查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
---|---|---|---|
Alibaba | Worm:Win32/Small.afae7e33 | 20190527 | 0.3.0.5 |
Avast | Win32:SillyP2P-X [Wrm] | 20200923 | 18.4.3895.0 |
Baidu | None | 20190318 | 1.0.0.2 |
CrowdStrike | win/malicious_confidence_80% (D) | 20190702 | 1.0 |
Kingsoft | None | 20200923 | 2013.8.14.323 |
McAfee | W32/Xiquitir.ow!p2p | 20200922 | 6.0.6.653 |
Tencent | Malware.Win32.Gencirc.10b5830a | 20200923 | 1.0.0.1 |
host | 114.114.114.114 | |||
host | 8.8.8.8 |
ALYac | Gen:Variant.Mikey.107419 |
APEX | Malicious |
AVG | Win32:SillyP2P-X [Wrm] |
Acronis | suspicious |
Ad-Aware | Gen:Variant.Mikey.107419 |
AhnLab-V3 | Worm/Win32.RL_Small.R284018 |
Alibaba | Worm:Win32/Small.afae7e33 |
Antiy-AVL | Worm/Win32.Agent.a |
Avast | Win32:SillyP2P-X [Wrm] |
Avira | TR/Dropper.Gen |
BitDefender | Gen:Variant.Mikey.107419 |
Bkav | W32.AIDetectVM.malware1 |
CAT-QuickHeal | Worm.Agent.AZ4 |
ClamAV | Win.Worm.Sillyp2p-7194313-0 |
Comodo | Worm.Win32.Agent.NIQ@8hjo1v |
CrowdStrike | win/malicious_confidence_80% (D) |
Cybereason | malicious.9316d9 |
Cylance | Unsafe |
Cynet | Malicious (score: 100) |
Cyren | W32/P2P_Worm.NXSZ-6858 |
DrWeb | Win32.HLLW.Xiquit |
ESET-NOD32 | Win32/Agent.OHT |
Elastic | malicious (high confidence) |
Emsisoft | Gen:Variant.Mikey.107419 (B) |
FireEye | Generic.mg.27ffbfd9316d90e8 |
Fortinet | W32/Agent.NIQ!worm |
GData | Win32.Worm.Agent.ASR |
Ikarus | Worm.Win32.Agent |
Invincea | ML/PE-A + Troj/Agent-BCMZ |
Jiangmin | Worm.Small.q |
K7AntiVirus | EmailWorm ( 004df05b1 ) |
K7GW | EmailWorm ( 004df05b1 ) |
Kaspersky | P2P-Worm.Win32.Small.p |
MAX | malware (ai score=88) |
Malwarebytes | Worm.Small |
McAfee | W32/Xiquitir.ow!p2p |
McAfee-GW-Edition | W32/Xiquitir.ow!p2p |
MicroWorld-eScan | Gen:Variant.Mikey.107419 |
Microsoft | Trojan:Win32/Ashify.J!rfn |
NANO-Antivirus | Trojan.Win32.Small.fsvyjs |
Qihoo-360 | Worm.Win32.Small.B |
Rising | Worm.Agent!1.9D8A (CLASSIC) |
Sangfor | Malware |
Sophos | Troj/Agent-BCMZ |
Symantec | W32.SillyP2P |
TACHYON | Worm/W32.SillyP2P.Zen |
Tencent | Malware.Win32.Gencirc.10b5830a |
TrendMicro | TROJ_SMALL_0000040.TOMA |
TrendMicro-HouseCall | TROJ_SMALL_0000040.TOMA |
VBA32 | Trojan.Ditertag |
Name | Virtual Address | Virtual Size | Size of Raw Data | Entropy |
---|---|---|---|---|
.text | 0x00001000 | 0x00005b50 | 0x00006000 | 6.363900829399006 |
.rdata | 0x00007000 | 0x000009ac | 0x00001000 | 4.014497177343175 |
.data | 0x00008000 | 0x00003438 | 0x00002000 | 3.5317328886870287 |
.rsrc | 0x0000c000 | 0x00000ab0 | 0x00001000 | 2.789173186295458 |
Name | Offset | Size | Language | Sub-language | File type |
---|---|---|---|---|---|
RT_ICON | 0x0000c408 | 0x00000128 | LANG_SPANISH | SUBLANG_SPANISH_MODERN | None |
RT_ICON | 0x0000c408 | 0x00000128 | LANG_SPANISH | SUBLANG_SPANISH_MODERN | None |
RT_GROUP_ICON | 0x0000c530 | 0x00000022 | LANG_SPANISH | SUBLANG_SPANISH_MODERN | None |
RT_VERSION | 0x0000c558 | 0x00000554 | LANG_SPANISH | SUBLANG_SPANISH_MODERN | None |
IP |
---|
114.114.114.114 |
8.8.8.8 |
Name | Response | Post-Analysis Lookup |
---|---|---|
dns.msftncsi.com |
A 131.107.255.255
A 131.107.255.255 |
131.107.255.255 |
dns.msftncsi.com | AAAA fd3e:4f5a:5b81::1 | 131.107.255.255 |
No TCP connections recorded.
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 53179 | 224.0.0.252 | 5355 |
192.168.56.101 | 49642 | 224.0.0.252 | 5355 |
192.168.56.101 | 137 | 192.168.56.255 | 137 |
192.168.56.101 | 61714 | 114.114.114.114 | 53 |
192.168.56.101 | 61714 | 8.8.8.8 | 53 |
192.168.56.101 | 56933 | 8.8.8.8 | 53 |
192.168.56.101 | 138 | 192.168.56.255 | 138 |
192.168.56.101 | 58485 | 114.114.114.114 | 53 |
192.168.56.101 | 58485 | 8.8.8.8 | 53 |
192.168.56.101 | 57665 | 114.114.114.114 | 53 |
No HTTP requests performed.
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts
Name | e2919f03fb24ae58_winamp 3.5 (full version).exe |
---|---|
Filepath | C:\Windows\Intelx386\Winamp 3.5 (full version).exe |
Size | 15.7MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 2f43f4d0bd5138e214c365866b54718e |
SHA1 | 24cea67c3ef8fbe7d9020c4d3e02942307eabb54 |
SHA256 | e2919f03fb24ae582f3e8de42a1340793e63800ab73a0fccf4a8d9ea0a11559f |
CRC32 | 9267B898 |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 0da9aed087766d6d_winamp 5.0 (full version).exe |
---|---|
Filepath | C:\Windows\Intelx386\Winamp 5.0 (full version).exe |
Size | 16.5MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 39e6459d0f359d393c93cd80018a1447 |
SHA1 | c10cec18f8c91b667091335b9a8f91ac2bdba99e |
SHA256 | 0da9aed087766d6da041072d8534c15d5649b0f51d75f58f751a700e42020d99 |
CRC32 | 9E47BD2B |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | e2cc4cd598add621_virtualdub 2.1.4.exe |
---|---|
Filepath | C:\Windows\Intelx386\VirtualDub 2.1.4.exe |
Size | 15.5MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 4d7910d0297cc56a5c2d98700656c88e |
SHA1 | 25719b0e185b726b2016e1b6c6947d80d3d08129 |
SHA256 | e2cc4cd598add621e8a3f826b0a875a09ec701c8ad824e860f96b32df6257a00 |
CRC32 | 291D51DE |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | d539a4efdb22f135_hacha profesional edition.exe |
---|---|
Filepath | C:\Windows\Intelx386\Hacha Profesional Edition.exe |
Size | 12.7MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | d36d1ff17984adee4747291c37d24ddf |
SHA1 | 63bd2afda32bb110413d1f3fd35980872f809b87 |
SHA256 | 6afb5d5a8606130028c3d9d6b8872ef641d094948b5a131669edd02187aafe96 |
CRC32 | 915C4E1F |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | eee84fbc164e9ffc_hacha profesional edition.exe |
---|---|
Filepath | C:\Windows\Intelx386\Hacha Profesional Edition.exe |
Size | 9.2MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | ae628ceaef8dfb34d6c643f59941b425 |
SHA1 | 573a4f88d0238f8b30403d747cac17d8954ca57d |
SHA256 | 7219b251ad99ddc7e8b85f4920eff402d67644f9773dcd009dd6ccf8976fb69a |
CRC32 | DEDF6722 |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 9c601ffa23164782_hacha profesional edition.exe |
---|---|
Filepath | C:\Windows\Intelx386\Hacha Profesional Edition.exe |
Size | 13.8MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 20d4d733dd5edce0088268044ea2a320 |
SHA1 | e32c01ba9e7a8dbb729fbf13ee05ad8692889307 |
SHA256 | 9c601ffa231647820917f33718a4b383aafd5ae7ff65255082d77d347c20fc85 |
CRC32 | 8F2555CA |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 86c97d4bef653cae_update photoshop 8.0 to photoshop 9.5 (it磗 work!).exe |
---|---|
Filepath | C:\Windows\Intelx386\Update Photoshop 8.0 to Photoshop 9.5 (It磗 Work!).exe |
Size | 15.0MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 7602ba07227e1ed703c1d92a45afc8fd |
SHA1 | a359fa5dcb18b67e2ff30ec160ce1e876d5ae7de |
SHA256 | 86c97d4bef653caef1b6ce2ee7987e47a2af3bbcc098ace20154d4b4b6bb3fb0 |
CRC32 | 37FED1B2 |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 2d356fac8076da3e_contawin 2000 (full version).exe |
---|---|
Filepath | C:\Windows\Intelx386\ContaWin 2000 (full version).exe |
Size | 14.3MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 991265a8c8aef2a53ad946625dd463af |
SHA1 | dc2105b4f29e5c6b3eeaaadc9f7ccaed18f24458 |
SHA256 | 2d356fac8076da3ef6a3ed10340cc4c73c9bb23ed71a5d8bb9dae49483f7f23c |
CRC32 | D1B5C532 |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 24c7f382745e4d09_download accelerator plus (dap) (full version with serial).exe |
---|---|
Filepath | C:\Windows\Intelx386\Download Accelerator Plus (DAP) (full version with serial).exe |
Size | 14.4MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | b1fa0806350b1e4051c1c2f07f316417 |
SHA1 | 694d1500ca96bb04ec40395b1901fc3dfa256193 |
SHA256 | 24c7f382745e4d09e501a19bcabb3234bacad4b9c56f36419fba3c9fe84d7e8a |
CRC32 | 06854C79 |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 17e1526db3a6bb2f_winrar 4 (with crack).exe |
---|---|
Filepath | C:\Windows\Intelx386\WinRar 4 (with crack).exe |
Size | 15.5MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | fc0e0801f4d853e442e40febb8adfe70 |
SHA1 | 084b355f64c9a5d0d0f0006660939c938af4acf1 |
SHA256 | 17e1526db3a6bb2ff42522f55f2944a7a12310206c864d931ee95efab771d33c |
CRC32 | E05CF767 |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 5e05d134017f934e_realone player (full version).exe |
---|---|
Filepath | C:\Windows\Intelx386\RealOne Player (Full version).exe |
Size | 14.4MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 859f464c550a3e5a9b0be8ba9961eb75 |
SHA1 | 9c944fb366b029abc800896aa2114bceada664d0 |
SHA256 | 5e05d134017f934e1619778eadade3fb551771f09a3ed393119a1e912d37894d |
CRC32 | 7939C6BE |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | d7583b3214aa344c_msn messenger 6.3.exe |
---|---|
Filepath | C:\Windows\Intelx386\MSN messenger 6.3.exe |
Size | 15.1MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | dcd87ec0aa3bab89a0251ce183791393 |
SHA1 | 3cdf6c9b9d3a40410da95804bd485e7ac3591bce |
SHA256 | d7583b3214aa344c27389942a3981cbdbbc5d868bee9fc24c22112f2e1a00451 |
CRC32 | A2C1608E |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | d4808fb34e3c3098_simpsons pack guiones (temporada 2004).exe |
---|---|
Filepath | C:\Windows\Intelx386\Simpsons pack guiones (Temporada 2004).exe |
Size | 1.2MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 99511132d2691f0e749e4e1d329b6927 |
SHA1 | 32c06b74ce0bec7667a3035972cca762e92ab151 |
SHA256 | a7d4c3a6fa4bb725f3a3562f3b6c0beafc3392efab67bfcc5a0664a8713375fb |
CRC32 | CC05BC02 |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | fd27c4a21d22d61f_simpsons pack guiones (temporada 2004).exe |
---|---|
Filepath | C:\Windows\Intelx386\Simpsons pack guiones (Temporada 2004).exe |
Size | 5.5MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 5962959b157878e2c803ecd9c9074283 |
SHA1 | facda5938830f437f3b6bdc105f51b376c557530 |
SHA256 | 804240b11d16cdf6319bbaac271c617eb14ec48b3c2ea1abaf3399300076e1b8 |
CRC32 | 88527704 |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 5a6cbe1c0153d75d_simpsons pack guiones (temporada 2004).exe |
---|---|
Filepath | C:\Windows\Intelx386\Simpsons pack guiones (Temporada 2004).exe |
Size | 3.9MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | d587b293d2bec774f3bf08313e52ec3c |
SHA1 | 96ad840980e949881a31f1e6075e540e984d4053 |
SHA256 | e4f6675b463df55e4bdf5a7e30daa5975f6ef831d9fe178e55115d27d1835f06 |
CRC32 | 4C7E1168 |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 229f25b638936f0c_hacha profesional edition.exe |
---|---|
Filepath | C:\Windows\Intelx386\Hacha Profesional Edition.exe |
Size | 10.8MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | d2c84d193974d12a6ba163ea04557d7c |
SHA1 | eb26967d8b5f984a2685ac4ab5db52bfec4c1f77 |
SHA256 | b4226fcfd8f91a03a502dde785f0dcbaf0828740a9c5db1230cd99f360421709 |
CRC32 | 80F09389 |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 28267a9a28f333e2_update photoshop 7.0 to photoshop 9.16 (it磗 work!).exe |
---|---|
Filepath | C:\Windows\Intelx386\Update Photoshop 7.0 to Photoshop 9.16 (It磗 Work!).exe |
Size | 14.9MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 9c1e4b9505c5c2ede8138f6925cfd2ad |
SHA1 | ee13c3ccb4cfcee4bd4e3bdcd9afd40cc17f2cf5 |
SHA256 | 28267a9a28f333e25a0aa2853ceb54da3ad14da142eda2e8944db7cec21f57f7 |
CRC32 | 010779C5 |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 6fbdad25bc9c5a97_winzip 9.exe |
---|---|
Filepath | C:\Windows\Intelx386\WinZip 9.exe |
Size | 15.1MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 11077748e2a97aa3d0969ec4a61ce086 |
SHA1 | 685e229c74433e04a3ccc74258f5df521932dd22 |
SHA256 | 6fbdad25bc9c5a9742ad0575fd343cf1d841de422226ace926ce93044b0cb706 |
CRC32 | E94A31FD |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 50a65963cc69070b_winrar v6.11 (with crack).exe |
---|---|
Filepath | C:\Windows\Intelx386\WinRar v6.11 (with crack).exe |
Size | 15.6MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 409061ce77ef3a3e0e7867e7786551af |
SHA1 | b0e19134543cdd8c9fd124c90119547e5740cdad |
SHA256 | 50a65963cc69070bb882116213e6c2ac4ce101f58df563acb33d8170d5989e6e |
CRC32 | 6C53158C |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 253a45312bb7a211_3d studio r8 (it's work!!).exe |
---|---|
Filepath | C:\Windows\Intelx386\3D Studio R8 (It's Work!!).exe |
Size | 22.0MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | bf71826947242be2dd8fcb79473e5ea3 |
SHA1 | 91f64e0d4a08557c45e51fb00302e9a99e673418 |
SHA256 | 253a45312bb7a2113150686ce7acb4671ede8036dd3b6ce43894988f5f9f7745 |
CRC32 | B232F9D6 |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 5f08c2f6e3d39ac9_simpsons pack guiones (temporada 2004).exe |
---|---|
Filepath | C:\Windows\Intelx386\Simpsons pack guiones (Temporada 2004).exe |
Size | 2.4MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | b317ec21cbf47f6e696c3faddd739e79 |
SHA1 | f513ab5b790ed2506e4ae68787b240f1ca8776b2 |
SHA256 | a88be4013bc85ad240018ed9550f27ffe124f6bcbfc47ffa343f49131cbf7e38 |
CRC32 | CF7F30CF |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 6e91439c4c00fd2e_winace 3.85 (with serial).exe |
---|---|
Filepath | C:\Windows\Intelx386\WinAce 3.85 (with Serial).exe |
Size | 16.9MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 9cc5576456f1a5eda4857f738af8f1e6 |
SHA1 | fc2db0429779ec2b67f578cbf1b20d16103a7564 |
SHA256 | 6e91439c4c00fd2e716c059ba0bbfec3f61617d693dd3e032acc1ae051cacc6b |
CRC32 | 07649CF4 |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | c5b34ac35c98babe_winamp 3 (full version).exe |
---|---|
Filepath | C:\Windows\Intelx386\Winamp 3 (full version).exe |
Size | 15.3MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 697ca753e06759a24962224311a9b4b5 |
SHA1 | ad6d58b6ef7a0e546a22d408089c17ab6ddba447 |
SHA256 | c5b34ac35c98babe0ac6ea9541e9dbea6d692dcb8073d27e5fab80a619b6f860 |
CRC32 | FAC5341B |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 8a79085e33d0d5b5_divx 7.2 freeware.exe |
---|---|
Filepath | C:\Windows\Intelx386\DivX 7.2 freeware.exe |
Size | 14.2MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 18ba655eeba878e97c50f181f1902a53 |
SHA1 | bddb6ae6c9259bd3188e07c6c5eea3f7f4aa19a1 |
SHA256 | 8a79085e33d0d5b5597662ffc1291af200d4073da03cac67283fef7e14d829ff |
CRC32 | DE34A95E |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |
Name | 1fbfd4257b8d9251_bsplayer v3.exe |
---|---|
Filepath | C:\Windows\Intelx386\BsPlayer v3.exe |
Size | 15.5MB |
Processes | 2064 (None) |
Type | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5 | 28e0d6db54b431b542dea74ee63ae0db |
SHA1 | 339dcfffc85726ff384bf415598f05736b1aaae3 |
SHA256 | 1fbfd4257b8d9251d5b27ef29c699409c59571016bad376dac8ee0d048e4215a |
CRC32 | 0D0202F1 |
ssdeep | None |
Yara | None matched |
VirusTotal | Search for analysis |