| section | {'name': 'UPX1', 'virtual_address': '0x0000e000', 'virtual_size': '0x00004000', 'size_of_data': '0x00003c00', 'entropy': 7.8826026615026645} | entropy | 7.8826026615026645 | description | 发现高熵的节 | |||||||||
| entropy | 0.967741935483871 | description | 此PE文件的整体熵值较高 | |||||||||||
| section | UPX0 | description | 节名称指示UPX | ||||||
| section | UPX1 | description | 节名称指示UPX | ||||||
| host | 114.114.114.114 | |||
| host | 8.8.8.8 | |||
| Name | Virtual Address | Virtual Size | Size of Raw Data | Entropy |
|---|---|---|---|---|
| UPX0 | 0x00001000 | 0x0000d000 | 0x00000000 | 0.0 |
| UPX1 | 0x0000e000 | 0x00004000 | 0x00003c00 | 7.8826026615026645 |
| .rsrc | 0x00012000 | 0x00001000 | 0x00000200 | 3.3640239376570715 |
| Name | Offset | Size | Language | Sub-language | File type |
|---|---|---|---|---|---|
| RT_RCDATA | 0x0000f0c0 | 0x00000080 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| RT_RCDATA | 0x0000f0c0 | 0x00000080 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| IP |
|---|
| 114.114.114.114 |
| 8.8.8.8 |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| dns.msftncsi.com | A 131.107.255.255 | 131.107.255.255 |
| dns.msftncsi.com | 131.107.255.255 |
No TCP connections recorded.
| Source | Source Port | Destination | Destination Port |
|---|---|---|---|
| 192.168.56.101 | 53179 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 49642 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 137 | 192.168.56.255 | 137 |
| 192.168.56.101 | 61714 | 114.114.114.114 | 53 |
| 192.168.56.101 | 61714 | 8.8.8.8 | 53 |
| 192.168.56.101 | 56933 | 8.8.8.8 | 53 |
| 192.168.56.101 | 138 | 192.168.56.255 | 138 |
| 192.168.56.101 | 58485 | 114.114.114.114 | 53 |
| 192.168.56.101 | 58485 | 8.8.8.8 | 53 |
No HTTP requests performed.
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts