2.2
中危

07fc2906cf59248af272ce460d21c631f295111fea9c17c059a5971d628eb681

001b820fb028362de214aa920afd480b.exe

分析耗时

72s

最近分析

文件大小

98.0KB
静态报毒 动态报毒 AIDETECT ARTEMIS BSCOPE CJA POTENTIALLY UNSAFE CLOUD GAMEHACK GENERIC PUA BI MALWARE2 PRESENOKER SAVE STATIC AI SUSPICIOUS PE TIGGRE UNSAFE 更多
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
McAfee Artemis!001B820FB028 20210312 6.0.6.653
Alibaba 20190527 0.3.0.5
CrowdStrike 20210203 1.0
Baidu 20190318 1.0.0.2
Avast 20210312 21.1.5827.0
Tencent 20210312 1.0.0.1
Kingsoft 20210312 2017.9.26.565
静态指标
This executable has a PDB path (1 个事件)
pdb_path G:\Downloads\csgo hax\external_esp_glow\Cs-Go-Glow-Esp-master\Release\Shadow.pdb
行为判定
动态指标
网络通信
Communicates with host for which no DNS query was performed (2 个事件)
host 172.217.24.14
host 58.63.233.66
File has been identified by 11 AntiVirus engines on VirusTotal as malicious (11 个事件)
Bkav W32.AIDetect.malware2
McAfee Artemis!001B820FB028
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
McAfee-GW-Edition Artemis
Sophos Generic PUA BI (PUA)
Microsoft PUA:Win32/Presenoker
ESET-NOD32 a variant of Win32/GameHack.CJA potentially unsafe
VBA32 BScope.Trojan.Tiggre
Rising PUA.Presenoker!8.F608 (CLOUD)
SentinelOne Static AI - Suspicious PE
Generates some ICMP traffic
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2018-07-29 01:49:50

Imports

Library KERNEL32.dll:
0x413000 CloseHandle
0x413004 Sleep
0x413008 CreateThread
0x41300c TerminateThread
0x413010 OpenProcess
0x413014 ReadProcessMemory
0x413018 WriteProcessMemory
0x41301c SetConsoleTitleA
0x413024 Process32Next
0x413028 Module32Next
0x41302c GetStartupInfoW
0x413030 IsDebuggerPresent
0x413034 InitializeSListHead
0x41303c GetCurrentThreadId
0x413040 GetCurrentProcessId
0x41304c TerminateProcess
0x413050 GetCurrentProcess
0x41305c GetModuleHandleW
Library USER32.dll:
0x4130b0 GetAsyncKeyState
Library VCRUNTIME140.dll:
0x4130c0 _CxxThrowException
0x4130c8 memset
0x4130d0 __CxxFrameHandler3
0x4130d4 memmove
0x4130d8 memcpy
0x4130dc memcmp
Library api-ms-win-crt-runtime-l1-1-0.dll:
0x41310c _c_exit
0x413114 __p___argv
0x413118 _initterm
0x413124 _seh_filter_dll
0x413128 __p___argc
0x413134 _crt_atexit
0x413138 _crt_at_quick_exit
0x41313c _controlfp_s
0x413140 terminate
0x413148 _initterm_e
0x41314c _seh_filter_exe
0x413150 _set_app_type
0x413154 _exit
0x413158 _cexit
0x413160 exit
Library api-ms-win-crt-string-l1-1-0.dll:
0x413178 strcmp
0x41317c strlen
Library api-ms-win-crt-utility-l1-1-0.dll:
0x41318c srand
0x413190 rand
Library api-ms-win-crt-time-l1-1-0.dll:
0x413184 _time64
Library api-ms-win-crt-heap-l1-1-0.dll:
0x4130e4 _callnewh
0x4130e8 free
0x4130ec _set_new_mode
0x4130f0 malloc
Library api-ms-win-crt-math-l1-1-0.dll:
0x413100 __setusermatherr
0x413104 _except1
Library api-ms-win-crt-stdio-l1-1-0.dll:
0x41316c __p__commode
0x413170 _set_fmode
Library api-ms-win-crt-locale-l1-1-0.dll:
0x4130f8 _configthreadlocale

Hosts

No hosts contacted.

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 50534 114.114.114.114 53
192.168.56.101 51963 114.114.114.114 53
192.168.56.101 56539 114.114.114.114 53
192.168.56.101 65004 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 49235 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 60123 224.0.0.252 5355
192.168.56.101 62191 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900
192.168.56.101 50535 239.255.255.250 3702
192.168.56.101 56540 239.255.255.250 3702
192.168.56.101 56807 239.255.255.250 1900
192.168.56.101 58707 239.255.255.250 3702

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.