1.0
低危

16514b6fce6b56a43d90f4acca8025b764b381d57b637592d9b06d3dcf1236e3

16514b6fce6b56a43d90f4acca8025b764b381d57b637592d9b06d3dcf1236e3.exe

分析耗时

193s

最近分析

372天前

文件大小

40.0KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN
鹰眼引擎
DACN 0.12
FACILE 1.00
IMCLNet 0.66
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba None 20190527 0.3.0.5
Avast Win32:Malware-gen 20190920 18.4.3895.0
Baidu Win32.Adware.Kryptik.h 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (D) 20190702 1.0
Kingsoft None 20190920 2013.8.14.323
McAfee GenericRXHB-SZ!2006B28B2B72 20190920 6.0.6.653
Tencent None 20190920 1.0.0.1
行为判定
动态指标
网络通信
与未执行 DNS 查询的主机进行通信 (1 个事件)
host 114.114.114.114
文件已被 VirusTotal 上 41 个反病毒引擎识别为恶意 (41 个事件)
ALYac Trojan.Agent.VB.CAT
APEX Malicious
AVG Win32:Malware-gen
Acronis suspicious
Ad-Aware Trojan.Agent.VB.CAT
AhnLab-V3 Malware/Win32.RL_Generic.R259209
Antiy-AVL Trojan/Win32.VB.cuvt
Arcabit Trojan.Agent.VB.CAT
Avast Win32:Malware-gen
Avira TR/VB.Agent.dleuig
Baidu Win32.Adware.Kryptik.h
BitDefender Trojan.Agent.VB.CAT
CAT-QuickHeal Trojan.Agent.S5534944
ClamAV Win.Trojan.Agent-1388662
CrowdStrike win/malicious_confidence_100% (D)
Cybereason malicious.b2b728
Cylance Unsafe
DrWeb Trojan.VbCrypt.250
Emsisoft Trojan.Agent.VB.CAT (B)
Endgame malicious (high confidence)
F-Secure Trojan.TR/VB.Agent.dleuig
FireEye Generic.mg.2006b28b2b7285b8
Fortinet W32/Agent.CAT!tr
GData Trojan.Agent.VB.CAT
Ikarus Trojan-Downloader.Win32.VB.auq
Invincea heuristic
MAX malware (ai score=86)
Malwarebytes Trojan.VBClone
McAfee GenericRXHB-SZ!2006B28B2B72
McAfee-GW-Edition BehavesLike.Win32.VBObfus.pt
MicroWorld-eScan Trojan.Agent.VB.CAT
Microsoft Trojan:Win32/Wacatac.B!ml
NANO-Antivirus Trojan.Win32.VB.fnrisw
Panda Trj/GdSda.A
Qihoo-360 HEUR/QVM03.0.0435.Malware.Gen
Rising Trojan.Win32.VBClone.a (CLASSIC)
SentinelOne DFI - Malicious PE
Symantec ML.Attribute.HighConfidence
Trapmine malicious.moderate.ml.score
VBA32 BScope.Trojan.VBKryjetor
Zillya Trojan.Agent.Win32.1076006
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2012-06-24 14:09:09

PE Imphash

56f6502f5b2292e04bc0e535f0cb2ac4

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000065c8 0x00007000 5.628343820073602
.data 0x00008000 0x000009ec 0x00001000 3.161546516182495
.rsrc 0x00009000 0x00004000 0x00000000 0.0
.ap0x 0x0000d000 0x0000049c 0x00001000 1.6137461961326465

Imports

Library MSVBVM60.DLL:
0x401000 _CIcos
0x401004 _adj_fptan
0x401008 __vbaStrI4
0x40100c __vbaFreeVar
0x401010 __vbaFreeVarList
0x401014 _adj_fdiv_m64
0x401018 __vbaFreeObjList
0x40101c _adj_fprem1
0x401020 __vbaStrCat
0x401028 _adj_fdiv_m32
0x40102c rtcRandomNext
0x401030 rtcRandomize
0x401034 rtcMsgBox
0x401038 _adj_fdiv_m16i
0x40103c _adj_fdivr_m16i
0x401040 _CIsin
0x401044 __vbaChkstk
0x401048 __vbaFileClose
0x40104c EVENT_SINK_AddRef
0x401054 __vbaStrCmp
0x401058 __vbaPutOwner4
0x40105c _adj_fpatan
0x401060 __vbaRedim
0x401064 EVENT_SINK_Release
0x401068 __vbaUI1I2
0x40106c _CIsqrt
0x401074 __vbaExceptHandler
0x401078 _adj_fprem
0x40107c _adj_fdivr_m64
0x401080 rtcVarBstrFromAnsi
0x401084 __vbaFPException
0x401088 __vbaInStrVar
0x40108c rtcStrConvVar2
0x401090 __vbaVarCat
0x401094 __vbaGetOwner4
0x401098 rtcDir
0x40109c _CIlog
0x4010a0 __vbaErrorOverflow
0x4010a4 __vbaFileOpen
0x4010a8 __vbaNew2
0x4010ac rtcFileLength
0x4010b0 _adj_fdiv_m32i
0x4010b4 _adj_fdivr_m32i
0x4010b8 __vbaFreeStrList
0x4010bc _adj_fdivr_m32
0x4010c0 _adj_fdiv_r
0x4010c4 ThunRTMain
0x4010c8 __vbaVarTstNe
0x4010cc __vbaI4Var
0x4010d0 __vbaVarDup
0x4010d4 __vbaR8IntI2
0x4010d8 _CIatan
0x4010dc __vbaStrMove
0x4010e0 _allmul
0x4010e4 _CItan
0x4010e8 _CIexp
0x4010ec __vbaFreeObj

L!This program cannot be run in DOS mode.
Project1
FSY<u:O3f
U<.}0;
`eW\TH'2sl
^}yokuvy
ld`bigrnhc
~|~nww
yraorql
rz|~~~
}pnodf]g
T`_VKN
To_abb^i
3vVU:y
`HD fc:)zcg
V]MG(z
w3;E1l
XW`COXKB@A.? 0&
wtuy}tv{u
21*!>{855H7
HeM|DIP{SR@X~WTt^wSczSv]<
53@:??7
5540#%'5
~mt[R`bf]faUb
m\RXffjcgXZe[]`
ahhker
xq`kmj
g_Telmg
gd}djc
#7KPILSHC683~(<{0q*d#
_dWkd_kcXq
0S3U.}
2d&g12
Qbwpmo
2O,w"dBA
YCA5M
=\Gn)3[X0z7
T#0aE!
ZKDgS
NiQ9vLM60B
TkP~xzT!Nd
0NGX[-A"q
m\[ZDA877884(xA
NuV-{q
zr{akihUDgSXJIR6p\
_RKXCCJHH?E;6=;4*)"2-i
{syqu~|vutrqyln[e
VB5!*
Icon_Morphic
Project1
Project1
Project1
HAXMjVeBD
+3q"=h
VBA6.DLL
__vbaVarDup
__vbaGetOwner4
__vbaRedim
__vbaFreeObjList
__vbaUI1I2
__vbaGenerateBoundsError
__vbaR8IntI2
__vbaI4Var
__vbaFreeVarList
__vbaVarCat
__vbaInStrVar
__vbaVarTstNe
__vbaErrorOverflow
__vbaFileClose
__vbaPutOwner4
__vbaFileOpen
__vbaFreeVar
__vbaFreeObj
__vbaFreeStrList
__vbaStrI4
__vbaHresultCheckObj
__vbaNew2
__vbaStrCat
__vbaStrMove
__vbaStrCmp
XSVWeE
UQERMPUQRj
pYM3hb[@
ERMPUQERPj
EEEEEp`P@0
p`P@0
REMPQPUERP
pP`QRPP@PQP0 RP
QRPPQPRP
PQRPPQPp`RP
PP@QRP0 PQ
Q R0P@QPR`PpQRPQRPQRP
R P0Q@RPP`QpRMPUQERMPUQRPj
ERMPQURPEMPQPp`RP
PP@QRP0 PQP
PQRPPQPRP
PQRPp`PQPP@RP
0P QRP
Q R0P@QPR`PpQRPQRPQRP
R P0Q@RPP`QpRMPUQERMPUQRPj
C8t+f8
C4t/f8
K8t)f9
C4t/f8
UQERMPQPUERP
pP`QRPP@PQP0 RP
QRPPQPRP
PQRPPQPp`RP
PP@QRP0 PQP
Q R0P@QPR`PpQRPQRPQRP
R P0Q@RPP`QpRMPUQERMPUQRPj
RPUQERP
MPUQRPp`PQPP@RP
0P QRP
PQRPPQPRP
pP`QRPP@PQP0 RP
R P0Q@RPP`QpRPQRPQRPQ
P Q0R@PPQ`RpPUQERMPUQERPQj
C8t+f8
C4t/f8
K8t)f9
C4t/f8
R P0Q@RPP`QpRPQRPQRPQ
P Q0R@PPQ`RpPUQERMPUQERMPQj
SVWeE
U]R]]]]
ERMPUQERPj
MMMUMEEEEDV@
MUQERPMj
UERMPUQRj
MPUQERMPQj
MUQERMPQj
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaStrI4
__vbaFreeVar
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaStrCat
__vbaHresultCheckObj
_adj_fdiv_m32
_adj_fdiv_m16i
_adj_fdivr_m16i
_CIsin
__vbaChkstk
__vbaFileClose
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaStrCmp
__vbaPutOwner4
_adj_fpatan
__vbaRedim
EVENT_SINK_Release
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaInStrVar
__vbaVarCat
__vbaGetOwner4
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaI4Var
__vbaVarDup
__vbaR8IntI2
_CIatan
__vbaStrMove
_allmul
_CItan
_CIexp
__vbaFreeObj
CsCsdOsdOsDsDsT
Rs$Rs,Rs4Rs<RsDRsLRsTRs\RsdRslRstRs|RsRsRsRsRsRsRsRsRsRsRsRsRsRsRsRsRs
Rs$ Rs, Rs4 Rs< RsD RsL RsT Rs\ Rsd Rsl Rst Rs| Rs Rs Rs Rs Rs Rs Rs Rs Rs Rs Rs Rs Rs Rs Rs Rs Rs
!Rs$!Rs,!Rs4!Rs<!RsD!RsL!RsT!Rs\!Rsd!Rsl!Rst!Rs|!Rs!Rs!Rs!Rs!Rs!Rs!Rs!Rs!Rs!Rs!Rs!Rs!Rs!Rs!Rs!Rs!Rs
"Rs$"Rs,"Rs4"Rs<"RsD"RsL"RsT"Rs\"Rsd"Rsl"Rst"Rs|"Rs"Rs"Rs"Rs"Rs"Rs"Rs"Rs"Rs"Rs"Rs"Rs"Rs"Rs"Rs"Rs"Rs
#Rs$#Rs,#Rs4#Rs<#RsD#RsL#RsT#Rs\#Rsd#Rsl#Rst#Rs|#Rs#Rs#Rs#Rs#Rs#Rs#Rs#Rs#Rs#Rs#Rs#Rs#Rs#Rs#Rs#Rs#Rs
$Rs$$Rs,$Rs4$Rs<$RsD$RsL$RsT$Rs\$Rsd$Rsl$Rst$Rs|$Rs$Rs$Rs$Rs$Rs$Rs$Rs$Rs$Rs$Rs$Rs$Rs$Rs$Rs$Rs$Rs$Rs
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaStrI4
__vbaFreeVar
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaStrCat
__vbaHresultCheckObj
_adj_fdiv_m32
rtcRandomNext
rtcRandomize
rtcMsgBox
_adj_fdiv_m16i
_adj_fdivr_m16i
_CIsin
__vbaChkstk
__vbaFileClose
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaStrCmp
__vbaPutOwner4
_adj_fpatan
__vbaRedim
EVENT_SINK_Release
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
rtcVarBstrFromAnsi
__vbaFPException
__vbaInStrVar
rtcStrConvVar2
__vbaVarCat
__vbaGetOwner4
rtcDir
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaNew2
rtcFileLength
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
ThunRTMain
__vbaVarTstNe
__vbaI4Var
__vbaVarDup
__vbaR8IntI2
_CIatan
__vbaStrMove
_allmul
_CItan
_CIexp
__vbaFreeObj
5;KO:3
2A>R8@
=4M6SI
54;7B@
n8F?B@09G
<8D@9F0@A7AE:?HB?8:HL8BA?J>=4G7@5E@GC:BFA9>;3/=:K0DEO7BFE<DF:2?A@AE5<2'?D9I
:<4J@E>8/A0;4H
<G>B<,BLCK9>5/
>9JD?=GA;?7D:A
93=>B;I55@H7;M
86EEMBC49D@EHG
9G@E)LDDL9G96:
7DLD=G?B:67DA7
<AF5B@4D4<5:<B
54'C;@4869B9=A
@>F6<?A@;A(JB?
=F?=>8AJ7IE?BJ
<LE57K
9K;@B88L
AEA3K6G<>5AG3?K8<A;6
>?FD?BIDC1AC:G9LF/JCB8
?J?'BCGEI<8=<KC7C<AH7C4F<AA:;R2=D?>;K;<DD85:<A>58;CDALIQ@AA<0D@JGIMNAIGG?=1D
[?D5;@BJB?FA9=2B?;;49G=Q:3J3:DK*C>AE><>7=M5H;;:F8:6>E22=;42J,L/E8B67<C<7F9;<D<:=7B@68<B;1=79FFIC5;M<@7G?:3<>?B/E;:LGA
<8:493M@G5F9=GAA<F8@
W?KFF9A7?>A6CF;1@9,>
II?56C78:9CC89:.D3OA
B;@K>=?7>G.@>HIG9>H;
:A??=??H=9NG>9K7>3KJ
@JHA=>;?4JGG:?<9;@4K
@;?4E?:DIG=@:?,5AEH>
EH?A/NBF;6C85==I5:G=
7B=G:K?BCIJ?(>@>D3:<
@?AG@?HCZ?:BCA<82<B@
3KCA24CE@N@:?7;DKA3C
:D9<83>>F9GJEA929:><
B@B0IA9AA1A>DB:5H7=F
A:8C4>IB:@<8572A<7P7
I5JB:262;G-FI>;F=63F
1:?>KJ:<>@J:<B:M@DI9
788II/.A;KG:>4F@=A;9
F6FBA4>RB1?3;@?49D@;
;?>>49HB@B=<8B1G?>?G
<=<27DF::=:8=7A@.I>0AA:;
71E4HP87G78B1?89;?B:=9>=D8
3O>2?>G??@+B>8575AC@?9EB8;I@
FIM>H@5=;J7EJI:>CIHK=@E88B8=<<
5>==H59EDF:D8G7/4?;I>9=JJ6HD=BI/
6;>3BV22==A7B2>A?F3@IIBJ?9?M/=MI8<70C68;;JD4E8F;5KB@;8I1@I2F;=7A><<B;M9CG@QM=J<:;8D=>D99>/A?3A33HC1CD=H4D8G;?A
@*\AC:\Users\darka\Desktop\Untitled\Anti Heur Icon\Source_Code\Project1.vbp
\CloneF_
Finish!
@*\AC:\Users\darka\Desktop\Untitled\Anti Heur Icon\Source_Code\Project1.vbp

DNS

Name Response Post-Analysis Lookup
dns.msftncsi.com A 131.107.255.255
dns.msftncsi.com AAAA fd3e:4f5a:5b81::1

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 56933 114.114.114.114 53
192.168.56.101 138 192.168.56.255 138

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.