分析类型 | 开始时间 | 结束时间 | 持续时间 | 分析引擎版本 |
---|---|---|---|---|
FILE | 2016-08-26 17:01:38 | 2016-08-26 17:02:18 | 40 秒 | 1.4-Maldun |
虚拟机机器名 | 标签 | 虚拟机管理 | 开机时间 | 关机时间 |
---|---|---|---|---|
win7-sp1-x64-1 | win7-sp1-x64-1 | KVM | 2016-08-26 17:01:38 | 2016-08-26 17:02:16 |
魔盾分数 |
---|
3.3可疑的 |
文件名 | MiniTPFw.exe |
---|---|
文件大小 | 59848 字节 |
文件类型 | PE32 executable (console) Intel 80386, for MS Windows |
CRC32 | 0E23C82A |
MD5 | 58bb62e88687791ad2ea5d8d6e3fe18b |
SHA1 | 0ffb029064741d10c9cf3f629202aa97167883de |
SHA256 | f02fa7ddab2593492b9b68e3f485e59eb755380a9235f6269705f6d219dff100 |
SHA512 | cd36b28f87be9cf718f0c44bf7c500d53186edc08889bcfa5222041ff31c5cbee509b186004480efbd99c36b2233182ae0969447f4051510e1771a73ed209da5 |
Ssdeep | 768:BSODywYihzSrVPdQsNruuGYOLO3NNkFlBi1jSZIfjeGdJARt03juFGu:BSKywYDdQsQuG5L27Ui1SPRt0qf |
PEiD | 无匹配 |
Yara |
|
VirusTotal |
VirusTotal链接 VirusTotal扫描时间: 2016-06-22 15:30:30 扫描结果: 0/55 |
直接访问 | IP地址 | 国家名 |
---|---|---|
是 | 23.44.155.27 | United States |
否 | 23.41.75.27 | United States |
域名 | 响应 |
---|---|
ocsp.verisign.com |
A 23.41.75.27
CNAME ocsp-ds.ws.symantec.com.edgekey.net CNAME e8218.dscb1.akamaiedge.net |
IP地址 | 端口 |
---|---|
23.41.75.27 | 80 |
IP地址 | 端口 |
---|---|
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.255 | 137 |
192.168.122.69 | 53197 |
192.168.122.69 | 64810 |
224.0.0.252 | 5355 |
224.0.0.252 | 5355 |
224.0.0.252 | 5355 |
224.0.0.252 | 5355 |
224.0.0.252 | 5355 |
224.0.0.252 | 5355 |
224.0.0.252 | 5355 |
224.0.0.252 | 5355 |
239.255.255.250 | 1900 |
40.69.40.157 | 123 |
URL | HTTP数据 |
---|---|
http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D | GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D HTTP/1.1 Connection: Keep-Alive Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: ocsp.verisign.com |
http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEAz%2FezKc%2F387jS1UKrJYJro%3D | GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEAz%2FezKc%2F387jS1UKrJYJro%3D HTTP/1.1 Connection: Keep-Alive Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: ocsp.verisign.com |
http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEAz%2FezKc%2F387jS1UKrJYJro%3D | GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEAz%2FezKc%2F387jS1UKrJYJro%3D HTTP/1.1 Cache-Control: no-cache Connection: Keep-Alive Pragma: no-cache Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: ocsp.verisign.com |
初始地址 | 0x00400000 |
---|---|
入口地址 | 0x00402cda |
声明校验值 | 0x00012a3f |
实际校验值 | 0x00012a3f |
最低操作系统版本要求 | 5.0 |
PDB路径 | d:\Project\MiniTPFw\MiniTPFw\Release\MiniTPFw.pdb |
编译时间 | 2014-01-07 14:46:58 |
LegalCopyright: | Copyright (c) 2014 Thunder Networking Technologies,LTD |
InternalName: | MiniTPFw |
FileVersion: | 1, 0, 0, 1 |
ProductName: | MiniTPFw Application |
ProductVersion: | 1, 0, 0, 1 |
FileDescription: | MiniTPFw Application |
OriginalFilename: | MiniTPFw.exe |
Translation: | 0x0804 0x04b0 |
名称 | 虚拟地址 | 虚拟大小 | 原始数据大小 | 特征 | 熵(Entropy) |
---|---|---|---|---|---|
.text | 0x00001000 | 0x00008aeb | 0x00008c00 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ | 6.51 |
.rdata | 0x0000a000 | 0x00002ab4 | 0x00002c00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 5.20 |
.data | 0x0000d000 | 0x00001a1c | 0x00000e00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 2.71 |
.rsrc | 0x0000f000 | 0x00000504 | 0x00000600 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 4.51 |
偏移量: | 0x0000d000 |
大小: | 0x000019c8 |
名称 | 偏移量 | 大小 | 语言 | 子语言 | 熵(Entropy) | 文件类型 |
---|---|---|---|---|---|---|
RT_VERSION | 0x0000f0a0 | 0x000002fc | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 3.37 | data |
RT_MANIFEST | 0x0000f39c | 0x00000165 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 4.78 | ASCII text, with CRLF line terminators |