二进制文件可能包含加密或压缩数据
section: name: UPX1, entropy: 7.79, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x000c7400, virtual_size: 0x000c8000
专有的Yara规则检测结果 - 安全告警
Warning: Detected UPX. Commonly used by RAT!
可执行文件被使用UPX压缩
section: name: UPX0, entropy: 0.00, characteristics: IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00000000, virtual_size: 0x00200000
网络分析
TCP连接
IP地址 |
端口 |
23.223.198.226 |
80 |
HTTP请求
URL |
HTTP数据 |
http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip |
GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1
Accept: */*
If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT
User-Agent: IPM
Host: acroipm.adobe.com
Connection: Keep-Alive
Cache-Control: no-cache
|
静态分析
版本信息
LegalCopyright: |
Copyright Uderzo Umberto |
InternalName: |
|
FileVersion: |
1.1.2.0 |
CompanyName: |
Uderzo Software e Consulenza Informatica |
LegalTrademarks: |
|
Comments: |
|
ProductName: |
SpaceSniffer |
ProductVersion: |
1.1.2.0 |
FileDescription: |
\xe7\xe7\xe7\xe9\xe5\xe6\xe5\xe5 |
OriginalFilename: |
|
Translation: |
0x0804 0x03a8 |
PE数据组成
名称 |
虚拟地址 |
虚拟大小 |
原始数据大小 |
特征 |
熵(Entropy) |
UPX0 |
0x00001000 |
0x00200000 |
0x00000000 |
IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE |
0.00 |
UPX1 |
0x00201000 |
0x000c8000 |
0x000c7400 |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE |
7.79 |
.rsrc |
0x002c9000 |
0x00008000 |
0x00008000 |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE |
4.45 |
资源
名称 |
偏移量 |
大小 |
语言 |
子语言 |
熵(Entropy) |
文件类型 |
RT_CURSOR |
0x0024667c |
0x00000134 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
7.16 |
data |
RT_CURSOR |
0x0024667c |
0x00000134 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
7.16 |
data |
RT_CURSOR |
0x0024667c |
0x00000134 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
7.16 |
data |
RT_CURSOR |
0x0024667c |
0x00000134 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
7.16 |
data |
RT_CURSOR |
0x0024667c |
0x00000134 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
7.16 |
data |
RT_CURSOR |
0x0024667c |
0x00000134 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
7.16 |
data |
RT_CURSOR |
0x0024667c |
0x00000134 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
7.16 |
data |
RT_BITMAP |
0x002479e4 |
0x000000e8 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
6.84 |
data |
RT_BITMAP |
0x002479e4 |
0x000000e8 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
6.84 |
data |
RT_BITMAP |
0x002479e4 |
0x000000e8 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
6.84 |
data |
RT_BITMAP |
0x002479e4 |
0x000000e8 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
6.84 |
data |
RT_BITMAP |
0x002479e4 |
0x000000e8 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
6.84 |
data |
RT_BITMAP |
0x002479e4 |
0x000000e8 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
6.84 |
data |
RT_BITMAP |
0x002479e4 |
0x000000e8 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
6.84 |
data |
RT_BITMAP |
0x002479e4 |
0x000000e8 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
6.84 |
data |
RT_BITMAP |
0x002479e4 |
0x000000e8 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
6.84 |
data |
RT_BITMAP |
0x002479e4 |
0x000000e8 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
6.84 |
data |
RT_BITMAP |
0x002479e4 |
0x000000e8 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
6.84 |
data |
RT_ICON |
0x002ce17c |
0x000025a8 |
LANG_ITALIAN |
SUBLANG_ITALIAN |
3.82 |
data |
RT_ICON |
0x002ce17c |
0x000025a8 |
LANG_ITALIAN |
SUBLANG_ITALIAN |
3.82 |
data |
RT_ICON |
0x002ce17c |
0x000025a8 |
LANG_ITALIAN |
SUBLANG_ITALIAN |
3.82 |
data |
RT_ICON |
0x002ce17c |
0x000025a8 |
LANG_ITALIAN |
SUBLANG_ITALIAN |
3.82 |
data |
RT_ICON |
0x002ce17c |
0x000025a8 |
LANG_ITALIAN |
SUBLANG_ITALIAN |
3.82 |
data |
RT_ICON |
0x002ce17c |
0x000025a8 |
LANG_ITALIAN |
SUBLANG_ITALIAN |
3.82 |
data |
RT_ICON |
0x002ce17c |
0x000025a8 |
LANG_ITALIAN |
SUBLANG_ITALIAN |
3.82 |
data |
RT_ICON |
0x002ce17c |
0x000025a8 |
LANG_ITALIAN |
SUBLANG_ITALIAN |
3.82 |
data |
RT_DIALOG |
0x0024e2e0 |
0x00000052 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
5.71 |
data |
RT_DIALOG |
0x0024e2e0 |
0x00000052 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
5.71 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_STRING |
0x0024f8f4 |
0x0000014c |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
7.08 |
data |
RT_RCDATA |
0x002c48a0 |
0x00000498 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
6.92 |
data |
RT_RCDATA |
0x002c48a0 |
0x00000498 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
6.92 |
data |
RT_RCDATA |
0x002c48a0 |
0x00000498 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
6.92 |
data |
RT_RCDATA |
0x002c48a0 |
0x00000498 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
6.92 |
data |
RT_RCDATA |
0x002c48a0 |
0x00000498 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
6.92 |
data |
RT_RCDATA |
0x002c48a0 |
0x00000498 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
6.92 |
data |
RT_RCDATA |
0x002c48a0 |
0x00000498 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
6.92 |
data |
RT_RCDATA |
0x002c48a0 |
0x00000498 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
6.92 |
data |
RT_RCDATA |
0x002c48a0 |
0x00000498 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
6.92 |
data |
RT_RCDATA |
0x002c48a0 |
0x00000498 |
LANG_NEUTRAL |
SUBLANG_NEUTRAL |
6.92 |
data |
RT_GROUP_CURSOR |
0x002c4db0 |
0x00000014 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
3.88 |
data |
RT_GROUP_CURSOR |
0x002c4db0 |
0x00000014 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
3.88 |
data |
RT_GROUP_CURSOR |
0x002c4db0 |
0x00000014 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
3.88 |
data |
RT_GROUP_CURSOR |
0x002c4db0 |
0x00000014 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
3.88 |
data |
RT_GROUP_CURSOR |
0x002c4db0 |
0x00000014 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
3.88 |
data |
RT_GROUP_CURSOR |
0x002c4db0 |
0x00000014 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
3.88 |
data |
RT_GROUP_CURSOR |
0x002c4db0 |
0x00000014 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
3.88 |
data |
RT_GROUP_ICON |
0x002d0728 |
0x00000076 |
LANG_ITALIAN |
SUBLANG_ITALIAN |
2.86 |
MS Windows icon resource - 8 icons, 16x16 |
RT_VERSION |
0x002d07a4 |
0x0000031c |
LANG_CHINESE |
SUBLANG_NEUTRAL |
3.42 |
data |
RT_MANIFEST |
0x002d0ac4 |
0x00000245 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
4.95 |
XML 1.0 document, ASCII text, with CRLF line terminators |
导入
库 KERNEL32.DLL:
• 0x6d0e10 - LoadLibraryA
• 0x6d0e14 - GetProcAddress
• 0x6d0e18 - VirtualProtect
• 0x6d0e1c - VirtualAlloc
• 0x6d0e20 - VirtualFree
• 0x6d0e24 - ExitProcess
库 ADVAPI32.DLL:
• 0x6d0e2c - RegCloseKey
库 COMCTL32.DLL:
• 0x6d0e34 - None
库 COMDLG32.DLL:
• 0x6d0e3c - ChooseColorA
库 GDI32.DLL:
• 0x6d0e44 - BitBlt
库 MSIMG32.DLL:
• 0x6d0e4c - GradientFill
库 OLE32.DLL:
• 0x6d0e54 - CoInitialize
库 OLEAUT32.DLL:
• 0x6d0e5c - VariantInit
库 SHELL32.DLL:
• 0x6d0e64 - SHGetMalloc
库 USER32.DLL:
• 0x6d0e6c - GetDC
库 VERSION.DLL:
• 0x6d0e74 - VerQueryValueA
库 WINMM.DLL:
• 0x6d0e7c - timeGetTime