6.0
高危

7a89bde0a6c3c23a3eb3b6e44f0ea164a30f8fe80f07cd5e016006dae718acc2

3c06c6013a33acdb0304c5f82ae04202.exe

分析耗时

117s

最近分析

文件大小

443.3KB
静态报毒 动态报毒
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
未检测 暂无反病毒引擎检测结果
静态指标
Queries for the computername (5 个事件)
Time & API Arguments Status Return Repeated
1619397636.258499
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619397638.055499
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619397640.070499
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619397643.352499
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619397643.352499
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
Checks if process is being debugged by a debugger (2 个事件)
Time & API Arguments Status Return Repeated
1619397624.195499
IsDebuggerPresent
failed 0 0
1619397624.195499
IsDebuggerPresent
failed 0 0
Checks amount of memory in system, this can be used to detect virtual machines that have a low amount of memory available (1 个事件)
Time & API Arguments Status Return Repeated
1619384499.266
GlobalMemoryStatusEx
success 1 0
The executable contains unknown PE section names indicative of a packer (could be a false positive) (1 个事件)
section .ndata
One or more processes crashed (1 个事件)
Time & API Arguments Status Return Repeated
1619397639.820499
__exception__
stacktrace:
0x106ebd5
0x106e046
DllUnregisterServerInternal-0x3e21 clr+0x21db @ 0x739721db
CoUninitializeEE+0x6862 DllRegisterServerInternal-0xc91e clr+0x24a2a @ 0x73994a2a
CoUninitializeEE+0x6a04 DllRegisterServerInternal-0xc77c clr+0x24bcc @ 0x73994bcc
CoUninitializeEE+0x6a39 DllRegisterServerInternal-0xc747 clr+0x24c01 @ 0x73994c01
CoUninitializeEE+0x6a59 DllRegisterServerInternal-0xc727 clr+0x24c21 @ 0x73994c21
GetCLRFunction+0xc08 GetMetaDataPublicInterfaceFromInternal-0x8a65 clr+0xece82 @ 0x73a5ce82
GetCLRFunction+0xd16 GetMetaDataPublicInterfaceFromInternal-0x8957 clr+0xecf90 @ 0x73a5cf90
GetCLRFunction+0xb2a GetMetaDataPublicInterfaceFromInternal-0x8b43 clr+0xecda4 @ 0x73a5cda4
GetCLRFunction+0xf1f GetMetaDataPublicInterfaceFromInternal-0x874e clr+0xed199 @ 0x73a5d199
GetCLRFunction+0xe20 GetMetaDataPublicInterfaceFromInternal-0x884d clr+0xed09a @ 0x73a5d09a
_CorExeMain+0x1c SetRuntimeInfo-0x181d clr+0x16af00 @ 0x73adaf00
_CorExeMain+0x38 _CorExeMain2-0x134 mscoreei+0x55ab @ 0x73fe55ab
CreateConfigStream+0x13f GetProcessExecutableHeap-0xad6 mscoree+0x7f16 @ 0x74057f16
_CorExeMain+0x8 CreateConfigStream-0x2ff4 mscoree+0x4de3 @ 0x74054de3
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77d69ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77d69ea5

registers.esp: 2945288
registers.edi: 2945316
registers.eax: 0
registers.ebp: 2945332
registers.edx: 8
registers.ebx: 0
registers.esi: 39926308
registers.ecx: 0
exception.instruction_r: 8b 01 8b 40 28 ff 10 89 45 dc b8 e8 39 43 2e e9
exception.instruction: mov eax, dword ptr [ecx]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0xce25e2
success 0 0
行为判定
动态指标
One or more potentially interesting buffers were extracted, these generally contain injected code, configuration data, etc.
Allocates read-write-execute memory (usually to unpack itself) (27 个事件)
Time & API Arguments Status Return Repeated
1619397604.773124
NtAllocateVirtualMemory
process_identifier: 2272
region_size: 24576
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x00320000
success 0 0
1619397604.789124
NtAllocateVirtualMemory
process_identifier: 2272
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x00350000
success 0 0
1619397604.805124
NtAllocateVirtualMemory
process_identifier: 2272
region_size: 28672
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x00420000
success 0 0
1619397617.133124
NtAllocateVirtualMemory
process_identifier: 2272
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x00450000
success 0 0
1619397617.133124
NtAllocateVirtualMemory
process_identifier: 2272
region_size: 135168
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x00460000
success 0 0
1619397623.773499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 1245184
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 8192 (MEM_RESERVE)
base_address: 0x007d0000
success 0 0
1619397623.773499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x008c0000
success 0 0
1619397624.055499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 589824
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 8192 (MEM_RESERVE)
base_address: 0x004c0000
success 0 0
1619397624.055499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00510000
success 0 0
1619397624.086499
NtProtectVirtualMemory
process_identifier: 300
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x73971000
success 0 0
1619397624.195499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 2031616
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 8192 (MEM_RESERVE)
base_address: 0x00c20000
success 0 0
1619397624.195499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00dd0000
success 0 0
1619397624.211499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x0047a000
success 0 0
1619397624.211499
NtProtectVirtualMemory
process_identifier: 300
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x73972000
success 0 0
1619397624.211499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00472000
success 0 0
1619397624.492499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00482000
success 0 0
1619397624.570499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x004a5000
success 0 0
1619397624.586499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x004ab000
success 0 0
1619397624.586499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x004a7000
success 0 0
1619397624.742499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00483000
success 0 0
1619397624.820499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 12288
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00484000
success 0 0
1619397624.852499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x0048c000
success 0 0
1619397624.914499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x01060000
success 0 0
1619397624.914499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 53248
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x01061000
success 0 0
1619397625.133499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00487000
success 0 0
1619397625.445499
NtAllocateVirtualMemory
process_identifier: 300
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00488000
success 0 0
1619397231.058645
NtAllocateVirtualMemory
process_identifier: 1424
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x0000000004790000
success 0 0
Checks whether any human activity is being performed by constantly checking whether the foreground window changed
Creates executable files on the filesystem (10 个事件)
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\lt\cfm\dbi\show_thread\7\undname.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\hitcount\da\phpmyadmin\12.opends60.dll
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\oldie\cr\ADM\VSLauncher.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\catchpenny.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\crontab\exch\privacy_policy\message\datafiles\buildr\undname.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\SoapSafranine.dll
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\network\null\R\scriptlet\pear\sproxyui.dll
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\bb-hist\psql\9.opends60.dll
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\hitcount\da\phpmyadmin\wsdl.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\oldie\cr\ADM\DirControlUI.dll
Creates a shortcut to an executable file (3 个事件)
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\7706a12e.lnk
file C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\doskey.lnk
file C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AN-SSRW\AN-SSRW.lnk
Drops an executable to the user AppData folder (4 个事件)
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\network\null\R\scriptlet\pear\sproxyui.dll
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\oldie\cr\ADM\DirControlUI.dll
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\SoapSafranine.dll
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\catchpenny.exe
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2019-12-16 08:50:47

Imports

Library KERNEL32.dll:
0x408074 SetFileAttributesW
0x408078 Sleep
0x40807c GetTickCount
0x408080 GetFileSize
0x408084 GetModuleFileNameW
0x408088 GetCurrentProcess
0x40808c CopyFileW
0x408094 GetFileAttributesW
0x40809c GetTempPathW
0x4080a0 GetCommandLineW
0x4080a4 GetVersion
0x4080a8 SetErrorMode
0x4080ac lstrlenW
0x4080b0 lstrcpynW
0x4080b4 GetDiskFreeSpaceW
0x4080b8 ExitProcess
0x4080bc MoveFileW
0x4080c0 CreateThread
0x4080c4 GetLastError
0x4080c8 CreateDirectoryW
0x4080cc CreateProcessW
0x4080d0 RemoveDirectoryW
0x4080d4 lstrcmpiA
0x4080d8 CreateFileW
0x4080dc GetTempFileNameW
0x4080e0 WriteFile
0x4080e4 lstrcpyA
0x4080e8 MoveFileExW
0x4080ec lstrcatW
0x4080f0 GetSystemDirectoryW
0x4080f4 GetProcAddress
0x4080f8 GetModuleHandleA
0x4080fc GetExitCodeProcess
0x408100 WaitForSingleObject
0x408104 lstrcmpiW
0x408108 lstrcmpW
0x40810c GetFullPathNameW
0x408110 GetShortPathNameW
0x408114 SearchPathW
0x408118 CompareFileTime
0x40811c SetFileTime
0x408120 CloseHandle
0x408128 GlobalFree
0x40812c GlobalLock
0x408130 GlobalUnlock
0x408134 GlobalAlloc
0x408138 DeleteFileW
0x40813c FindFirstFileW
0x408140 FindNextFileW
0x408144 FindClose
0x408148 SetFilePointer
0x40814c ReadFile
0x408150 MulDiv
0x408154 lstrlenA
0x408158 WideCharToMultiByte
0x40815c MultiByteToWideChar
0x408164 FreeLibrary
0x40816c GetModuleHandleW
0x408170 LoadLibraryExW
Library USER32.dll:
0x408194 GetWindowRect
0x408198 GetSystemMenu
0x40819c SetClassLongW
0x4081a0 IsWindowEnabled
0x4081a4 SetWindowPos
0x4081a8 GetSysColor
0x4081ac GetWindowLongW
0x4081b0 SetCursor
0x4081b4 LoadCursorW
0x4081b8 CheckDlgButton
0x4081bc GetMessagePos
0x4081c0 CallWindowProcW
0x4081c4 IsWindowVisible
0x4081c8 CloseClipboard
0x4081cc SetClipboardData
0x4081d0 EmptyClipboard
0x4081d4 OpenClipboard
0x4081d8 TrackPopupMenu
0x4081dc ScreenToClient
0x4081e0 EnableMenuItem
0x4081e4 GetDlgItem
0x4081e8 SetDlgItemTextW
0x4081ec GetDlgItemTextW
0x4081f0 MessageBoxIndirectW
0x4081f4 CharPrevW
0x4081f8 CharNextA
0x4081fc wsprintfA
0x408200 DispatchMessageW
0x408204 PeekMessageW
0x408208 GetDC
0x40820c ReleaseDC
0x408210 EnableWindow
0x408214 InvalidateRect
0x408218 SendMessageW
0x40821c DefWindowProcW
0x408220 BeginPaint
0x408224 GetClientRect
0x408228 FillRect
0x408230 EndDialog
0x408234 RegisterClassW
0x408238 DialogBoxParamW
0x40823c CreateWindowExW
0x408240 GetClassInfoW
0x408244 DestroyWindow
0x408248 CharNextW
0x40824c ExitWindowsEx
0x408250 SetWindowTextW
0x408254 LoadImageW
0x408258 SetTimer
0x40825c ShowWindow
0x408260 PostQuitMessage
0x408264 wsprintfW
0x408268 SetWindowLongW
0x40826c FindWindowExW
0x408270 IsWindow
0x408274 CreatePopupMenu
0x408278 AppendMenuW
0x40827c GetSystemMetrics
0x408280 DrawTextW
0x408284 EndPaint
0x408288 CreateDialogParamW
0x40828c SendMessageTimeoutW
0x408290 SetForegroundWindow
Library GDI32.dll:
0x40804c SelectObject
0x408050 SetTextColor
0x408054 SetBkMode
0x408058 CreateFontIndirectW
0x40805c CreateBrushIndirect
0x408060 DeleteObject
0x408064 GetDeviceCaps
0x408068 SetBkColor
Library SHELL32.dll:
0x408178 ShellExecuteExW
0x408184 SHGetFileInfoW
0x408188 SHFileOperationW
0x40818c SHBrowseForFolderW
Library ADVAPI32.dll:
0x408004 RegCreateKeyExW
0x408008 RegOpenKeyExW
0x40800c SetFileSecurityW
0x408010 OpenProcessToken
0x408018 RegEnumValueW
0x40801c RegDeleteKeyW
0x408020 RegDeleteValueW
0x408024 RegCloseKey
0x408028 RegSetValueExW
0x40802c RegQueryValueExW
0x408030 RegEnumKeyW
Library COMCTL32.dll:
0x408038 ImageList_Create
0x40803c ImageList_AddMasked
0x408040
0x408044 ImageList_Destroy
Library ole32.dll:
0x408298 OleUninitialize
0x40829c OleInitialize
0x4082a0 CoTaskMemFree
0x4082a4 CoCreateInstance

Hosts

No hosts contacted.

TCP

Source Source Port Destination Destination Port
192.168.56.101 49200 203.208.41.34 update.googleapis.com 443

UDP

Source Source Port Destination Destination Port
192.168.56.101 49235 114.114.114.114 53
192.168.56.101 51963 114.114.114.114 53
192.168.56.101 53210 114.114.114.114 53
192.168.56.101 55368 114.114.114.114 53
192.168.56.101 58367 114.114.114.114 53
192.168.56.101 60088 114.114.114.114 53
192.168.56.101 60215 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 123 20.189.79.72 time.windows.com 123
192.168.56.101 50002 224.0.0.252 5355
192.168.56.101 50534 224.0.0.252 5355
192.168.56.101 53380 224.0.0.252 5355
192.168.56.101 53657 224.0.0.252 5355
192.168.56.101 56539 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 57756 224.0.0.252 5355
192.168.56.101 57874 224.0.0.252 5355
192.168.56.101 58970 224.0.0.252 5355
192.168.56.101 60123 224.0.0.252 5355

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.