分析类型 | 开始时间 | 结束时间 | 持续时间 | 分析引擎版本 |
---|---|---|---|---|
FILE | 2016-06-20 20:27:03 | 2016-06-20 20:39:22 | 739 秒 | 1.4-Maldun |
虚拟机机器名 | 标签 | 虚拟机管理 | 开机时间 | 关机时间 |
---|---|---|---|---|
win7-sp1-x64 | win7-sp1-x64 | KVM | 2016-06-20 20:27:17 | 2016-06-20 20:39:22 |
魔盾分数 |
---|
10.0Andromeda |
文件名 | Ip9440545.scr |
---|---|
文件大小 | 130048 字节 |
文件类型 | PE32 executable (GUI) Intel 80386, for MS Windows |
CRC32 | 5D16B7EF |
MD5 | 8b15a0a8111c7f07230a999501b560c2 |
SHA1 | 691f2c0351af68999908ca9688ecd59fe4205bea |
SHA256 | 38ebe74b7363f67072b4e1c79ab848e7cd429784376a03fdd067cd703929a7bf |
SHA512 | 2364762ea5905f230fa76c2b1b146efffe7b149914c33a3c609df54985d760f05d4504ff850538787a82aab4ee1a82b37d692a919edf24e1b76473b6097f4507 |
Ssdeep | 3072:Y4l3YiT5JrQVqJhqa4eFa8iXZOdDyQVgJ:Y639TXQVO4Oa5XZOdDd |
PEiD | 无匹配 |
Yara |
|
VirusTotal |
VirusTotal链接 VirusTotal扫描时间: 2016-06-20 12:24:15 扫描结果: 2/55 |
直接访问 | IP地址 | 国家名 |
---|---|---|
是 | 23.7.139.27 | United States |
否 | 92.243.95.172 | Russian Federation |
是 | 8.8.4.4 | United States |
否 | 46.101.52.119 | Russian Federation |
否 | 23.96.52.53 | United States |
否 | 168.181.185.90 | unknown |
否 | 108.61.73.243 | United States |
否 | 104.43.195.251 | unknown |
否 | 104.40.211.35 | unknown |
是 | 150.138.151.192 | China |
域名 | 响应 |
---|---|
europe.pool.ntp.org |
A 5.9.80.113
A 82.220.2.2 A 144.76.14.132 A 46.101.52.119 |
north-america.pool.ntp.org |
A 137.190.2.4
A 64.6.144.6 A 64.34.171.122 A 108.61.73.243 |
south-america.pool.ntp.org |
A 190.15.128.72
A 200.89.75.198 A 168.181.185.90 A 201.49.148.135 |
microsoft.com |
A 104.40.211.35
A 104.43.195.251 A 23.100.122.175 A 191.239.213.197 A 23.96.52.53 |
secure.adnxs.eskey.it | A 92.243.95.172 |
distroi.pilenga.co.uk | NXDOMAIN |
dns.msftncsi.com | A 131.107.255.255 |
dns.msftncsi.com | AAAA fd3e:4f5a:5b81::1 |
IP地址 | 端口 |
---|---|
92.243.95.172 | 80 |
92.243.95.172 | 80 |
92.243.95.172 | 80 |
92.243.95.172 | 80 |
92.243.95.172 | 80 |
92.243.95.172 | 80 |
92.243.95.172 | 80 |
92.243.95.172 | 80 |
92.243.95.172 | 80 |
92.243.95.172 | 80 |
IP地址 | 端口 |
---|---|
108.61.73.243 | 123 |
168.181.185.90 | 123 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.255 | 137 |
192.168.122.255 | 138 |
46.101.52.119 | 123 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
8.8.4.4 | 53 |
URL | HTTP数据 |
---|---|
http://secure.adnxs.eskey.it/new_and/state.php | POST /new_and/state.php HTTP/1.1 Cache-Control: no-cache Connection: close Pragma: no-cache Content-Type: application/octet-stream User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; InfoPath.3) Content-Length: 74 Host: secure.adnxs.eskey.it |
初始地址 | 0x00400000 |
---|---|
入口地址 | 0x0040fba6 |
声明校验值 | 0x00029efe |
实际校验值 | 0x00029efe |
最低操作系统版本要求 | 5.0 |
编译时间 | 2016-06-18 10:48:23 |
名称 | 虚拟地址 | 虚拟大小 | 原始数据大小 | 特征 | 熵(Entropy) |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0000f1c4 | 0x0000f200 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ | 7.07 |
.rdata | 0x00011000 | 0x00004076 | 0x00004200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 6.17 |
.data | 0x00016000 | 0x00003dd0 | 0x00003a00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 4.38 |
.rsrc | 0x0001a000 | 0x000076ac | 0x00007800 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 7.18 |
.reloc | 0x00022000 | 0x00001120 | 0x00001200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ | 4.77 |
名称 | 偏移量 | 大小 | 语言 | 子语言 | 熵(Entropy) | 文件类型 |
---|---|---|---|---|---|---|
GIF | 0x0001a3f0 | 0x00002a4e | LANG_ENGLISH | SUBLANG_ENGLISH_US | 7.75 | GIF image data, version 89a, 293 x 65 |
LANG | 0x0001e464 | 0x00001428 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 5.37 | GNU message catalog (little endian), revision 0.0, 53 messages |
LANG | 0x0001e464 | 0x00001428 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 5.37 | GNU message catalog (little endian), revision 0.0, 53 messages |
PNG | 0x00020678 | 0x00000a6d | LANG_ENGLISH | SUBLANG_ENGLISH_US | 7.53 | PNG image data, 885 x 37, 8-bit/color RGBA, non-interlaced |
PNG | 0x00020678 | 0x00000a6d | LANG_ENGLISH | SUBLANG_ENGLISH_US | 7.53 | PNG image data, 885 x 37, 8-bit/color RGBA, non-interlaced |
XML | 0x000210e8 | 0x00000168 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 5.01 | XML document text |
RT_DIALOG | 0x00021414 | 0x00000040 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 2.53 | data |
RT_DIALOG | 0x00021414 | 0x00000040 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 2.53 | data |
RT_DIALOG | 0x00021414 | 0x00000040 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 2.53 | data |
RT_DIALOG | 0x00021414 | 0x00000040 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 2.53 | data |
RT_DIALOG | 0x00021414 | 0x00000040 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 2.53 | data |
RT_DIALOG | 0x00021414 | 0x00000040 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 2.53 | data |
RT_DIALOG | 0x00021414 | 0x00000040 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 2.53 | data |
RT_DIALOG | 0x00021414 | 0x00000040 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 2.53 | data |
RT_MANIFEST | 0x00021454 | 0x00000256 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 5.02 | ASCII text, with CRLF line terminators |
文件名 | mstfoogq.exe |
---|---|
相关文件 |
|
文件大小 | 130048 bytes |
文件类型 | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 8b15a0a8111c7f07230a999501b560c2 |
SHA1 | 691f2c0351af68999908ca9688ecd59fe4205bea |
SHA256 | 38ebe74b7363f67072b4e1c79ab848e7cd429784376a03fdd067cd703929a7bf |
SHA512 | 2364762ea5905f230fa76c2b1b146efffe7b149914c33a3c609df54985d760f05d4504ff850538787a82aab4ee1a82b37d692a919edf24e1b76473b6097f4507 |
Ssdeep | 3072:Y4l3YiT5JrQVqJhqa4eFa8iXZOdDyQVgJ:Y639TXQVO4Oa5XZOdDd |
Yara |
|
VirusTotal | 搜索相关分析 |