分析类型 | 开始时间 | 结束时间 | 持续时间 | 分析引擎版本 |
---|---|---|---|---|
FILE | 2019-08-16 10:30:20 | 2019-08-16 10:33:03 | 163 秒 | 1.4-Maldun |
虚拟机机器名 | 标签 | 虚拟机管理 | 开机时间 | 关机时间 |
---|---|---|---|---|
win7-sp1-x64-hpdapp01-1 | win7-sp1-x64-hpdapp01-1 | KVM | 2019-08-16 10:30:42 | 2019-08-16 10:33:04 |
魔盾分数 |
---|
10.0恶意的 |
文件名 | ZSsafe.exe |
---|---|
文件大小 | 3213573 字节 |
文件类型 | PE32 executable (GUI) Intel 80386, for MS Windows |
CRC32 | B6815DA2 |
MD5 | 78cc1fbaa1a89984591c90218e9d8806 |
SHA1 | 400d6f503ba76129e9d2f9fe77c65f6cceb24f47 |
SHA256 | c1f8a2be52e1739a4d8475f97f73daeae71af56bcd5bf468862b38b5f7e4a10b |
SHA512 | 6e6c223906cd59206f28dbbfc28c52c955efe606ce51e330c6c79dda233d0779f0e806a117b298271be4f43f1c4148f7094ab0a92312e20486f9b028f356feef |
Ssdeep | 49152:7fkH7Ag+ZNBaX5FvI6zZDQ6Y3eqa3rpq9nBmuT+xahqg2ryR7KmBS2RBokBF45ck:Dr9aX5l83f0rcBtTUao7yq27okBa5oA |
PEiD | 无匹配 |
Yara |
|
VirusTotal |
VirusTotal链接 VirusTotal扫描时间: 2019-08-16 02:27:17 扫描结果: 45/67 |
直接访问 | IP地址 | 国家名 |
---|---|---|
否 | 119.23.59.239 | China |
否 | 122.114.130.31 | China |
否 | 123.58.180.39 | China |
域名 | 响应 |
---|---|
mojunxie521.blog.163.com |
A 123.58.180.101
A 123.58.180.39 |
2018k.cn | A 119.23.59.239 |
yuanlin.6600.org | A 122.114.130.31 |
IP地址 | 端口 |
---|---|
119.23.59.239 | 80 |
119.23.59.239 | 80 |
122.114.130.31 | 80 |
IP地址 | 端口 |
---|---|
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
192.168.122.1 | 53 |
URL | HTTP数据 |
---|---|
http://2018k.cn/api | GET /api HTTP/1.1 Cache-Control: no-cache Connection: Keep-Alive Accept: text/html, application/xhtml+xml, */* Accept-Encoding: gbk, GB2312 Accept-Language: zh-cn User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0) Host: 2018k.cn |
http://2018k.cn/api/ | GET /api/ HTTP/1.1 Cache-Control: no-cache Connection: Keep-Alive Accept: text/html, application/xhtml+xml, */* Accept-Encoding: gbk, GB2312 Accept-Language: zh-cn User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0) Host: 2018k.cn |
http://yuanlin.6600.org/cansu521.txt | GET /cansu521.txt HTTP/1.1 Accept: application/x-ms-application, image/jpeg, application/xaml+xml, image/gif, image/pjpeg, application/x-ms-xbap, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */* Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: yuanlin.6600.org Connection: Keep-Alive |
http://2018k.cn/api/checkVersion?id=abebaa2cbd49475f9ad45be62b11f3d1&version=1.2.8.6 | GET /api/checkVersion?id=abebaa2cbd49475f9ad45be62b11f3d1&version=1.2.8.6 HTTP/1.1 Cache-Control: no-cache Connection: Keep-Alive Accept: text/html, application/xhtml+xml, */* Accept-Encoding: gbk, GB2312 Accept-Language: zh-cn User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0) Host: 2018k.cn |
http://2018k.cn/api/checkVersion?id=abebaa2cbd49475f9ad45be62b11f3d1&html=true.html | GET /api/checkVersion?id=abebaa2cbd49475f9ad45be62b11f3d1&html=true.html HTTP/1.1 Accept: application/x-ms-application, image/jpeg, application/xaml+xml, image/gif, image/pjpeg, application/x-ms-xbap, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */* Accept-Language: zh-cn Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: 2018k.cn Connection: Keep-Alive |
初始地址 | 0x00400000 |
---|---|
入口地址 | 0x00401000 |
声明校验值 | 0x00000000 |
实际校验值 | 0x00315d2c |
最低操作系统版本要求 | 4.0 |
编译时间 | 1972-12-25 13:33:23 |
载入哈希 | 469b1bae2575baede5bf1f06a01b4767 |
LegalCopyright: | \u901d\u53bb\u7684\u9752\u6625 \u7248\u6743\u6240\u6709 |
FileVersion: | 1.1.6.8 |
CompanyName: | \u901d\u53bb\u7684\u9752\u6625 |
Comments: | \u672c\u7a0b\u5e8f\u4f7f\u7528\u6613\u8bed\u8a00\u7f16\u5199(http://www.eyuyan.com) |
ProductName: | ZSsafe |
ProductVersion: | 1.1.6.8 |
FileDescription: | ZSsafe\u4e3b\u7a0b\u5e8f |
Translation: | 0x0804 0x04b0 |
名称 | 虚拟地址 | 虚拟大小 | 原始数据大小 | 特征 | 熵(Entropy) |
---|---|---|---|---|---|
.UPX1 | 0x00001000 | 0x001c6000 | 0x00000200 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ | 1.36 |
.UPX1 | 0x001c7000 | 0x0014ca75 | 0x001485b3 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 7.88 |
偏移量: | 0x0030e791 |
大小: | 0x00002174 |