PageWebTools.js?128cf2e HTTP/1.1 Accept: */* Referer: http://my.4399.com/yxssjj/?from=news&newsrefer= Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: s1.img4399.com Connection: Keep-Alive |
http://s1.img4399.com/merge/?file=webgame%2Fssjj%2Fnews%2Fcss%2Fssjj_news.css&v=128cf2e | GET /merge/?file=webgame%2Fssjj%2Fnews%2Fcss%2Fssjj_news.css&v=128cf2e HTTP/1.1 Accept: */* Referer: http://my.4399.com/yxssjj/?from=news&newsrefer= Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: s1.img4399.com Connection: Keep-Alive |
http://s1.img4399.com/base/css/KS.css?20a4607 | GET /base/css/KS.css?20a4607 HTTP/1.1 Accept: */* Referer: http://my.4399.com/yxssjj/?from=news&newsrefer= Accept-Language: zh-CN Accept-Encoding: gzip, deflate If-Modified-Since: Tue, 20 Nov 2012 02:13:11 GMT If-None-Match: W/"50aae737-902" User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: s1.img4399.com Connection: Keep-Alive |
http://asdata.ui10.net//asjjdata/gonggao/gglx.txt | GET //asjjdata/gonggao/gglx.txt HTTP/1.1 User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0) Accept: */* Host: asdata.ui10.net Cache-Control: no-cache |
http://asdata.ui10.net//asjjdata/banben.txt | GET //asjjdata/banben.txt HTTP/1.1 User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0) Accept: */* Host: asdata.ui10.net Cache-Control: no-cache |
http://asdata.ui10.net//asjjdata/zdbanben.txt | GET //asjjdata/zdbanben.txt HTTP/1.1 User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0) Accept: */* Host: asdata.ui10.net Cache-Control: no-cache |
http://asdata.ui10.net//asjjdata/tj.html?V15.5 | GET //asjjdata/tj.html?V15.5 HTTP/1.1 Accept: */* Accept-Language: zh-cn Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: asdata.ui10.net Connection: Keep-Alive |
http://s1.img4399.com/base/css/ue_common.css?20a4607 | GET /base/css/ue_common.css?20a4607 HTTP/1.1 Accept: */* Referer: http://my.4399.com/yxssjj/?from=news&newsrefer= Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: s1.img4399.com Connection: Keep-Alive |
http://asdata.ui10.net//asjjdata/gxdz.txt | GET //asjjdata/gxdz.txt HTTP/1.1 User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0) Accept: */* Host: asdata.ui10.net Cache-Control: no-cache |
http://ptlogin.3304399.net/resource/css/base.css?v=2 | GET /resource/css/base.css?v=2 HTTP/1.1 Accept: */* Referer: http://my.4399.com/yxssjj/?from=news&newsrefer= Accept-Language: zh-CN Accept-Encoding: gzip, deflate If-Modified-Since: Sat, 02 Apr 2022 07:00:38 GMT If-None-Match: "6247f496-e58d" User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: ptlogin.3304399.net Connection: Keep-Alive |
文件名 | V155.exe |
---|---|
相关文件 |
|
文件大小 | 8671232 bytes |
文件类型 | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 08aa277b506b594bf4212933cbc56a7b |
SHA1 | f18d1ecd31314366a2c59c34d1ed83c839549419 |
SHA256 | 67cb55e2c29506b1df035eafb09412449753a63932f1363f208756d440e20d57 |
SHA512 | 17e3d360a8b2e331961f95759ec34c457b7b13f776324c42cabadf20ef02b04209495a4f8cdbc1321f97acbef40b400d9f77dd3ed2b457657ce90d0c5831673e |
Ssdeep | 98304:udF5ZqlG4082zfokp8prJB45SbWf+YFC2t7TZMtW1ywPZpHCZkdNcw:uDrzAlHB4Qaf+HQT2Wcasg |
VirusTotal | 搜索相关分析 |