5.2
中危

b68d8c629166ba63c211539263a63e4103d66733b5e832458e39b76b65266955

3475df2d4c7676d85addb9b0e3ea2883.exe

分析耗时

85s

最近分析

文件大小

13.9MB
静态报毒 动态报毒 DRIVETHELIFE GENASA SCORE U0HBQDGCMVM UNSAFE
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
McAfee 20210504 6.0.6.653
Alibaba 20190527 0.3.0.5
Avast 20210510 21.1.5827.0
Baidu 20190318 1.0.0.2
Kingsoft 20210510 2017.9.26.565
Tencent 20210510 1.0.0.1
CrowdStrike 20210203 1.0
静态指标
This executable is signed
The executable uses a known packer (1 个事件)
packer UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
The file contains an unknown PE resource name possibly indicative of a packer (4 个事件)
resource name LUA
resource name PNG
resource name XML
resource name _7Z
行为判定
动态指标
HTTP traffic contains suspicious features which may be indicative of malware related traffic (1 个事件)
suspicious_features POST method with no referer header suspicious_request POST https://update.googleapis.com/service/update2?cup2key=10:4026187667&cup2hreq=74fdd741120954ac9ad4fa1ee5a74421c9f3295e5c077a3afce1e67ace788dce
Performs some HTTP requests (4 个事件)
request HEAD http://redirector.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe
request HEAD http://r1---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.100&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620708498&mv=m&mvi=1&pl=23&shardbypass=yes
request HEAD http://r3---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5ok7e&req_id=d5c76a3fb64c619f&cms_redirect=yes&ipbypass=yes&mip=59.50.85.19&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620708745&mv=m&mvi=3
request POST https://update.googleapis.com/service/update2?cup2key=10:4026187667&cup2hreq=74fdd741120954ac9ad4fa1ee5a74421c9f3295e5c077a3afce1e67ace788dce
Sends data using the HTTP POST Method (1 个事件)
request POST https://update.googleapis.com/service/update2?cup2key=10:4026187667&cup2hreq=74fdd741120954ac9ad4fa1ee5a74421c9f3295e5c077a3afce1e67ace788dce
Allocates read-write-execute memory (usually to unpack itself) (1 个事件)
Time & API Arguments Status Return Repeated
1620737588.536375
NtAllocateVirtualMemory
process_identifier: 2116
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x002b0000
success 0 0
Queries the disk size which could be used to detect virtual machine with small fixed size or dynamic allocation (2 个事件)
Time & API Arguments Status Return Repeated
1620737588.520375
GetDiskFreeSpaceW
root_path: C:\
sectors_per_cluster: 8
number_of_free_clusters: 4750986
total_number_of_clusters: 8362495
bytes_per_sector: 512
success 1 0
1620737588.520375
GetDiskFreeSpaceW
root_path: C:\
sectors_per_cluster: 8
number_of_free_clusters: 4750986
total_number_of_clusters: 8362495
bytes_per_sector: 512
success 1 0
Foreign language identified in PE resource (33 个事件)
name LUA language LANG_CHINESE offset 0x00e4556c filetype Lua bytecode, version 5.2 sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000062ba
name LUA language LANG_CHINESE offset 0x00e4556c filetype Lua bytecode, version 5.2 sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000062ba
name LUA language LANG_CHINESE offset 0x00e4556c filetype Lua bytecode, version 5.2 sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000062ba
name PNG language LANG_CHINESE offset 0x00e9fa68 filetype PNG image data, 644 x 55, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000025f1
name PNG language LANG_CHINESE offset 0x00e9fa68 filetype PNG image data, 644 x 55, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000025f1
name PNG language LANG_CHINESE offset 0x00e9fa68 filetype PNG image data, 644 x 55, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000025f1
name PNG language LANG_CHINESE offset 0x00e9fa68 filetype PNG image data, 644 x 55, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000025f1
name PNG language LANG_CHINESE offset 0x00e9fa68 filetype PNG image data, 644 x 55, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000025f1
name PNG language LANG_CHINESE offset 0x00e9fa68 filetype PNG image data, 644 x 55, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000025f1
name PNG language LANG_CHINESE offset 0x00e9fa68 filetype PNG image data, 644 x 55, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000025f1
name PNG language LANG_CHINESE offset 0x00e9fa68 filetype PNG image data, 644 x 55, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000025f1
name PNG language LANG_CHINESE offset 0x00e9fa68 filetype PNG image data, 644 x 55, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000025f1
name PNG language LANG_CHINESE offset 0x00e9fa68 filetype PNG image data, 644 x 55, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000025f1
name PNG language LANG_CHINESE offset 0x00e9fa68 filetype PNG image data, 644 x 55, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000025f1
name PNG language LANG_CHINESE offset 0x00e9fa68 filetype PNG image data, 644 x 55, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000025f1
name PNG language LANG_CHINESE offset 0x00e9fa68 filetype PNG image data, 644 x 55, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000025f1
name PNG language LANG_CHINESE offset 0x00e9fa68 filetype PNG image data, 644 x 55, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000025f1
name PNG language LANG_CHINESE offset 0x00e9fa68 filetype PNG image data, 644 x 55, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000025f1
name XML language LANG_CHINESE offset 0x00ea2060 filetype XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF, CR line terminators sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00003374
name _7Z language LANG_CHINESE offset 0x00ea53d8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00cfa1d8
name RT_ICON language LANG_CHINESE offset 0x01bcd8ac filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000468
name RT_ICON language LANG_CHINESE offset 0x01bcd8ac filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000468
name RT_ICON language LANG_CHINESE offset 0x01bcd8ac filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000468
name RT_ICON language LANG_CHINESE offset 0x01bcd8ac filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000468
name RT_ICON language LANG_CHINESE offset 0x01bcd8ac filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000468
name RT_ICON language LANG_CHINESE offset 0x01bcd8ac filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000468
name RT_ICON language LANG_CHINESE offset 0x01bcd8ac filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000468
name RT_ICON language LANG_CHINESE offset 0x01bcd8ac filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000468
name RT_ICON language LANG_CHINESE offset 0x01bcd8ac filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000468
name RT_DIALOG language LANG_CHINESE offset 0x01bcdd18 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000072
name RT_STRING language LANG_CHINESE offset 0x01bcdd90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000038
name RT_GROUP_ICON language LANG_CHINESE offset 0x01bcddcc filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000084
name RT_VERSION language LANG_CHINESE offset 0x01bcde54 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000004ec
File has been identified by 3 AntiVirus engines on VirusTotal as malicious (3 个事件)
eGambit Unsafe.AI_Score_99%
Malwarebytes PUP.Optional.DriveTheLife
Yandex Trojan.GenAsa!U0HbqDGcMvM
The binary likely contains encrypted or compressed data indicative of a packer (3 个事件)
entropy 7.926999119019942 section {'size_of_data': '0x00045200', 'virtual_address': '0x00df6000', 'entropy': 7.926999119019942, 'name': 'UPX1', 'virtual_size': '0x00046000'} description A section with a high entropy has been found
entropy 7.993119060259876 section {'size_of_data': '0x00d92c00', 'virtual_address': '0x00e3c000', 'entropy': 7.993119060259876, 'name': '.rsrc', 'virtual_size': '0x00d93000'} description A section with a high entropy has been found
entropy 1.0 description Overall entropy of this PE file is high
Queries for potentially installed applications (3 个事件)
Time & API Arguments Status Return Repeated
1620737588.520375
RegOpenKeyExW
access: 0x0002001f
base_handle: 0x80000002
key_handle: 0x00000000
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{29FE44D7-BC89-4188-8B0E-F6BA073C15A4}_is1
regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{29FE44D7-BC89-4188-8B0E-F6BA073C15A4}_is1
options: 0
failed 2 0
1620737588.520375
RegOpenKeyExW
access: 0x0002001f
base_handle: 0x80000002
key_handle: 0x00000000
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4705B7D9-5E57-4508-8EBD-27E3A710AE6C}_is1
regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4705B7D9-5E57-4508-8EBD-27E3A710AE6C}_is1
options: 0
failed 2 0
1620737588.520375
RegOpenKeyExW
access: 0x0002001f
base_handle: 0x80000002
key_handle: 0x00000000
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{29FE44D7-BC89-4188-8B0E-F6BA073C15A4}_is1
regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{29FE44D7-BC89-4188-8B0E-F6BA073C15A4}_is1
options: 0
failed 2 0
The executable is compressed using UPX (2 个事件)
section UPX0 description Section name indicates UPX
section UPX1 description Section name indicates UPX
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2015-11-26 18:06:04

Imports

Library KERNEL32.DLL:
0x1fce864 LoadLibraryA
0x1fce868 GetProcAddress
0x1fce86c VirtualProtect
0x1fce870 VirtualAlloc
0x1fce874 VirtualFree
0x1fce878 ExitProcess
Library ADVAPI32.dll:
0x1fce880 RegCloseKey
Library COMCTL32.dll:
0x1fce888 _TrackMouseEvent
Library GDI32.dll:
0x1fce890 DPtoLP
Library gdiplus.dll:
0x1fce898 GdipFree
Library IMM32.dll:
0x1fce8a0 ImmGetContext
Library MSIMG32.dll:
0x1fce8a8 AlphaBlend
Library ole32.dll:
0x1fce8b0 CoInitialize
Library OLEAUT32.dll:
0x1fce8b8 VarUI4FromStr
Library PSAPI.DLL:
Library SHELL32.dll:
0x1fce8c8
Library SHLWAPI.dll:
0x1fce8d0 PathIsURLW
Library urlmon.dll:
0x1fce8d8 URLDownloadToFileW
Library USER32.dll:
0x1fce8e0 GetDC

Hosts

No hosts contacted.

TCP

Source Source Port Destination Destination Port
192.168.56.101 49185 113.108.239.194 r1---sn-j5o7dn7e.gvt1.com 80
192.168.56.101 49186 113.108.239.196 r3---sn-j5o7dn7e.gvt1.com 80
192.168.56.101 49184 203.208.41.65 redirector.gvt1.com 80
192.168.56.101 49183 203.208.41.66 update.googleapis.com 443

UDP

Source Source Port Destination Destination Port
192.168.56.101 49235 114.114.114.114 53
192.168.56.101 50534 114.114.114.114 53
192.168.56.101 53237 114.114.114.114 53
192.168.56.101 53657 114.114.114.114 53
192.168.56.101 56539 114.114.114.114 53
192.168.56.101 57756 114.114.114.114 53
192.168.56.101 62318 114.114.114.114 53
192.168.56.101 65004 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 123 20.189.79.72 time.windows.com 123
192.168.56.101 51808 224.0.0.252 5355
192.168.56.101 55368 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 57874 224.0.0.252 5355
192.168.56.101 60123 224.0.0.252 5355
192.168.56.101 62191 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900
192.168.56.101 50535 239.255.255.250 3702
192.168.56.101 50537 239.255.255.250 3702

HTTP & HTTPS Requests

URI Data
http://r3---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5ok7e&req_id=d5c76a3fb64c619f&cms_redirect=yes&ipbypass=yes&mip=59.50.85.19&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620708745&mv=m&mvi=3
HEAD /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5ok7e&req_id=d5c76a3fb64c619f&cms_redirect=yes&ipbypass=yes&mip=59.50.85.19&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620708745&mv=m&mvi=3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Host: r3---sn-j5o7dn7e.gvt1.com

http://redirector.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe
HEAD /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Host: redirector.gvt1.com

http://r1---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.100&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620708498&mv=m&mvi=1&pl=23&shardbypass=yes
HEAD /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.100&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620708498&mv=m&mvi=1&pl=23&shardbypass=yes HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Host: r1---sn-j5o7dn7e.gvt1.com

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.