分析类型 | 开始时间 | 结束时间 | 持续时间 | 分析引擎版本 |
---|---|---|---|---|
FILE | 2016-05-28 14:56:56 | 2016-05-28 14:59:30 | 154 秒 | 1.4-Maldun |
虚拟机机器名 | 标签 | 虚拟机管理 | 开机时间 | 关机时间 |
---|---|---|---|---|
win7-sp1-x64 | win7-sp1-x64 | KVM | 2016-05-28 14:56:56 | 2016-05-28 14:59:28 |
魔盾分数 |
---|
2.8可疑的 |
文件名 | atl71.dll |
---|---|
文件大小 | 89600 字节 |
文件类型 | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows |
CRC32 | 1387F05A |
MD5 | 79cb6457c81ada9eb7f2087ce799aaa7 |
SHA1 | 322ddde439d9254182f5945be8d97e9d897561ae |
SHA256 | a68e1297fae2bcf854b47ffa444f490353028de1fa2ca713b6cf6cc5aa22b88a |
SHA512 | eca4b91109d105b2ce8c40710b8e3309c4cc944194843b7930e06daf3d1df6ae85c1b7063036c7e5cd10276e5e5535b33e49930adbad88166228316283d011b8 |
Ssdeep | 1536:kIlL9T5Xx1ogKMvw5Br7KLKLI+Xe+QnyH4Cc0tR6nGVp/VTbkE0DJ4ZwmroV:BtvBOI+FQny5R6nG//SdaZwms |
PEiD | 无匹配 |
Yara |
|
VirusTotal |
VirusTotal链接 VirusTotal扫描时间: 2016-05-27 23:32:19 扫描结果: 0/56 |
直接访问 | IP地址 | 国家名 |
---|---|---|
否 | 111.108.54.10 | Japan |
域名 | 响应 |
---|---|
www.msftncsi.com |
A 111.108.54.11
CNAME www.msftncsi.com.edgesuite.net A 111.108.54.10 CNAME a1961.g2.akamai.net |
IP地址 | 端口 |
---|---|
111.108.54.10 | 80 |
IP地址 | 端口 |
---|---|
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.255 | 137 |
192.168.122.255 | 138 |
224.0.0.252 | 5355 |
224.0.0.252 | 5355 |
239.255.255.250 | 1900 |
52.169.179.91 | 123 |
192.168.122.69 | 53197 |
URL | HTTP数据 |
---|---|
http://www.msftncsi.com/ncsi.txt | GET /ncsi.txt HTTP/1.1 Connection: Close User-Agent: Microsoft NCSI Host: www.msftncsi.com |
初始地址 | 0x7c120000 |
---|---|
入口地址 | 0x7c12c872 |
声明校验值 | 0x00000000 |
实际校验值 | 0x00021ff1 |
最低操作系统版本要求 | 4.0 |
PDB路径 | atl71.pdb |
编译时间 | 2006-07-12 09:07:28 |
导出DLL库名称 | ATL71.DLL |
LegalCopyright: | \xa9 Microsoft Corporation. All rights reserved. |
InternalName: | ATL71.DLL |
FileVersion: | 7.10.6030.0 |
CompanyName: | Microsoft Corporation |
ProductName: | Microsoft\xae Visual Studio .NET |
ProductVersion: | 7.10.6030.0 |
FileDescription: | ATL Module for Windows (Unicode) |
OriginalFilename: | ATL71.DLL |
Translation: | 0x0409 0x04b0 |
名称 | 虚拟地址 | 虚拟大小 | 原始数据大小 | 特征 | 熵(Entropy) |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0000cc34 | 0x0000ce00 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ | 6.49 |
.rdata | 0x0000e000 | 0x0000374d | 0x00003800 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 5.64 |
.data | 0x00012000 | 0x00001bc0 | 0x00001a00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 4.92 |
.rsrc | 0x00014000 | 0x00002330 | 0x00002400 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 4.60 |
.reloc | 0x00017000 | 0x000014ca | 0x00001600 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ | 6.00 |
名称 | 偏移量 | 大小 | 语言 | 子语言 | 熵(Entropy) | 文件类型 |
---|---|---|---|---|---|---|
TYPELIB | 0x00014130 | 0x00001e34 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 4.81 | data |
RT_STRING | 0x00016308 | 0x00000026 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0.70 | data |
RT_STRING | 0x00016308 | 0x00000026 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 0.70 | data |
RT_VERSION | 0x00015f68 | 0x00000358 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 3.52 | data |
序列 | 地址 | 名称 |
---|---|---|
10 | 0x7c124fe7 | AtlAdvise |
41 | 0x7c12a0d3 | AtlAxAttachControl |
39 | 0x7c129b97 | AtlAxCreateControl |
40 | 0x7c1297dd | AtlAxCreateControlEx |
59 | 0x7c129800 | AtlAxCreateControlLic |
60 | 0x7c12970d | AtlAxCreateControlLicEx |
38 | 0x7c12a0b5 | AtlAxCreateDialogA |
37 | 0x7c12a097 | AtlAxCreateDialogW |
36 | 0x7c12a079 | AtlAxDialogBoxA |
35 | 0x7c12a05b | AtlAxDialogBoxW |
47 | 0x7c1242cc | AtlAxGetControl |
48 | 0x7c124304 | AtlAxGetHost |
42 | 0x7c129bb9 | AtlAxWinInit |
64 | 0x7c12175d | AtlCallTermFunc |
15 | 0x7c1250d2 | AtlComModuleGetClassObject |
17 | 0x7c123de3 | AtlComModuleRegisterClassObjects |
18 | 0x7c12595f | AtlComModuleRegisterServer |
20 | 0x7c123e21 | AtlComModuleRevokeClassObjects |
22 | 0x7c1259e5 | AtlComModuleUnregisterServer |
30 | 0x7c121187 | AtlComPtrAssign |
31 | 0x7c12389a | AtlComQIPtrAssign |
61 | 0x7c1234ec | AtlCreateRegistrar |
26 | 0x7c124353 | AtlCreateTargetDC |
29 | 0x7c124481 | AtlDevModeW2A |
12 | 0x7c123d2a | AtlFreeMarshalStream |
54 | 0x7c1256a3 | AtlGetObjectSourceInterface |
34 | 0x7c123f08 | AtlGetVersion |
27 | 0x7c1243c1 | AtlHiMetricToPixel |
52 | 0x7c1246da | AtlIPersistPropertyBag_Load |
53 | 0x7c1248b6 | AtlIPersistPropertyBag_Save |
50 | 0x7c1253ba | AtlIPersistStreamInit_Load |
51 | 0x7c12553e | AtlIPersistStreamInit_Save |
32 | 0x7c1211e3 | AtlInternalQueryInterface |
56 | 0x7c124521 | AtlLoadTypeLib |
13 | 0x7c123d54 | AtlMarshalPtrInProc |
58 | 0x7c1251a9 | AtlModuleAddTermFunc |
28 | 0x7c124423 | AtlPixelToHiMetric |
49 | 0x7c124da0 | AtlRegisterClassCategoriesHelper |
19 | 0x7c124c8e | AtlRegisterTypeLib |
25 | 0x7c125234 | AtlSetErrorInfo |
55 | 0x7c124c0b | AtlUnRegisterTypeLib |
11 | 0x7c12505e | AtlUnadvise |
14 | 0x7c123da4 | AtlUnmarshalPtr |
23 | 0x7c12350e | AtlUpdateRegistryFromResourceD |
24 | 0x7c123e56 | AtlWaitWithMessageLoop |
43 | 0x7c121390 | AtlWinModuleAddCreateWndData |
44 | 0x7c1213f1 | AtlWinModuleExtractCreateWndData |
65 | 0x7c121284 | AtlWinModuleInit |
63 | 0x7c125b49 | AtlWinModuleRegisterClassExA |
62 | 0x7c1214dc | AtlWinModuleRegisterClassExW |
46 | 0x7c129009 | AtlWinModuleRegisterWndClassInfoA |
45 | 0x7c121656 | AtlWinModuleRegisterWndClassInfoW |
66 | 0x7c1212e5 | AtlWinModuleTerm |