Greylist: www.shandian22.com
Neutral: note.youdao.com
Informational: Detected Entropy signature
Informational: Detected Rich Signature
Informational: Detected no presence of any attachment
Informational: Detected no presence of any image
Informational: Detected no presence of any url
Informational: ASPackv212AlexeySolodovnikov
Informational: ASProtectV2XDLLAlexeySolodovnikov
Process: 闪电活动助手 科学刀v2.9.6.exe
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
Process: 闪电活动助手 科学刀v2.9.6.exe
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
生成一个自己的复制文件
copy: C:\Users\test\AppData\Local\Temp\zip-tmp\\xe9\x97\xaa\xe7\x94\xb5\xe6\xb4\xbb\xe5\x8a\xa8\xe5\x8a\xa9\xe6\x89\x8b \xe7\xa7\x91\xe5\xad\xa6\xe5\x88\x80v2.9.6.exe
运行截图
网络分析
访问主机记录
直接访问 |
IP地址 |
国家名 |
否 |
46.232.249.248 |
unknown |
否 |
47.98.44.57 |
China |
否 |
59.111.179.136 |
China |
域名解析
域名 |
响应 |
www.shandian22.com |
A 47.98.44.57
|
note.youdao.com |
A 59.111.179.138
A 59.111.179.137
A 59.111.179.136
A 123.58.182.252
A 59.111.179.135
A 123.58.182.251
|
s2.ax1x.com |
A 46.232.249.248
A 94.16.116.44
|
TCP连接
IP地址 |
端口 |
46.232.249.248 |
443 |
46.232.249.248 |
443 |
47.98.44.57 |
443 |
47.98.44.57 |
1433 |
59.111.179.136 |
443 |
UDP连接
IP地址 |
端口 |
192.168.122.1 |
53 |
192.168.122.1 |
53 |
192.168.122.1 |
53 |
投放文件
\xc9\xc1\xb5\xe7\xbb\xee\xb6\xaf\xd6\xfa\xca\xd6 \xbf\xc6\xd1\xa7\xb5\xb6v2.9.6.exe
文件名 |
\xc9\xc1\xb5\xe7\xbb\xee\xb6\xaf\xd6\xfa\xca\xd6 \xbf\xc6\xd1\xa7\xb5\xb6v2.9.6.exe |
相关文件 |
- C:\Users\test\AppData\Local\Temp\zip-tmp\\xe9\x97\xaa\xe7\x94\xb5\xe6\xb4\xbb\xe5\x8a\xa8\xe5\x8a\xa9\xe6\x89\x8b \xe7\xa7\x91\xe5\xad\xa6\xe5\x88\x80v2.9.6.exe
|
文件大小 |
3061760 bytes |
文件类型 |
PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 |
e6fb704b0ef650f34e409c2c36067346 |
SHA1 |
f2e377b5c8d168ac675327c6065da8ef0761fb40 |
SHA256 |
d4c4e1402932fc065651f499f6e8e8e9377fe244b3516e2287de8990603ffa6e |
SHA512 |
a4d44a82c2222c65250cfeeec116eaea244e69365995003b6d1704760d7b912b4a79e99de18b4392e1a01175bf455700fa57a5a01fcf9e2f34585e7fd2d8fce4 |
Ssdeep |
49152:rB9K65G/x6e9FTOC9DIqA9madrAhG58jh3Lye/O4lqzJT2UVbgIl:9E6ScUpOC9UqIzdkhqKCiiJT2sgI |
VirusTotal |
搜索相关分析 |