3.2
中危

279c2c62706cc2d2e7b888d0edc770a8e4139776b8a39c8404ae711db40e7682

357b2fbcdaecf97b93e1594b5af6ef25.exe

分析耗时

78s

最近分析

文件大小

10.6MB
静态报毒 动态报毒 TENGA
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Baidu 20190318 1.0.0.2
Avast 20200927 18.4.3895.0
Alibaba 20190527 0.3.0.5
Tencent 20200927 1.0.0.1
Kingsoft 20200927 2013.8.14.323
McAfee 20200926 6.0.6.653
CrowdStrike 20190702 1.0
静态指标
行为判定
动态指标
Allocates read-write-execute memory (usually to unpack itself) (2 个事件)
Time & API Arguments Status Return Repeated
1620745643.032125
NtProtectVirtualMemory
process_identifier: 360
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x75150000
success 0 0
1620745643.142125
NtProtectVirtualMemory
process_identifier: 360
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x75121000
success 0 0
Creates (office) documents on the filesystem (1 个事件)
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\LBP3010_R102_V101_Win_x64_uk_RU_7\Windows 7_Notice.pdf
Creates executable files on the filesystem (5 个事件)
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\LBP3010_R102_V101_Win_x64_uk_RU_7\Setup.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\LBP3010_R102_V101_Win_x64_uk_RU_7\MISC\InsCmn.dll
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\LBP3010_R102_V101_Win_x64_uk_RU_7\MISC\CNAB8UND.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\LBP3010_R102_V101_Win_x64_uk_RU_7\MISC\CNAB8UND.dll
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\LBP3010_R102_V101_Win_x64_uk_RU_7\MISC\SetupUIR.dll
File has been identified by one AntiVirus engine on VirusTotal as malicious (1 个事件)
ClamAV Win.Worm.Tenga-132
The binary likely contains encrypted or compressed data indicative of a packer (2 个事件)
entropy 7.998048827420971 section {'size_of_data': '0x00a90c00', 'virtual_address': '0x0000a000', 'entropy': 7.998048827420971, 'name': '_winzip_', 'virtual_size': '0x00a91000'} description A section with a high entropy has been found
entropy 0.997556590290904 description Overall entropy of this PE file is high
网络通信
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2001-01-09 22:08:41

Imports

Library SHELL32.dll:
0x4060e4 ShellExecuteA
0x4060e8 FindExecutableA
Library USER32.dll:
0x4060f0 CharNextA
0x4060f4 DefWindowProcA
0x4060f8 GetWindowWord
0x4060fc SetWindowWord
0x406100 BeginPaint
0x406104 GetSysColor
0x406108 GetClientRect
0x40610c SetRect
0x406110 EndPaint
0x406114 RegisterClassA
0x406118 OemToCharBuffA
0x40611c LoadCursorA
0x406120 GetLastActivePopup
0x406124 ShowWindow
0x406128 PostMessageA
0x40612c EnableWindow
0x406130 DestroyWindow
0x406134 SetWindowTextA
0x406138 SetForegroundWindow
0x40613c SetActiveWindow
0x406140 GetWindowRect
0x406144 SetTimer
0x406148 KillTimer
0x406150 GetDlgItemTextA
0x406154 EndDialog
0x406158 SendMessageA
0x40615c GetKeyState
0x406160 PeekMessageA
0x406164 TranslateMessage
0x406168 DispatchMessageA
0x40616c GetParent
0x406170 SetDlgItemTextA
0x406174 SendDlgItemMessageA
0x406178 GetDlgItem
0x40617c InvalidateRect
0x406180 UpdateWindow
0x406184 wsprintfA
0x406188 MessageBoxA
0x40618c SetCursor
0x406190 GetSystemMetrics
0x406194 SetWindowPos
Library KERNEL32.dll:
0x40603c CreateDirectoryA
0x406040 _lclose
0x406044 _lopen
0x406048 GlobalUnlock
0x40604c RtlUnwind
0x406050 GetCommandLineA
0x406054 GetModuleHandleA
0x406058 ExitProcess
0x40605c GetACP
0x406060 GetModuleFileNameA
0x406064 SetErrorMode
0x406068 GetVersion
0x40606c LoadLibraryA
0x406070 GetProcAddress
0x406074 FreeLibrary
0x406078 lstrcmpiA
0x406084 LocalAlloc
0x406088 LocalFree
0x40608c GlobalHandle
0x406090 lstrcpyA
0x406094 GlobalFree
0x406098 GlobalAlloc
0x40609c GlobalLock
0x4060a0 WinExec
0x4060a4 _llseek
0x4060a8 GetDriveTypeA
0x4060ac _lread
0x4060b0 _lwrite
0x4060b8 FindClose
0x4060bc FindFirstFileA
0x4060c8 lstrlenA
0x4060cc lstrcatA
0x4060d0 SetFileTime
0x4060dc _lcreat
Library GDI32.dll:
0x406008 GetBkColor
0x40600c SetBkColor
0x406010 SetTextColor
0x406014 SetTextAlign
0x406018 DeleteObject
0x406020 ExtTextOutA
0x406024 CreateDCA
0x406028 GetDeviceCaps
0x40602c CreateFontIndirectA
0x406030 DeleteDC
0x406034 SelectObject
Library ADVAPI32.dll:
0x406000 RegQueryValueA

Hosts

No hosts contacted.

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 49235 114.114.114.114 53
192.168.56.101 50534 114.114.114.114 53
192.168.56.101 56539 114.114.114.114 53
192.168.56.101 58367 114.114.114.114 53
192.168.56.101 65004 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 123 20.189.79.72 time.windows.com 123
192.168.56.101 55368 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 60123 224.0.0.252 5355
192.168.56.101 62191 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900
192.168.56.101 56807 239.255.255.250 1900
192.168.56.101 58368 239.255.255.250 3702
192.168.56.101 58370 239.255.255.250 3702
192.168.56.101 58707 239.255.255.250 3702
192.168.56.101 62192 239.255.255.250 3702

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.