分析类型 | 开始时间 | 结束时间 | 持续时间 | 分析引擎版本 |
---|---|---|---|---|
FILE | 2018-07-09 20:21:28 | 2018-07-09 20:23:48 | 140 秒 | 1.4-Maldun |
虚拟机机器名 | 标签 | 虚拟机管理 | 开机时间 | 关机时间 |
---|---|---|---|---|
win7-sp1-x64-shaapp01-2 | win7-sp1-x64-shaapp01-2 | KVM | 2018-07-09 20:21:28 | 2018-07-09 20:23:46 |
魔盾分数 |
---|
10.0恶意的 |
文件名 | 最新的合同.bat |
---|---|
文件大小 | 480 字节 |
文件类型 | Little-endian UTF-16 Unicode text, with no line terminators |
CRC32 | 1FBA0C0E |
MD5 | 92aa86147a96d93a5584957764fff7f7 |
SHA1 | a7b31ee0db80f4da8e7cfefb607fb10a060b8048 |
SHA256 | 822e358dac14cf6db1506e5c135a95ee4a69e950de6d986f20dda7e3b00cea14 |
SHA512 | 37594220bcb3ed5497fa3491d7a10a8a46c33f762a4b40db3ccd4ee808ea72a7a7a054cc58ca9d9d955e43a70b5fd21789306c41d8ccc27323a68207f00a71b4 |
Ssdeep | 12:Q/Eaeb1KVX11P8Jm5lWpWZhQJeH9FPWRqrk20:QCSXLPxqJenOw0 |
PEiD | 无匹配 |
Yara |
|
VirusTotal | 无此文件扫描结果 |
直接访问 | IP地址 | 国家名 |
---|---|---|
否 | 222.187.232.9 | China |
否 | 47.75.173.43 | Canada |
域名 | 响应 |
---|---|
www.xiaobaremotecontrol.xyz | A 47.75.173.43 |
mine.ppxxmr.com | A 222.187.232.9 |
IP地址 | 端口 |
---|---|
222.187.232.9 | 5555 |
47.75.173.43 | 80 |
47.75.173.43 | 80 |
47.75.173.43 | 8080 |
IP地址 | 端口 |
---|---|
192.168.122.1 | 53 |
192.168.122.1 | 53 |
URL | HTTP数据 |
---|---|
http://www.xiaobaremotecontrol.xyz/sct/sct_BCX.sct | GET /sct/sct_BCX.sct HTTP/1.1 Accept: */* UA-CPU: AMD64 Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; InfoPath.3; .NET4.0C; .NET4.0E) Host: www.xiaobaremotecontrol.xyz Connection: Keep-Alive |
http://www.xiaobaremotecontrol.xyz/hta/BCX.hta | GET /hta/BCX.hta HTTP/1.1 Accept: */* Accept-Language: zh-CN UA-CPU: AMD64 Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; InfoPath.3; .NET4.0C; .NET4.0E) Host: www.xiaobaremotecontrol.xyz Connection: Keep-Alive |
http://www.xiaobaremotecontrol.xyz:8080/SGTool.exe | GET /SGTool.exe HTTP/1.1 Host: www.xiaobaremotecontrol.xyz:8080 Connection: Keep-Alive |
文件名 | error[1] |
---|---|
相关文件 |
|
文件大小 | 3138 bytes |
文件类型 | HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators |
MD5 | 9bba08a58fda3049383d1390bcfa8277 |
SHA1 | 919f125817eae113c9b4c6a0c5f18a37fb60f095 |
SHA256 | bfbe066acb5bf3459b4a221a1686d993a4b25dbb9b0b7de0ae965bb34797e109 |
SHA512 | bec5ffa97d18fb0d7be2de988e627757800969210f06f840d950ee3d0de99730dd26dcdc0f34ae9ac535eb8030c9de3445546a309ef436dd6cfdcfc15e5af80d |
Ssdeep | 96:lkMd1/TxjqDppzwO8ddFAdd5Eddd1hddv+dd8QFhlls1MH5:lXwpq+y1FWDls1MH5 |
VirusTotal | 搜索相关分析 |