18.0
0-day

45e9481702b87e03705d35c12c5a8a3d795d42f91d562cba539999846c729686

09fd8604639fa6f0d6a0d2a844c82ce8.exe

分析耗时

129s

最近分析

文件大小

236.5KB
静态报毒 动态报毒 100% AGEN AGENSLA AI SCORE=100 AITX ATTRIBUTE CLOUD CONFIDENCE CRYSIS DHARMA ELDORADO GDSDA GENERICRXKL HIGH CONFIDENCE HIGHCONFIDENCE KRYPTIK MALICIOUS PE MALWARE@#3M1XLCAT0X0K2 NANOCORE OMW@AQHQIDI PWSX QQPASS QQROB S13328749 SCORE SUSGEN THFAOBO TROJANPSW TSCOPE UNSAFE URSU WACATAC ZEMSILF 更多
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
McAfee GenericRXKL-TO!09FD8604639F 20200724 6.0.6.653
Alibaba TrojanPSW:MSIL/NanoCore.8a7ef6ff 20190527 0.3.0.5
Baidu 20190318 1.0.0.2
Avast Win32:PWSX-gen [Trj] 20200724 18.4.3895.0
Kingsoft 20200724 2013.8.14.323
Tencent Msil.Trojan-qqpass.Qqrob.Jcv 20200724 1.0.0.1
CrowdStrike win/malicious_confidence_100% (W) 20190702 1.0
静态指标
Queries for the computername (2 个事件)
Time & API Arguments Status Return Repeated
1620121084.01875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620121084.86275
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
Checks if process is being debugged by a debugger (4 个事件)
Time & API Arguments Status Return Repeated
1620119614.199184
IsDebuggerPresent
failed 0 0
1620119614.199184
IsDebuggerPresent
failed 0 0
1620121084.12775
IsDebuggerPresent
failed 0 0
1620121086.815625
IsDebuggerPresent
failed 0 0
Uses Windows APIs to generate a cryptographic key (3 个事件)
Time & API Arguments Status Return Repeated
1620119615.512184
CryptExportKey
crypto_handle: 0x00760cb0
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1620119615.512184
CryptExportKey
crypto_handle: 0x00760cb0
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1620119615.543184
CryptExportKey
crypto_handle: 0x00760bf0
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
Tries to locate where the browsers are installed (1 个事件)
file C:\Program Files\Google\Chrome\Application\89.0.4389.114\libGLESv2.dll
Checks amount of memory in system, this can be used to detect virtual machines that have a low amount of memory available (1 个事件)
Time & API Arguments Status Return Repeated
1620119614.230184
GlobalMemoryStatusEx
success 1 0
One or more processes crashed (1 个事件)
Time & API Arguments Status Return Repeated
1620119616.246184
__exception__
stacktrace:
0x5a091c
0x5a022d
DllUnregisterServerInternal-0x3e21 clr+0x21db @ 0x73e721db
CoUninitializeEE+0x6862 DllRegisterServerInternal-0xc91e clr+0x24a2a @ 0x73e94a2a
CoUninitializeEE+0x6a04 DllRegisterServerInternal-0xc77c clr+0x24bcc @ 0x73e94bcc
CoUninitializeEE+0x6a39 DllRegisterServerInternal-0xc747 clr+0x24c01 @ 0x73e94c01
CoUninitializeEE+0x6a59 DllRegisterServerInternal-0xc727 clr+0x24c21 @ 0x73e94c21
GetCLRFunction+0xc08 GetMetaDataPublicInterfaceFromInternal-0x8a65 clr+0xece82 @ 0x73f5ce82
GetCLRFunction+0xd16 GetMetaDataPublicInterfaceFromInternal-0x8957 clr+0xecf90 @ 0x73f5cf90
GetCLRFunction+0xb2a GetMetaDataPublicInterfaceFromInternal-0x8b43 clr+0xecda4 @ 0x73f5cda4
GetCLRFunction+0xf1f GetMetaDataPublicInterfaceFromInternal-0x874e clr+0xed199 @ 0x73f5d199
GetCLRFunction+0xe20 GetMetaDataPublicInterfaceFromInternal-0x884d clr+0xed09a @ 0x73f5d09a
_CorExeMain+0x1c SetRuntimeInfo-0x181d clr+0x16af00 @ 0x73fdaf00
_CorExeMain+0x38 _CorExeMain2-0x134 mscoreei+0x55ab @ 0x752655ab
CreateConfigStream+0x13f GetProcessExecutableHeap-0xad6 mscoree+0x7f16 @ 0x754e7f16
_CorExeMain+0x8 CreateConfigStream-0x2ff4 mscoree+0x4de3 @ 0x754e4de3
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77d69ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77d69ea5

registers.esp: 2814244
registers.edi: 2814620
registers.eax: 0
registers.ebp: 2814276
registers.edx: 38499920
registers.ebx: 0
registers.esi: 37992204
registers.ecx: 0
exception.instruction_r: 8b 50 04 83 c2 01 0f 80 7a 02 00 00 b9 5a 43 c1
exception.instruction: mov edx, dword ptr [eax + 4]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x5ab544
success 0 0
行为判定
动态指标
One or more potentially interesting buffers were extracted, these generally contain injected code, configuration data, etc.
Allocates read-write-execute memory (usually to unpack itself) (50 out of 57 个事件)
Time & API Arguments Status Return Repeated
1620119613.449184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 917504
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 8192 (MEM_RESERVE)
base_address: 0x00520000
success 0 0
1620119613.449184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x005c0000
success 0 0
1620119613.855184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 2228224
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 8192 (MEM_RESERVE)
base_address: 0x02210000
success 0 0
1620119613.855184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x023f0000
success 0 0
1620119614.027184
NtProtectVirtualMemory
process_identifier: 472
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x73e71000
success 0 0
1620119614.199184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 1769472
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 8192 (MEM_RESERVE)
base_address: 0x02020000
success 0 0
1620119614.199184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x02190000
success 0 0
1620119614.199184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x0039a000
success 0 0
1620119614.199184
NtProtectVirtualMemory
process_identifier: 472
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x73e72000
success 0 0
1620119614.199184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00392000
success 0 0
1620119614.527184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003a2000
success 0 0
1620119614.683184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003c5000
success 0 0
1620119614.683184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003cb000
success 0 0
1620119614.683184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003c7000
success 0 0
1620119614.887184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003a3000
success 0 0
1620119614.933184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003a4000
success 0 0
1620119614.965184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003ac000
success 0 0
1620119615.074184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x005a0000
success 0 0
1620119615.121184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003a5000
success 0 0
1620119615.183184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003a6000
success 0 0
1620119615.199184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003a7000
success 0 0
1620119615.199184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x005a1000
success 0 0
1620119615.324184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003a8000
success 0 0
1620119615.324184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x005bf000
success 0 0
1620119615.324184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x005b0000
success 0 0
1620119615.355184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003a9000
success 0 0
1620119615.371184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 16384
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x005a2000
success 0 0
1620119615.418184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003b6000
success 0 0
1620119615.418184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x005a6000
success 0 0
1620119615.465184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003ba000
success 0 0
1620119615.465184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003b7000
success 0 0
1620119615.480184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x005a7000
success 0 0
1620119615.496184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x005a8000
success 0 0
1620119615.527184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00700000
success 0 0
1620119615.558184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x02191000
success 0 0
1620119615.558184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x02192000
success 0 0
1620119615.574184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 12288
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x02193000
success 0 0
1620119615.574184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 16384
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x02196000
success 0 0
1620119615.574184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 20480
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x0219a000
success 0 0
1620119615.715184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00701000
success 0 0
1620119615.746184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00702000
success 0 0
1620119615.902184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00703000
success 0 0
1620119615.902184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003ad000
success 0 0
1620119616.043184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00704000
success 0 0
1620119616.090184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x005a9000
success 0 0
1620119616.105184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x005aa000
success 0 0
1620119666.277184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 16384
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x0219f000
success 0 0
1620119666.277184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 69632
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x021a3000
success 0 0
1620119666.402184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00705000
success 0 0
1620119666.402184
NtAllocateVirtualMemory
process_identifier: 472
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00706000
success 0 0
A process attempted to delay the analysis task. (1 个事件)
description 09fd8604639fa6f0d6a0d2a844c82ce8.exe tried to sleep 291 seconds, actually delayed analysis time by 291 seconds
Steals private information from local Internet browsers (17 个事件)
file \\OSKAR-PC\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db.id-38C63B41.[3441546223@qq.com].ncov
file \\OSKAR-PC\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
file \\OSKAR-PC\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt
file UNC\OSKAR-PC\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log
file UNC\OSKAR-PC\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt
file UNC\OSKAR-PC\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log.id-38C63B41.[3441546223@qq.com].ncov
file UNC\OSKAR-PC\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db
file UNC\OSKAR-PC\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt.id-38C63B41.[3441546223@qq.com].ncov
file UNC\OSKAR-PC\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db.id-38C63B41.[3441546223@qq.com].ncov
file \\OSKAR-PC\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log.id-38C63B41.[3441546223@qq.com].ncov
file UNC\OSKAR-PC\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat.id-38C63B41.[3441546223@qq.com].ncov
file UNC\OSKAR-PC\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
file UNC\OSKAR-PC\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000003.log
file \\OSKAR-PC\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db
file \\OSKAR-PC\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt.id-38C63B41.[3441546223@qq.com].ncov
file \\OSKAR-PC\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log
file \\OSKAR-PC\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat.id-38C63B41.[3441546223@qq.com].ncov
Creates executable files on the filesystem (3 个事件)
file C:\Windows\System32\09fd8604639fa6f0d6a0d2a844c82ce8.exe
file C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\09fd8604639fa6f0d6a0d2a844c82ce8.exe
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\09fd8604639fa6f0d6a0d2a844c82ce8.exe
Creates a shortcut to an executable file (50 out of 80 个事件)
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Speech Recognition.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sync Center.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\Python Manuals.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\Module Docs.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Information.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\NetworkProjection.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\More Games from Microsoft.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Task Scheduler.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Backup and Restore Center.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Hearts.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Create Recovery Disc.lnk
file C:\Program Files\Microsoft Games\Solitaire\SolitaireMCE.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Restore.lnk
file C:\Program Files\Microsoft Games\SpiderSolitaire\SpiderSolitaireMCE.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Chess.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Resource Monitor.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\IDLE (Python GUI).lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Solitaire.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Purble Place.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\Python (command line).lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Remote Assistance.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer Reports.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Minesweeper.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell (x86).lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\Uninstall Python.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE (x86).lnk
file C:\Program Files\Microsoft Games\Hearts\HeartsMCE.lnk
Creates a suspicious process (1 个事件)
cmdline C:\Windows\System32\cmd.exe
Searches running processes potentially to identify processes for sandbox evasion, code injection or memory dumping (22 个事件)
The binary likely contains encrypted or compressed data indicative of a packer (2 个事件)
entropy 7.032293996877585 section {'size_of_data': '0x0003ac00', 'virtual_address': '0x00002000', 'entropy': 7.032293996877585, 'name': '.text', 'virtual_size': '0x0003aa28'} description A section with a high entropy has been found
entropy 0.9957627118644068 description Overall entropy of this PE file is high
Checks for the Locally Unique Identifier on the system for a suspicious privilege (2 个事件)
Time & API Arguments Status Return Repeated
1620119616.183184
LookupPrivilegeValueW
system_name:
privilege_name: SeDebugPrivilege
success 1 0
1620121095.846875
LookupPrivilegeValueW
system_name:
privilege_name: SeBackupPrivilege
success 1 0
Repeatedly searches for a not-found process, you may want to run a web browser during analysis (50 out of 84 个事件)
Time & API Arguments Status Return Repeated
1620121084.01875
Process32NextW
process_name: cmd.exe
snapshot_handle: 0x00000150
process_identifier: 2412
failed 0 0
1620121084.59675
Process32NextW
process_name: mode.com
snapshot_handle: 0x0000021c
process_identifier: 1740
failed 0 0
1620121085.42475
Process32NextW
process_name: inject-x64.exe
snapshot_handle: 0x00000250
process_identifier: 2264
failed 0 0
1620121085.98775
Process32NextW
process_name: mode.com
snapshot_handle: 0x00000248
process_identifier: 1740
failed 0 0
1620121086.59675
Process32NextW
process_name: mode.com
snapshot_handle: 0x000001f0
process_identifier: 1740
failed 0 0
1620121087.17475
Process32NextW
process_name: mode.com
snapshot_handle: 0x00000208
process_identifier: 1740
failed 0 0
1620121088.76875
Process32NextW
process_name: inject-x64.exe
snapshot_handle: 0x000001ec
process_identifier: 3008
failed 0 0
1620121090.01875
Process32NextW
process_name: is32bit.exe
snapshot_handle: 0x000001a8
process_identifier: 1124
failed 0 0
1620121091.11275
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x00000240
process_identifier: 1816
failed 0 0
1620121092.23775
Process32NextW
process_name: vssadmin.exe
snapshot_handle: 0x000001e0
process_identifier: 2948
failed 0 0
1620121093.29975
Process32NextW
process_name: inject-x64.exe
snapshot_handle: 0x000002a8
process_identifier: 2428
failed 0 0
1620121094.47175
Process32NextW
process_name: inject-x64.exe
snapshot_handle: 0x000002d8
process_identifier: 2428
failed 0 0
1620121095.19075
Process32NextW
process_name: vssadmin.exe
snapshot_handle: 0x0000029c
process_identifier: 2948
failed 0 0
1620121096.08075
Process32NextW
process_name: vssadmin.exe
snapshot_handle: 0x0000029c
process_identifier: 2948
failed 0 0
1620121096.69075
Process32NextW
process_name: vssadmin.exe
snapshot_handle: 0x000002a8
process_identifier: 2948
failed 0 0
1620121097.31575
Process32NextW
process_name: vssadmin.exe
snapshot_handle: 0x000002e0
process_identifier: 2948
failed 0 0
1620121098.00275
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x00000304
process_identifier: 3184
failed 0 0
1620121098.90875
Process32NextW
process_name: VSSVC.exe
snapshot_handle: 0x000002f4
process_identifier: 3204
failed 0 0
1620121101.15875
Process32NextW
process_name: VSSVC.exe
snapshot_handle: 0x00000288
process_identifier: 3204
failed 0 0
1620121101.73775
Process32NextW
process_name: mscorsvw.exe
snapshot_handle: 0x00000308
process_identifier: 3236
failed 0 0
1620121102.56575
Process32NextW
process_name: mscorsvw.exe
snapshot_handle: 0x000001a8
process_identifier: 3236
failed 0 0
1620121103.15875
Process32NextW
process_name: mscorsvw.exe
snapshot_handle: 0x000002c8
process_identifier: 3236
failed 0 0
1620121103.75275
Process32NextW
process_name: mscorsvw.exe
snapshot_handle: 0x000002e4
process_identifier: 3236
failed 0 0
1620121104.56575
Process32NextW
process_name: mscorsvw.exe
snapshot_handle: 0x000002f4
process_identifier: 3236
failed 0 0
1620121105.31575
Process32NextW
process_name: mscorsvw.exe
snapshot_handle: 0x00000320
process_identifier: 3236
failed 0 0
1620121106.03375
Process32NextW
process_name: mscorsvw.exe
snapshot_handle: 0x0000032c
process_identifier: 3236
failed 0 0
1620121107.22175
Process32NextW
process_name: mscorsvw.exe
snapshot_handle: 0x000002c8
process_identifier: 3236
failed 0 0
1620121107.83075
Process32NextW
process_name: svchost.exe
snapshot_handle: 0x000002f8
process_identifier: 3288
failed 0 0
1620121108.45575
Process32NextW
process_name: svchost.exe
snapshot_handle: 0x00000320
process_identifier: 3288
failed 0 0
1620121109.19075
Process32NextW
process_name: svchost.exe
snapshot_handle: 0x0000030c
process_identifier: 3288
failed 0 0
1620121109.81575
Process32NextW
process_name: svchost.exe
snapshot_handle: 0x00000328
process_identifier: 3288
failed 0 0
1620121110.34675
Process32NextW
process_name: is32bit.exe
snapshot_handle: 0x00000314
process_identifier: 3340
failed 0 0
1620121111.29975
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x00000330
process_identifier: 3360
failed 0 0
1620121112.34675
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x00000354
process_identifier: 3360
failed 0 0
1620121113.39375
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x00000328
process_identifier: 3360
failed 0 0
1620121114.34675
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x00000350
process_identifier: 3360
failed 0 0
1620121114.98775
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x00000344
process_identifier: 3360
failed 0 0
1620121115.56575
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x0000029c
process_identifier: 3360
failed 0 0
1620121116.62775
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x00000174
process_identifier: 3360
failed 0 0
1620121117.23775
Process32NextW
process_name: is32bit.exe
snapshot_handle: 0x00000348
process_identifier: 3396
failed 0 0
1620121117.76875
Process32NextW
process_name: inject-x64.exe
snapshot_handle: 0x00000344
process_identifier: 3412
failed 0 0
1620121118.39375
Process32NextW
process_name: inject-x64.exe
snapshot_handle: 0x00000304
process_identifier: 3412
failed 0 0
1620121119.03375
Process32NextW
process_name: inject-x64.exe
snapshot_handle: 0x00000328
process_identifier: 3412
failed 0 0
1620121119.75275
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000002e0
process_identifier: 3360
failed 0 0
1620121120.39375
Process32NextW
process_name: inject-x64.exe
snapshot_handle: 0x000002e8
process_identifier: 3460
failed 0 0
1620121121.15875
Process32NextW
process_name: inject-x64.exe
snapshot_handle: 0x00000258
process_identifier: 3460
failed 0 0
1620121121.86275
Process32NextW
process_name: inject-x64.exe
snapshot_handle: 0x00000344
process_identifier: 3460
failed 0 0
1620121122.50275
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x00000350
process_identifier: 3360
failed 0 0
1620121123.08075
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x00000330
process_identifier: 3360
failed 0 0
1620121123.59675
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000001a8
process_identifier: 3360
failed 0 0
网络通信
Communicates with host for which no DNS query was performed (1 个事件)
host 172.217.24.14
Allocates execute permission to another process indicative of possible code injection (1 个事件)
Time & API Arguments Status Return Repeated
1620119666.793184
NtAllocateVirtualMemory
process_identifier: 2604
region_size: 102400
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0x0000021c
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x00400000
success 0 0
Installs itself for autorun at Windows startup (4 个事件)
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\09fd8604639fa6f0d6a0d2a844c82ce8.exe reg_value C:\Windows\System32\09fd8604639fa6f0d6a0d2a844c82ce8.exe
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini.id-38C63B41.[3441546223@qq.com].ncov
file C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\09fd8604639fa6f0d6a0d2a844c82ce8.exe
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\09fd8604639fa6f0d6a0d2a844c82ce8.exe
Attempts to detect Cuckoo Sandbox through the presence of a file (1 个事件)
file C:\Python27\agent.pyw
Potential code injection by writing to the memory of another process (2 个事件)
Time & API Arguments Status Return Repeated
1620119666.793184
WriteProcessMemory
process_identifier: 2604
buffer: MZÿÿ¸@Ⱥ´ Í!¸LÍ!This program cannot be run in DOS mode. $àgaT¤¤¤­~œ§¤®¿›¡¯¿›’¥Rich¤PELr¯¸Xà  žÔЩ°@…àÔ(0°°(.text%œž `.rdata6&°(¢@@.dataÕªà¨Ê@À
process_handle: 0x0000021c
base_address: 0x00400000
success 1 0
1620119666.808184
WriteProcessMemory
process_identifier: 2604
buffer: @
process_handle: 0x0000021c
base_address: 0x7efde008
success 1 0
Code injection by writing an executable or DLL to the memory of another process (1 个事件)
Time & API Arguments Status Return Repeated
1620119666.793184
WriteProcessMemory
process_identifier: 2604
buffer: MZÿÿ¸@Ⱥ´ Í!¸LÍ!This program cannot be run in DOS mode. $àgaT¤¤¤­~œ§¤®¿›¡¯¿›’¥Rich¤PELr¯¸Xà  žÔЩ°@…àÔ(0°°(.text%œž `.rdata6&°(¢@@.dataÕªà¨Ê@À
process_handle: 0x0000021c
base_address: 0x00400000
success 1 0
Used NtSetContextThread to modify a thread in a remote process indicative of process injection (2 个事件)
Process injection Process 472 called NtSetContextThread to modify thread in remote process 2604
Time & API Arguments Status Return Repeated
1620119666.808184
NtSetContextThread
thread_handle: 0x00000220
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 4237776
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 2604
success 0 0
Deletes a large number of files from the system indicative of ransomware, wiper malware or system destruction (50 out of 1090 个事件)
file C:\Python27\Lib\email\test\data\msg_17.txt
file C:\Python27\Lib\distutils\tests\__init__.py
file C:\Program Files\Google\Chrome\Application\89.0.4389.114\Locales\pl.pak
file C:\Python27\Lib\encodings\__init__.pyc
file C:\Python27\Lib\encodings\iso8859_13.py
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
file C:\Python27\Lib\email\mime\multipart.py
file C:\Python27\Lib\encodings\iso2022_jp_2.py
file C:\Python27\Lib\collections.pyc
file C:\Python27\Lib\codeop.py
file C:\Python27\Lib\ctypes\test\test_callbacks.py
file C:\Python27\Lib\site-packages\PIL\ContainerIO.pyc
file C:\Python27\Lib\ctypes\test\test_win32.py
file C:\Program Files (x86)\Google\Update\1.3.36.72\goopdateres_ta.dll
file C:\Python27\Lib\email\_parseaddr.pyc
file C:\Program Files (x86)\Google\Update\1.3.36.72\goopdateres_ro.dll
file C:\Python27\Lib\copy_reg.pyc
file C:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.Targets
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
file C:\Python27\Lib\encodings\cp855.py
file C:\Python27\Lib\email\test\data\msg_01.txt
file C:\Python27\Lib\bsddb\test\test_thread.py
file C:\Python27\include\pythonrun.h
file C:\Program Files\Microsoft Games\SpiderSolitaire\SpiderSolitaireMCE.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\displayswitch.lnk
file C:\Python27\Lib\bisect.pyc
file C:\Program Files\Google\Chrome\Application\89.0.4389.114\Locales\cs.pak
file C:\Python27\Lib\email\feedparser.py
file C:\Python27\include\dtoa.h
file C:\Program Files (x86)\Google\Update\1.3.36.72\psmachine.dll
file C:\Python27\Lib\netrc.pyc
file C:\Python27\Lib\distutils\log.py
file C:\Python27\Lib\antigravity.py
file C:\Python27\Lib\chunk.py
file C:\Python27\Lib\idlelib\idle.bat
file C:\Program Files (x86)\Google\Update\1.3.36.72\goopdateres_lv.dll
file C:\Python27\include\bufferobject.h
file C:\Program Files (x86)\Google\Update\1.3.36.72\goopdateres_ar.dll
file C:\Program Files (x86)\Google\Update\1.3.36.72\goopdateres_cs.dll
file C:\Python27\Lib\ctypes\test\test_struct_fields.py
file C:\Python27\Lib\distutils\command\build_py.py
file C:\Python27\Lib\site-packages\easy_install.pyc
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Remote Assistance.lnk
file C:\Python27\Lib\distutils\tests\test_bdist.py
file C:\Python27\Lib\logging\handlers.pyc
file C:\Program Files (x86)\Google\Update\1.3.36.72\goopdateres_sr.dll
file C:\Program Files (x86)\Google\Update\1.3.36.72\goopdateres_hi.dll
file C:\Program Files (x86)\Google\Update\1.3.36.72\goopdateres_kn.dll
file C:\Program Files (x86)\Google\Update\1.3.36.72\psuser_64.dll
file C:\Python27\Lib\encodings\cp862.py
Removes the Shadow Copy to avoid recovery of the system (1 个事件)
cmdline vssadmin delete shadows /all /quiet
Resumed a suspended thread in a remote process potentially indicative of process injection (2 个事件)
Process injection Process 472 resumed a thread in remote process 2604
Time & API Arguments Status Return Repeated
1620119667.043184
NtResumeThread
thread_handle: 0x00000220
suspend_count: 1
process_identifier: 2604
success 0 0
Uses suspicious command line tools or Windows utilities (1 个事件)
cmdline vssadmin delete shadows /all /quiet
Detects VirtualBox through the presence of a device (2 个事件)
file \??\VBoxGuest
file \??\VBoxMiniRdrDN
Detects VirtualBox through the presence of a file (10 个事件)
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxDisp.dll
dll C:\Windows\system32\VBoxMRXNP.dll
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxControl.exe
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxTray.exe
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxDrvInst.exe
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxWHQLFake.exe
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxGuest.sys
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxMouse.sys.id-38C63B41.[3441546223@qq.com].ncov
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxVideo.inf.id-38C63B41.[3441546223@qq.com].ncov
file C:\Program Files\Oracle\VirtualBox Guest Additions\uninst.exe.id-38C63B41.[3441546223@qq.com].ncov
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2020-05-16 19:16:21

Imports

Library mscoree.dll:
0x402000 _CorExeMain

Hosts

No hosts contacted.

TCP

Source Source Port Destination Destination Port
192.168.56.101 49186 192.168.56.1 139
192.168.56.101 49188 192.168.56.1 139
192.168.56.101 49191 192.168.56.1 139

UDP

Source Source Port Destination Destination Port
192.168.56.1 137 192.168.56.101 137
192.168.56.1 138 192.168.56.101 138
192.168.56.101 50534 114.114.114.114 53
192.168.56.101 51963 114.114.114.114 53
192.168.56.101 56539 114.114.114.114 53
192.168.56.101 58367 114.114.114.114 53
192.168.56.101 65004 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 123 20.189.79.72 time.windows.com 123
192.168.56.101 49235 224.0.0.252 5355
192.168.56.101 53657 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 57756 224.0.0.252 5355
192.168.56.101 57874 224.0.0.252 5355
192.168.56.101 60123 224.0.0.252 5355
192.168.56.101 62191 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900
192.168.56.101 56540 239.255.255.250 3702
192.168.56.101 56807 239.255.255.250 1900

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.