分析类型 | 开始时间 | 结束时间 | 持续时间 | 分析引擎版本 |
---|---|---|---|---|
URL | 2018-05-21 19:54:40 | 2018-05-21 19:57:03 | 143 秒 | 1.4-Maldun |
虚拟机机器名 | 标签 | 虚拟机管理 | 开机时间 | 关机时间 |
---|---|---|---|---|
win7-sp1-x64-hpdapp03-1 | win7-sp1-x64-hpdapp03-1 | KVM | 2018-05-21 19:54:40 | 2018-05-21 19:57:00 |
魔盾分数 |
---|
0.05正常的 |
URL | http://khd.nwzhi.com/khd_nwzhi_start.dll?v=201801220416 |
---|---|
VirusTotal | VirusTotal无域名信息 |
直接访问 | IP地址 | 国家名 |
---|---|---|
否 | 58.216.106.208 | China |
域名 | 响应 |
---|---|
khd.nwzhi.com |
CNAME temp.p23.tc.cdntip.com
CNAME tiny.china.qiniu.cloud.cdntip.com CNAME iduxcfq.qiniudns.com A 180.101.217.205 A 180.101.217.192 A 180.101.217.117 A 221.228.218.203 A 58.216.106.210 A 221.228.219.107 A 58.216.106.208 A 221.228.219.71 A 221.228.218.214 CNAME tiny2.china.line.qiniudns.com A 180.101.217.196 |
IP地址 | 端口 |
---|---|
192.168.122.1 | 53 |
58.216.106.208 | 80 |
IP地址 | 端口 |
---|---|
192.168.122.1 | 53 |
192.168.122.1 | 53 |
URL | HTTP数据 |
---|---|
http://khd.nwzhi.com/khd_nwzhi_start.dll?v=201801220416 | GET /khd_nwzhi_start.dll?v=201801220416 HTTP/1.1 Accept: */* Referer: http://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=4&ved=0CCEQfjWVp5RlZpZkNDQ0lYVUZoT3lqaXB2&url=http%3A%2F%2Fkhd.nwzhi.com%2Fkhd_nwzhi_start.dll%3Fv%3D201801220416&ei=UkR1dGFPUUREWEFU&usg=AFQjaW9nZnFyQ05EdFZJ Accept-Language: zh-cn User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Host: khd.nwzhi.com Connection: Keep-Alive |
文件名 | index.dat |
---|---|
相关文件 |
|
文件大小 | 32768 bytes |
文件类型 | Internet Explorer cache file version Ver 5.2 |
MD5 | 0aee387ca0a52dcdd8f8a29ea76edb42 |
SHA1 | 5df81547dcadb2a7b8bc689da8e1383ba1a84cb9 |
SHA256 | c31bc37e102b70a472837d530ec80bdaea28b0fefda3e9aa8c8cda98c4200c4e |
SHA512 | 101bdb7178e031b1fbd78d595d778d06174749246cdcb70eb4b92af534910e30e0627147260ec319bccecf7a105c814b6b32c077a777fb5e90bd1459c78dcdf9 |
Ssdeep | 12:qjtSaFpbZli3zIoYDPO7em4GZj03W/cKYDPOCG5A30WUsOXQDG9YRm4GZ5:qj4avEIoYTCebGZ7ZYTlEJ0oQQ4bGZ |
VirusTotal | 搜索相关分析 |
文件名 | RecoveryStore.{BB754F03-5CED-11E8-91CC-525400E1D82E}.dat |
---|---|
相关文件 |
|
文件大小 | 3584 bytes |
文件类型 | Composite Document File V2 Document, Cannot read section info |
MD5 | d5fb5ecaf9bfbb758c8460d06b6f316c |
SHA1 | 76c7ea8bde0fc17cc524ee479d98c1e818ac8965 |
SHA256 | f5ecfa82b181af938bcaf7f7e887aa4809e06a5bedb3de8714f9d7b9aa77bec9 |
SHA512 | 6e10f10c8a8016d7d91da69ef65e656540bd64a716e59c9d7e19502c9af6ffa74416104f47085431cc1d307850d03f2ba5a60011ffdaddbb34647bf5e10dee17 |
Ssdeep | 12:rl0YmGF2trEg5+IaCrI017+FPDrEgmf+IaCy8qgQNlTqof5m0PlD0Pla40Pl:rIt5/AGv/TQNlWof5 |
VirusTotal | 搜索相关分析 |
文件名 | down[1] |
---|---|
相关文件 |
|
文件大小 | 3414 bytes |
文件类型 | PNG image data, 15 x 15, 8-bit/color RGBA, non-interlaced |
MD5 | 555e83ce7f5d280d7454af334571fb25 |
SHA1 | 47f78f68d72e3d9041acc9107a6b0d665f408385 |
SHA256 | 70f316a5492848bb8242d49539468830b353ddaa850964db4e60a6d2d7db4880 |
SHA512 | 021f2f0da228a23826cfddf2898e2b63787b3be2d94a49e58fc6973628b3995dc690ff7a80a09974b7769b45c7e5df953edb5632562c907273d7071af5ad253c |
Ssdeep | 96:/SDZ/I09Da01l+gmkyTt6Hk8nTjTnJw1Ne:/SDS0tKg9E05TPoNe |
VirusTotal | 搜索相关分析 |
文件名 | MSIMGSIZ.DAT |
---|---|
相关文件 |
|
文件大小 | 16384 bytes |
文件类型 | data |
MD5 | 133feee5310e20e4ba94e459bae8b3e4 |
SHA1 | 3683dd609fb29ed26d3f41f0f943914d29b6ffae |
SHA256 | 7cbd32f4a41694695e78f9ac3af6fe2e8afca7dc966f7904fa498269572d68b6 |
SHA512 | d350105dba6ef0b3945d4049a88019038b2786ebb3df3a78c84b05b75d942f869e9bfa04d7dec364329343ddf7f68e5b5af88304c3ecf5a048e031e6ab77a513 |
Ssdeep | 48:jGQhN7sXHWrVmqESaakad5PIy+9/8JrcVjdS6gPdY4z7el:CBXHbbSrka5PIL8mJdcPzz76 |
VirusTotal | 搜索相关分析 |
文件名 | info_48[1] |
---|---|
相关文件 |
|
文件大小 | 6993 bytes |
文件类型 | PNG image data, 47 x 48, 8-bit/color RGBA, non-interlaced |
MD5 | 49e0ef03e74704089a60c437085db89e |
SHA1 | c2e7ab3ce114465ea7060f2ef738afcb3341a384 |
SHA256 | caa140523ba00994536b33618654e379216261babaae726164a0f74157bb11ff |
SHA512 | fede6e06011d2203f0359ba7b178771e4dd6500af1c72dd13456f0fad0cde3b75b8709af68447d25b2b916126d85808579940aa24e25b2357d407afd1143da08 |
Ssdeep | 192:NS0tKg9E05THXQJBCnFux5TsRfb+Y0ObhD9Uc7:LXE05UBCFAORfK9S7b7 |
VirusTotal | 搜索相关分析 |
文件名 | index.dat |
---|---|
相关文件 |
|
文件大小 | 65536 bytes |
文件类型 | Internet Explorer cache file version Ver 5.2 |
MD5 | 0ee0d92f5ad9cd4d354a120734ae8e5e |
SHA1 | a3d2338356b933a1240f053b89efe7f1b5e63353 |
SHA256 | bd15c1573c53ac40e26c307c00be243ace57eb5fd0d2879349b24832d2e7a771 |
SHA512 | 126b0b6063509b59a2af9fe58d96ea741b3316af252b309000ab14b014dddde0b7bffbd9042bd2ce2194d3294677ae82c5470b8503470102b1b912f8ca309b9d |
Ssdeep | 384:wEEG/+oo0M7hPfdoW7QRyUEZeluUFyvp64PBhqNLguX3/5YSHYjitk9t7sub/2Iw:wEEG/+Rg |
VirusTotal | 搜索相关分析 |
文件名 | background_gradient[1] |
---|---|
相关文件 |
|
文件大小 | 453 bytes |
文件类型 | JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 1x800, frames 3 |
MD5 | 20f0110ed5e4e0d5384a496e4880139b |
SHA1 | 51f5fc61d8bf19100df0f8aadaa57fcd9c086255 |
SHA256 | 1471693be91e53c2640fe7baeecbc624530b088444222d93f2815dfce1865d5b |
SHA512 | 5f52c117e346111d99d3b642926139178a80b9ec03147c00e27f07aab47fe38e9319fe983444f3e0e36def1e86dd7c56c25e44b14efdc3f13b45ededa064db5a |
Ssdeep | 6:3llVuiPjlXJYhg5suRd8PImMo23C/kHrJ8yA/NIeYoWg78C/vTFvbKLAh3:V/XPYhiPRd8j7+9LoIrobtHTdbKi |
VirusTotal | 搜索相关分析 |
文件名 | ErrorPageTemplate[1] |
---|---|
相关文件 |
|
文件大小 | 2226 bytes |
文件类型 | UTF-8 Unicode (with BOM) text, with CRLF line terminators |
MD5 | 9e7f4ae3f245c70af5b7dbe095647d30 |
SHA1 | cbcffb08f72c10e3e2493ca0044872a7ebdc7215 |
SHA256 | 2f9117806e0e1ae4fc3b023b348910657b6948de2ecfd4f39f2846cebbefc1df |
SHA512 | 41948894968d3f39cccbb089fcd02ae20064c4c728c54b5fa0434d6d7af5dbcec5ac35d09ac07769d81fe590ad2c61d960b97eac030869199c6765d5a90cf1eb |
Ssdeep | 48:5sFR52FH5k5pvFehWrrarrZIrHd3FIQfOS6:5s52TydFPr81yHpBGR |
VirusTotal | 搜索相关分析 |
文件名 | bullet[1] |
---|---|
相关文件 |
|
文件大小 | 3169 bytes |
文件类型 | PNG image data, 15 x 15, 8-bit/color RGBA, non-interlaced |
MD5 | 0c4c086dd852704e8eeb8ff83e3b73d1 |
SHA1 | 56bac3d2c88a83628134b36322e37deb6b00b1a1 |
SHA256 | 1cb3b6ea56c5b5decf5e1d487ad51dbb2f62e6a6c78f23c1c81fda1b64f8db16 |
SHA512 | 8d975b96217e503d9fe01cf81d56500ef66a2dedd9ab70ebf0ad475f09522aef0107a6aae38e3c292bcdb206439611f1c2ce05aa692546ee8d56ba640d78bc4e |
Ssdeep | 48:VocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcOD2X+r0svw:VZ/I09Da01l+gmkyTt6Hk8nT2X+r0kw |
VirusTotal | 搜索相关分析 |
文件名 | {BB754F04-5CED-11E8-91CC-525400E1D82E}.dat |
---|---|
相关文件 |
|
文件大小 | 4608 bytes |
文件类型 | Composite Document File V2 Document, Cannot read section info |
MD5 | 37aef41afcc08b671de317ce88057bbb |
SHA1 | f72574378c92983ef88551ba8380bcf3aa38b611 |
SHA256 | f9974b089c5802e1ec61561abd548bcb005b301913cfa2a672122cf21561eb85 |
SHA512 | 881b113c97210bf9fe16dd120961686c50dd412df9bcf9c84cebd97fbad97f967fe5e2a38328ba3072dc30126e8f417dba00c342867b932071d7cf4ba74e7467 |
Ssdeep | 12:rlfFyrEgmfR16F0WrEgmfcB1qjNlYfOo3+/NlL9oAzAY3c:rWGKGTNljowNlpo8dc |
VirusTotal | 搜索相关分析 |
文件名 | errorPageStrings[1] |
---|---|
相关文件 |
|
文件大小 | 1643 bytes |
文件类型 | UTF-8 Unicode (with BOM) text, with CRLF line terminators |
MD5 | 13216fa0f896b1b7c445fe9a54b5b998 |
SHA1 | d343d35b45507640bc68487d4ad3afcb927ce950 |
SHA256 | 7a656b15efaacb1179b883327369819483b5a0c2f2d8486db6c347f4f8a7ae61 |
SHA512 | 721c2c387e0bf0f226aa45de1910bb82c44f138ee5c1ea93ea5b15a6310295b0bc718358965fe40b238c1dee0f4be3d7cff25020de5c51eecd72f038ab8b5a56 |
Ssdeep | 48:zGY5w5zquO05l9zWJ6N51Re45RnR5RynEK+5RXdHymL5RlRdPoh5y5U5BU5Cc:z5Qzq3crIM1RtR3Rynd6RXd5RTmnW4xc |
VirusTotal | 搜索相关分析 |
文件名 | http_403[1] |
---|---|
相关文件 |
|
文件大小 | 4542 bytes |
文件类型 | HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators |
MD5 | 5b60734d66bc3b523f2bc12c7bc06da2 |
SHA1 | e2648a430a93302108bc072e10f3fbcd0f177377 |
SHA256 | e15547a2e90df54a2b9240411ee76118978d0487f199bca6a9410822656ac7e6 |
SHA512 | 4c785961451414021138fcae0644e4236f5f268933751aebe93199186322b698ed3f48236bc2818726d81fda456a4c0abcdaef50630ece414f95ddf284d6c14d |
Ssdeep | 48:upUwQV4VOBXvLM5ZIPTC5sU1a5TIm7n3GFEUKGuc1kpTcuKmFXiTr:ugpg5ZQws7B36HgAuBoTr |
VirusTotal | 搜索相关分析 |
文件名 | httpErrorPagesScripts[1] |
---|---|
相关文件 |
|
文件大小 | 8601 bytes |
文件类型 | UTF-8 Unicode (with BOM) text, with CRLF, CR line terminators |
MD5 | e7ca76a3c9ee0564471671d500e3f0f3 |
SHA1 | fe815ae0f865ec4c26e421bf0bd21bb09bc6f410 |
SHA256 | 58268ca71a28973b756a48bbd7c9dc2f6b87b62ae343e582ce067c725275b63c |
SHA512 | 40d33112debdd440f169d3a62b06607afa94c45903c3e650093036b3af2d616310ad6e0a4774f92927295cd3967963d127f63df33c4e763f0d40f306aa52449e |
Ssdeep | 192:HMmjTiiKfi9Ii4UFjC9jo4oXdu7mjxAb3Y:smjTiiKfi9IiPj+k3Xdu7mjxAb3Y |
VirusTotal | 搜索相关分析 |