2.3
中危

01f206ce6de06e57e8e3eb383a08f637a4f4197414c56d27f9fe203812800945

01f206ce6de06e57e8e3eb383a08f637a4f4197414c56d27f9fe203812800945.exe

分析耗时

153s

最近分析

392天前

文件大小

52.6KB
静态报毒 动态报毒 PERSISTANCE UNKNOWN
鹰眼引擎
DACN 0.14
FACILE 1.00
IMCLNet 0.52
MFGraph 0.00
静态判定
反病毒引擎
未检测 暂无反病毒引擎检测结果
静态指标
检查进程是否被调试器调试 (2 个事件)
Time & API Arguments Status Return Repeated
1727545279.468375
IsDebuggerPresent
failed 0 0
1727545279.99925
IsDebuggerPresent
failed 0 0
可执行文件包含未知的 PE 段名称,可能指示打包器(可能是误报) (15 个事件)
section .buildi
section .show
section M7/nWLy
section .po4
section .data2
section new_imp
section .po5
section .lzmjSu
section usj
section .opc
section gfelmge
section PAGEKDD
section ordo
section \\\\xb8
section .bin
行为判定
动态指标
提取了一个或多个潜在有趣的缓冲区,这些缓冲区通常包含注入的代码、配置数据等。
分配可读-可写-可执行内存(通常用于自解压) (6 个事件)
Time & API Arguments Status Return Repeated
1727545279.640375
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x03350000
region_size: 1904640
allocation_type: 8192 (MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3028
success 0 0
1727545279.640375
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x03520000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3028
success 0 0
1727545279.656375
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x03530000
region_size: 4194304
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3028
success 0 0
1727545280.17125
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x03310000
region_size: 856064
allocation_type: 8192 (MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 2736
success 0 0
1727545280.17125
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x033e0000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 2736
success 0 0
1727545280.18725
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x033f0000
region_size: 4194304
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 2736
success 0 0
在文件系统上创建可执行文件 (1 个事件)
file C:\Users\Administrator\AppData\Local\Temp\hhcbrnaff.exe
投放一个二进制文件并执行它 (1 个事件)
file C:\Users\Administrator\AppData\Local\Temp\hhcbrnaff.exe
一个进程创建了一个隐藏窗口 (1 个事件)
Time & API Arguments Status Return Repeated
1727545279.828375
ShellExecuteExW
filepath: C:\Users\Administrator\AppData\Local\Temp\hhcbrnaff.exe
filepath_r: C:\Users\ADMINI~1\AppData\Local\Temp\hhcbrnaff.exe
parameters:
show_type: 0
success 1 0
该二进制文件可能包含加密或压缩数据,表明使用了打包工具 (2 个事件)
section {'name': 'new_imp', 'virtual_address': '0x00018000', 'virtual_size': '0x00000200', 'size_of_data': '0x00000200', 'entropy': 7.322666847734032} entropy 7.322666847734032 description 发现高熵的节
section {'name': 'PAGEKDD', 'virtual_address': '0x0001a000', 'virtual_size': '0x00000200', 'size_of_data': '0x00000154', 'entropy': 7.245564145027691} entropy 7.245564145027691 description 发现高熵的节
网络通信
一个或多个缓冲区包含嵌入的PE文件 (1 个事件)
buffer Buffer with sha1: 06a9ad9f438bc7042361e5bfecc26d3b0e70d13f
与未执行 DNS 查询的主机进行通信 (2 个事件)
host 114.114.114.114
host 8.8.8.8
在用户文件夹中创建可执行文件 (1 个事件)
file C:\Users\Administrator\AppData\Local\Temp\hhcbrnaff.exe
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2004-10-13 11:27:30

PE Imphash

7f712f2a919df3038830bf06da63a3d5

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.buildi 0x00001000 0x00000d81 0x00000e00 6.435993345637047
.show 0x00002000 0x000014eb 0x00001600 4.921057910088666
M7/nWLy 0x00004000 0x000006be 0x00000800 3.9283002053078357
/42 0x00005000 0x00001a19 0x00001c00 5.117923445834665
.po4 0x00007000 0x00000200 0x00000200 3.8694310388062267
.data2 0x00008000 0x00000200 0x00000200 4.605309178500234
/30 0x00009000 0x00000200 0x00000200 3.8694310388062267
/4 0x0000a000 0x00001000 0x00000600 3.8797839023544
new_imp 0x0000b000 0x00001000 0x00000600 3.919738071083163
.po5 0x0000c000 0x00000200 0x00000200 3.8694310388062267
.lzmjSu 0x0000d000 0x00001000 0x00000600 3.960704083715032
usj 0x0000e000 0x00001000 0x00000600 4.000125471157331
.opc 0x0000f000 0x00000200 0x00000200 3.8694310388062267
gfelmge 0x00010000 0x00001000 0x00000800 3.3351728217745538
PAGEKDD 0x00011000 0x00000200 0x00000200 3.8694310388062267
new_imp 0x00012000 0x00001000 0x00000800 3.3842075664484055
ordo 0x00013000 0x00000200 0x00000200 3.8694310388062267
\\\\xb8 0x00014000 0x00001000 0x00000800 3.3948980553013484
new_imp 0x00015000 0x00001000 0x00000800 3.434236094841649
M7/nWLy 0x00016000 0x00001000 0x00000800 3.4543321541834007
new_imp 0x00017000 0x00001000 0x00000800 4.728096638571375
new_imp 0x00018000 0x00000200 0x00000200 7.322666847734032
.bin 0x00019000 0x00000200 0x00000200 6.726734369240647
PAGEKDD 0x0001a000 0x00000200 0x00000154 7.245564145027691

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00005178 0x00000ea8 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_DIALOG 0x00006020 0x000000e8 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_ICON 0x00006108 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_VERSION 0x0000611c 0x00000318 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_MANIFEST 0x00006434 0x00000193 LANG_NEUTRAL SUBLANG_NEUTRAL None

Imports

Library user32.dll:
0x4041e8 CreateWindowExA
0x4041ec GetMessageA
0x4041f0 DispatchMessageA
0x4041f4 DefWindowProcA
0x4041f8 PostQuitMessage
0x4041fc GetForegroundWindow
0x404200 SetForegroundWindow
0x404204 CreateMenu
0x404208 GetSystemMenu
0x40420c GetDoubleClickTime
0x404210 UpdateWindow
0x404214 GetQueueStatus
0x404218 GetClipboardOwner
0x40421c FindWindowA
0x404220 LoadIconA
0x404224 LoadCursorA
0x404228 RegisterClassA
Library GDI32.dll:
0x4043b4 CreateBitmap
0x4043b8 IntersectClipRect
0x4043bc ExcludeClipRect
0x4043c0 UpdateColors
0x4043c4 DeleteDC
0x4043cc CreateCompatibleDC
0x4043d0 DeleteObject
0x4043d4 TextOutA
0x4043d8 SetBkColor
0x4043dc SetTextColor
0x4043e0 Rectangle
0x4043e4 CreateSolidBrush
0x4043e8 GetStockObject
0x4043ec SelectObject
0x4043f0 CreateFontIndirectA
0x4043f8 SetMapMode
0x4043fc GetDeviceCaps
0x404400 GetTextMetricsA
0x404404 CreateFontA
0x404408 RealizePalette
Library Winmm.dll:
0x404694 mciSendStringA
Library Msacm32.dll:
0x404674 acmStreamOpen
Library IMM32.dll:
0x4045a8 ImmGetContext
Library kernel32.dll:
0x404110 GetModuleHandleA
0x404114 CreateSemaphoreW
0x404118 GetProcAddress
0x40411c HeapCreate
0x404120 HeapAlloc
0x404124 ExitProcess
0x404128 FreeLibrary
Library OLE32.dll:
0x404624 CoUninitialize
0x404628 CoInitialize
0x40462c CoCreateInstance

.buildi
M7/nWLy
.data2
new_imp
.lzmjSu
gfelmge
PAGEKDD
new_imp
\\\\xb8
new_imp
M7/nWLy
new_imp
new_imp
PAGEKDD
E%)E%-
2Q?@HGGQ
g@N[vf
X=g;QFvZVCy
LoadLibraryExA
save recsound aaa
TranslateMessage
user32.dll
user32.dll
GDI32.dll
Winmm.dll
Msacm32.dll
IMM32.dll
kernel32.dll
OLE32.dll
GetModuleHandleA
CreateSemaphoreW
GetProcAddress
HeapCreate
HeapAlloc
ExitProcess
FreeLibrary
CreateWindowExA
GetMessageA
DispatchMessageA
DefWindowProcA
PostQuitMessage
GetForegroundWindow
SetForegroundWindow
CreateMenu
GetSystemMenu
GetDoubleClickTime
UpdateWindow
GetQueueStatus
GetClipboardOwner
FindWindowA
LoadIconA
LoadCursorA
RegisterClassA
CreateBitmap
IntersectClipRect
ExcludeClipRect
UpdateColors
DeleteDC
GetTextExtentPoint32A
CreateCompatibleDC
DeleteObject
TextOutA
SetBkColor
SetTextColor
Rectangle
CreateSolidBrush
GetStockObject
SelectObject
CreateFontIndirectA
GetTextExtentExPointA
SetMapMode
GetDeviceCaps
GetTextMetricsA
CreateFontA
RealizePalette
ImmGetCompositionStringW
ImmSetCompositionFontA
ImmGetContext
ImmSetCompositionWindow
CoUninitialize
CoInitialize
CoCreateInstance
acmStreamOpen
mciSendStringA
#######
###;KK>
26;2+##########
#########
#####+bEXL
+######+
#####3
######3#
PD[>J22Ib|tLx63
#######3#>>
vDDP>2
########3+ug
DW[[FvV####
########3#J~~3#5gJIk#
3333333333+g +zT
##++++######
3333333333#J%Tz+33#3333######
33333333333+
#33############
33333333333@II#333###########
33333333333@+333333#########
33333333@?a
+233333#3#######
33@j+23333333#######
j@33333333#######
+jj23333333333####
+I@3333333333##
2+@2333333333#
al233333333
$$$2333
C&SCCCSCS&&&&
&&&&$$
7:::::::****************ss****@$$$$$
788888881;111n;;;11p;11111111;
))))))
o,,,,,,,L6,6Lr66rq6,,,,,,,E
)f/HHHH/
8(((((,Lx|>>Eq6,(,((,EM&/-999N/
K((((((XmV#R?DlV((((((EMC/N9<<<<<
,444444X|JJVT
DRmXF4444F4VMC-9<UUU
(444444X3?
DPIDP#F04440tM
4000000y2WIWRIuRI
0000050
5y{kkJ0? D~`f9f
0%%%%%%_
3^%%%%%y`f\f#
%%%%%%%%^_a%G_a%%G=%%%%%%^`f\f#
%%%%%%%%%BB%%%BB%GG%BB%GGGGG%G`f
G.......'''''''''''''''''''''.
-----------------d-)/
&&&&$$$&
$$$$$$$
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Thank you for choosing Microsoft Office 2013. This is a license agreement between you and Microsoft Corporation (or, based on where you live, one of its affiliates) that describes your rights to use the Office 2013 software. For your convenience, we
ve organized this agreement into two parts. The first part includes introductory terms;
jAtIk:
Microsoft Updates1
Microsoft Updates0
191006134601Z
201006140601Z0E1
Microsof
Thank you for choosing Microsoft Office 2013. This is a license agreement between you and Microsoft Corporation (or, based on where you live, one of its affiliates) that describes your rights to use the Office 2013 software. For your convenience, we
ve organized this agreement into two parts. The first part includes introductory terms;
user32.dll
CreateWindowExA
GetMessageA
DispatchMessageA
DefWindowProcA
PostQuitMessage
GetForegroundWindow
SetForegroundWindow
CreateMenu
GetSystemMenu
GetDoubleClickTime
UpdateWindow
GetQueueStatus
GetClipboardOwner
FindWindowA
LoadIconA
LoadCursorA
RegisterClassA
GDI32.dll
CreateBitmap
IntersectClipRect
ExcludeClipRect
UpdateColors
DeleteDC
GetTextExtentPoint32A
CreateCompatibleDC
DeleteObject
TextOutA
SetBkColor
SetTextColor
Rectangle
CreateSolidBrush
GetStockObject
SelectObject
CreateFontIndirectA
GetTextExtentExPointA
SetMapMode
GetDeviceCaps
GetTextMetricsA
CreateFontA
RealizePalette
Winmm.dll
mciSendStringA
Msacm32.dll
acmStreamOpen
IMM32.dll
ImmGetCompositionStringW
ImmSetCompositionFontA
ImmGetContext
ImmSetCompositionWindow
kernel32.dll
GetModuleHandleA
CreateSemaphoreW
GetProcAddress
HeapCreate
HeapAlloc
ExitProcess
FreeLibrary
OLE32.dll
CoUninitialize
CoInitialize
CoCreateInstance
user32.dll
CreateWindowExA
GetMessageA
DispatchMessageA
DefWindowProcA
PostQuitMessage
GetForegroundWindow
SetForegroundWindow
CreateMenu
GetSystemMenu
GetDoubleClickTime
UpdateWindow
GetQueueStatus
GetClipboardOwner
FindWindowA
LoadIconA
LoadCursorA
RegisterClassA
GDI32.dll
CreateBitmap
IntersectClipRect
ExcludeClipRect
UpdateColors
DeleteDC
GetTextExtentPoint32A
CreateCompatibleDC
DeleteObject
TextOutA
SetBkColor
SetTextColor
Rectangle
CreateSolidBrush
GetStockObject
SelectObject
CreateFontIndirectA
GetTextExtentExPointA
SetMapMode
GetDeviceCaps
GetTextMetricsA
CreateFontA
RealizePalette
Winmm.dll
mciSendStringA
Msacm32.dll
acmStreamOpen
IMM32.dll
ImmGetCompositionStringW
ImmSetCompositionFontA
ImmGetContext
ImmSetCompositionWindow
kernel32.dll
GetModuleHandleA
CreateSemaphoreW
GetProcAddress
HeapCreate
HeapAlloc
ExitProcess
FreeLibrary
OLE32.dll
CoUninitialize
CoInitialize
CoCreateInstance
Thank you for choosing Microsoft Office 2013. This is a license agreement between you and Microsoft Corporation (or, based on where you live, one of its affiliates) that describes your rights to use the Office 2013 software. For your convenience, we
ve organized this agreement into two parts. The first part includes introductory terms;
user32.dll
CreateWindowExA
GetMessageA
DispatchMessageA
DefWindowProcA
PostQuitMessage
GetForegroundWindow
SetForegroundWindow
CreateMenu
GetSystemMenu
GetDoubleClickTime
UpdateWindow
GetQueueStatus
GetClipboardOwner
FindWindowA
LoadIconA
LoadCursorA
RegisterClassA
GDI32.dll
CreateBitmap
IntersectClipRect
ExcludeClipRect
UpdateColors
DeleteDC
GetTextExtentPoint32A
CreateCompatibleDC
DeleteObject
TextOutA
SetBkColor
SetTextColor
Rectangle
CreateSolidBrush
GetStockObject
SelectObject
CreateFontIndirectA
GetTextExtentExPointA
SetMapMode
GetDeviceCaps
GetTextMetricsA
CreateFontA
RealizePalette
Winmm.dll
mciSendStringA
Msacm32.dll
acmStreamOpen
IMM32.dll
ImmGetCompositionStringW
ImmSetCompositionFontA
ImmGetContext
ImmSetCompositionWindow
kernel32.dll
GetModuleHandleA
CreateSemaphoreW
GetProcAddress
HeapCreate
HeapAlloc
ExitProcess
FreeLibrary
OLE32.dll
CoUninitialize
CoInitialize
CoCreateInstance
user32.dll
CreateWindowExA
GetMessageA
DispatchMessageA
DefWindowProcA
PostQuitMessage
GetForegroundWindow
SetForegroundWindow
CreateMenu
GetSystemMenu
GetDoubleClickTime
UpdateWindow
GetQueueStatus
GetClipboardOwner
FindWindowA
LoadIconA
LoadCursorA
RegisterClassA
GDI32.dll
CreateBitmap
IntersectClipRect
ExcludeClipRect
UpdateColors
DeleteDC
GetTextExtentPoint32A
CreateCompatibleDC
DeleteObject
TextOutA
SetBkColor
SetTextColor
Rectangle
CreateSolidBrush
GetStockObject
SelectObject
CreateFontIndirectA
GetTextExtentExPointA
SetMapMode
GetDeviceCaps
GetTextMetricsA
CreateFontA
RealizePalette
Winmm.dll
mciSendStringA
Msacm32.dll
acmStreamOpen
IMM32.dll
ImmGetCompositionStringW
ImmSetCompositionFontA
ImmGetContext
ImmSetCompositionWindow
kernel32.dll
GetModuleHandleA
CreateSemaphoreW
GetProcAddress
HeapCreate
HeapAlloc
ExitProcess
FreeLibrary
OLE32.dll
CoUninitialize
CoInitialize
CoCreateInstance
Thank you for choosing Microsoft Office 2013. This is a license agreement between you and Microsoft Corporation (or, based on where you live, one of its affiliates) that describes your rights to use the Office 2013 software. For your convenience, we
ve organized this agreement into two parts. The first part includes introductory terms;
user32.dll
CreateWindowExA
GetMessageA
DispatchMessageA
DefWindowProcA
PostQuitMessage
GetForegroundWindow
SetForegroundWindow
CreateMenu
GetSystemMenu
GetDoubleClickTime
UpdateWindow
GetQueueStatus
GetClipboardOwner
FindWindowA
LoadIconA
LoadCursorA
RegisterClassA
GDI32.dll
CreateBitmap
IntersectClipRect
ExcludeClipRect
UpdateColors
DeleteDC
GetTextExtentPoint32A
CreateCompatibleDC
DeleteObject
TextOutA
SetBkColor
SetTextColor
Rectangle
CreateSolidBrush
GetStockObject
SelectObject
CreateFontIndirectA
GetTextExtentExPointA
SetMapMode
GetDeviceCaps
GetTextMetricsA
CreateFontA
RealizePalette
Winmm.dll
mciSendStringA
Msacm32.dll
acmStreamOpen
IMM32.dll
ImmGetCompositionStringW
ImmSetCompositionFontA
ImmGetContext
ImmSetCompositionWindow
kernel32.dll
GetModuleHandleA
CreateSemaphoreW
GetProcAddress
HeapCreate
HeapAlloc
ExitProcess
FreeLibrary
OLE32.dll
CoUninitialize
CoInitialize
CoCreateInstance
Thank you for choosing Microsoft Office 2013. This is a license agreement between you and Microsoft Corporation (or, based on where you live, one of its affiliates) that describes your rights to use the Office 2013 software. For your convenience, we
ve organized this agreement into two parts. The first part includes introductory terms;
user32.dll
CreateWindowExA
GetMessageA
DispatchMessageA
DefWindowProcA
PostQuitMessage
GetForegroundWindow
SetForegroundWindow
CreateMenu
GetSystemMenu
GetDoubleClickTime
UpdateWindow
GetQueueStatus
GetClipboardOwner
FindWindowA
LoadIconA
LoadCursorA
RegisterClassA
GDI32.dll
CreateBitmap
IntersectClipRect
ExcludeClipRect
UpdateColors
DeleteDC
GetTextExtentPoint32A
CreateCompatibleDC
DeleteObject
TextOutA
SetBkColor
SetTextColor
Rectangle
CreateSolidBrush
GetStockObject
SelectObject
CreateFontIndirectA
GetTextExtentExPointA
SetMapMode
GetDeviceCaps
GetTextMetricsA
CreateFontA
RealizePalette
Winmm.dll
mciSendStringA
Msacm32.dll
acmStreamOpen
IMM32.dll
ImmGetCompositionStringW
ImmSetCompositionFontA
ImmGetContext
ImmSetCompositionWindow
kernel32.dll
GetModuleHandleA
CreateSemaphoreW
GetProcAddress
HeapCreate
HeapAlloc
ExitProcess
FreeLibrary
OLE32.dll
CoUninitialize
CoInitialize
CoCreateInstance
Thank you for choosing Microsoft Office 2013. This is a license agreement between you and Microsoft Corporation (or, based on where you live, one of its affiliates) that describes your rights to use the Office 2013 software. For your convenience, we
ve organized this agreement into two parts. The first part includes introductory terms;
user32.dll
CreateWindowExA
GetMessageA
DispatchMessageA
DefWindowProcA
PostQuitMessage
GetForegroundWindow
SetForegroundWindow
CreateMenu
GetSystemMenu
GetDoubleClickTime
UpdateWindow
GetQueueStatus
GetClipboardOwner
FindWindowA
LoadIconA
LoadCursorA
RegisterClassA
GDI32.dll
CreateBitmap
IntersectClipRect
ExcludeClipRect
UpdateColors
DeleteDC
GetTextExtentPoint32A
CreateCompatibleDC
DeleteObject
TextOutA
SetBkColor
SetTextColor
Rectangle
CreateSolidBrush
GetStockObject
SelectObject
CreateFontIndirectA
GetTextExtentExPointA
SetMapMode
GetDeviceCaps
GetTextMetricsA
CreateFontA
RealizePalette
Winmm.dll
mciSendStringA
Msacm32.dll
acmStreamOpen
IMM32.dll
ImmGetCompositionStringW
ImmSetCompositionFontA
ImmGetContext
ImmSetCompositionWindow
kernel32.dll
GetModuleHandleA
CreateSemaphoreW
GetProcAddress
HeapCreate
HeapAlloc
ExitProcess
FreeLibrary
OLE32.dll
CoUninitialize
CoInitialize
CoCreateInstance
user32.dll
CreateWindowExA
GetMessageA
DispatchMessageA
DefWindowProcA
PostQuitMessage
GetForegroundWindow
SetForegroundWindow
CreateMenu
GetSystemMenu
GetDoubleClickTime
UpdateWindow
GetQueueStatus
GetClipboardOwner
FindWindowA
LoadIconA
LoadCursorA
RegisterClassA
GDI32.dll
CreateBitmap
IntersectClipRect
ExcludeClipRect
UpdateColors
DeleteDC
GetTextExtentPoint32A
CreateCompatibleDC
DeleteObject
TextOutA
SetBkColor
SetTextColor
Rectangle
CreateSolidBrush
GetStockObject
SelectObject
CreateFontIndirectA
GetTextExtentExPointA
SetMapMode
GetDeviceCaps
GetTextMetricsA
CreateFontA
RealizePalette
Winmm.dll
mciSendStringA
Msacm32.dll
acmStreamOpen
IMM32.dll
ImmGetCompositionStringW
ImmSetCompositionFontA
ImmGetContext
ImmSetCompositionWindow
kernel32.dll
GetModuleHandleA
CreateSemaphoreW
GetProcAddress
HeapCreate
HeapAlloc
ExitProcess
FreeLibrary
OLE32.dll
CoUninitialize
CoInitialize
CoCreateInstance
user32.dll
CreateWindowExA
GetMessageA
DispatchMessageA
DefWindowProcA
PostQuitMessage
GetForegroundWindow
SetForegroundWindow
CreateMenu
GetSystemMenu
GetDoubleClickTime
UpdateWindow
GetQueueStatus
GetClipboardOwner
FindWindowA
LoadIconA
LoadCursorA
RegisterClassA
GDI32.dll
CreateBitmap
IntersectClipRect
ExcludeClipRect
UpdateColors
DeleteDC
GetTextExtentPoint32A
CreateCompatibleDC
DeleteObject
TextOutA
SetBkColor
SetTextColor
Rectangle
CreateSolidBrush
GetStockObject
SelectObject
CreateFontIndirectA
GetTextExtentExPointA
SetMapMode
GetDeviceCaps
GetTextMetricsA
CreateFontA
RealizePalette
Winmm.dll
mciSendStringA
Msacm32.dll
acmStreamOpen
IMM32.dll
ImmGetCompositionStringW
ImmSetCompositionFontA
ImmGetContext
ImmSetCompositionWindow
kernel32.dll
GetModuleHandleA
CreateSemaphoreW
GetProcAddress
HeapCreate
HeapAlloc
ExitProcess
FreeLibrary
OLE32.dll
CoUninitialize
CoInitialize
CoCreateInstance
user32.dll
CreateWindowExA
GetMessageA
DispatchMessageA
DefWindowProcA
PostQuitMessage
GetForegroundWindow
SetForegroundWindow
CreateMenu
GetSystemMenu
GetDoubleClickTime
UpdateWindow
GetQueueStatus
GetClipboardOwner
FindWindowA
LoadIconA
LoadCursorA
RegisterClassA
GDI32.dll
CreateBitmap
IntersectClipRect
ExcludeClipRect
UpdateColors
DeleteDC
GetTextExtentPoint32A
CreateCompatibleDC
DeleteObject
TextOutA
SetBkColor
SetTextColor
Rectangle
CreateSolidBrush
GetStockObject
SelectObject
CreateFontIndirectA
GetTextExtentExPointA
SetMapMode
GetDeviceCaps
GetTextMetricsA
CreateFontA
RealizePalette
Winmm.dll
mciSendStringA
Msacm32.dll
acmStreamOpen
IMM32.dll
ImmGetCompositionStringW
ImmSetCompositionFontA
ImmGetContext
ImmSetCompositionWindow
kernel32.dll
GetModuleHandleA
CreateSemaphoreW
GetProcAddress
HeapCreate
HeapAlloc
ExitProcess
FreeLibrary
OLE32.dll
CoUninitialize
CoInitialize
CoCreateInstance
[gT'&gOc
jAtIk:
Microsoft Updates1
Microsoft Updates0
191006134601Z
201006140601Z0E1
Microsoft Updates1
Microsoft Updates0
iqi9O\
mP]>90dm{lx
'5{Rvu@;
Trw32u
JeJ[bcU
yT`o>,
W+Nt./
UJ"Tem4E
ME>bwbR
~|NYKw
Western Cape1
Durbanville1
Thawte1
Thawte Certification10
Thawte Timestamping CA0
121221000000Z
201230235959Z0^1
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
%y"W*o
%CE{t"
MD$k_E;DC
&Mq1Qa
xE/W?=
Qlie)`
h]jxdE`F~T
_n\t}?L.02
http://ocsp.thawte.com0
8060420.http://crl.thawte.com/ThawteTimestampingCA.crl0
TimeStamp-2048-10
DnmX|0i#s
y@b%n7j!
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
121018000000Z
201229235959Z0b1
Symantec Corporation1402
+Symantec Time Stamping Services Signer - G40
[LvCK"+Ch@O8
2[^Z(P
Gf=Gpr_
L-wDh
[2V3cI:3
http://ts-ocsp.ws.symantec.com07
+http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
50301/-+http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
TimeStamp-2048-20
_n\t}?L.0
Lb07x'
2m,&c3Idm
7Cxx(
]=Qy3+.{
[0W,I?
>"hcSit
Microsoft Updates1
Microsoft Updates
jAtIk:
http://www.ms.com/0
W0mwAG
fa*HZ#D
.!]~\n
ZafEtY5+
Symantec Corporation100.
'Symantec Time Stamping Services CA - G2
191011140749Z0#
cyrQvS@q#V
u`j#\HHD!
About
MS Sans Serif
VS_VERSION_INFO
StringFileInfo
08000025
Comments
CompanyName
MSFT Corp
FileDescrsiption
calc.exe
FileVersion
2.1.1.2
InternalName
calc.exe
LegalCopyright
Copyright (C) 2011
LegalTrademarks
OriginalFilename
calc.exe
PrivateBuild
ProductName
ProductVersion
3.1.1.3
SpecialBuild
VarFileInfo
Translation
<<<Obsolete>>
<<<Obsolete>>
putty.ex
C:\e8ceafbbc6e9c046e4b4deefd263682719ff915bf2698cbdf3cfbfc08e89d3d2
C:\Users\admin\Downloads\hhcbrnaff.exe
C:\Users\Petra\AppData\Local\Temp\hhcbrnaff.pe32
C:\Users\admin\Downloads\3052387a8b03968e_hhcbrnaff.exe
C:\Users\Petra\AppData\Local\Temp\hhcbrnaff.pe32
C:\23e9d29da2cb44473b132e00a64ba66495cd5f229d9333f0e1bfc005257dec4a
C:\8f2977bf7a49d83b30f041ad42f812c0a9989fbc5c5d63275f21acafc5a10b1d
C:\Users\Lisa\Desktop\mTdA6zLP.exe
C:\394b234f7986f068979fb2af532055b926e1c9bc22f0e6609b7059f6c749efa1
C:\7938f3645fccf2581ccdef0d5491012302aa5c4406f3357f1ee137afbabffe4e
C:\Documents and Settings\Administrator\Desktop\KdrGrQGg.exe
C:\759b3b1a93ca99a2a41cca70e3c2537c62d4d10cc083a0a281dd66fd523eea76
C:\Documents and Settings\Administrator\Desktop\DBHRakXf.exe
C:\Users\Petra\AppData\Local\Temp\.pe32.exe
C:\32b002cd5840ab3f504348dc9ed7b309c3ebd8e46b17ac78c515bc5bbd6e8b0b
C:\c8669991108b9699bf257a61c4231c783760606569e0b618fad29d35b8cf30bb
C:\Documents and Settings\Administrator\Desktop\lUr0zxMH.exe
C:\Users\admin\Downloads\dfe5443c87db3ae6258bba420f9ef289aad720b8409d493c3eea254afa6487a4.exe
C:\Users\Virtual\AppData\Local\Temp\0a010d81c7296cdd07d57bc4d167928b2673c0f191f6a1db8c5f674680850fd2.exe
C:\140ae853fc1870b55ec7d4b655c704ad53911be48f0885ca7febc138d64a7321
C:\Users\admin\Downloads\hhcbrnaff.exe
C:\b2def7b5b217fbe3d9681232f18a68a35987268a6bceaf15f441cf027d28cea1
C:\d67e2732b66b509c5813aa8ab631e88936e16c72773823504683b2105e2f8e07
C:\Documents and Settings\Administrator\Desktop\UGLXuyXv.exe
C:\Users\Petra\AppData\Local\Temp\.pe32.exe
C:\Users\admin\Downloads\7c9ac75fede1aeda_hhcbrnaff.exe
C:\d7ea90ee40ad8b656358ddbbbf548355216aaf8953f42c28589a93662150b5f0
C:\ba20048f43073d8cc48396a1eddde74e7d3b5b0843cace016daf1a6e17795f6f
C:\ea580765f654dde5ec15ee559d61a764f2a95479a520cf0c1e342b73f953395d
C:\Users\Lisa\Desktop\peZqJEyx.exe
C:\Users\admin\Downloads\02d9d42b1d644379290d0c2cbf2a751672c091d54f57a56853cab39b89ef0a45.exe
C:\161f5057652a6040455b4fd959b037b57bae3d717d02b4ee2f06c1a2c9aa6a17
C:\2e03bcb7332876ea86562f13f907d1b5ad9be5c211a527eab1ed6e43e59d3161
C:\Users\Lisa\Desktop\2x3C2TpM.exe
C:\7a1601f26cdbf70b3f43a5347b652b6ebed2a776a375585258b07f9b70e48440
C:\Users\Lisa\Desktop\tp2VI3es.exe
C:\810a27d67e3578ff98a30fcc45673a1042953c1cb43a3857afc706444c0c4747
C:\Documents and Settings\Administrator\Desktop\4mW3dEzg.exe
C:\04a69ccb985c60016153374d891a0a4577a0d7a73fcc1845cf75eed7414397f5
C:\Users\Lisa\Desktop\zUgbQfh3.exe
C:\Users\admin\Downloads\694d1c8c4d71c9a594e34b1ff155b0798b0863593a41d4a6aa66fbc2084e016e.exe
C:\92fba073450a709b07b4fe8de041350030fc3b1ac295dd1d2a69132b3aa9fb72
C:\Users\admin\Downloads\hhcbrnaff.exe
C:\957687cc720c891d7edb40e814a6b4314fea487c3e1ff11dcdab400ce4ece816
C:\77677ed2a46692639518ed9b8d13196f1f0b72e5a20cd11592d3bd937a2cf23d
C:\5c8d755ac8f0cf30a286e041875bf0a3b400e9b13a7cd3e0a29a49b30476c126
C:\0ed85d091ebbc69c8a4bc780501633147f46ba9af81cb42665adeec1f1c38b95
C:\8c7f84a0d346d5346d3c02060cc42731e72f02de0984b9a156a127b73d77f910
C:\Documents and Settings\Administrator\Desktop\AxPeBQ5e.exe
C:\Users\Petra\AppData\Local\Temp\.pe32.exe
C:\Users\Lisa\Desktop\DAcLiUNh.exe
C:\Users\Petra\AppData\Local\Temp\.pe32.exe
C:\Users\admin\Downloads\e10c7b21a018f401_hhcbrnaff.exe
C:\Users\Lisa\Desktop\NTnQc4KG.exe
C:\Users\Petra\AppData\Local\Temp\.pe32.exe
C:\Users\Petra\AppData\Local\Temp\hhcbrnaff.pe32
C:\Users\admin\Downloads\4ceada79d0663ed8_hhcbrnaff.exe
C:\c7f4b1519301ff3bfb05da2ce9ad404b5603223e3a743d8128960b5f8c434f3b
C:\Users\Lisa\Desktop\6yx2X1Kj.exe
C:\Users\RA491~1.VUL\AppData\Local\Temp\ea5ced9eec426219d0a70580a0b9bf02.bin
C:\Users\admin\Downloads\hhcbrnaff.exe
C:\b0db53f5b4b4ad7e55f90f046a75b3396ea952e202163ddc83893d4cf83290e1
C:\Users\Lisa\Desktop\fQnqvr1o.exe
C:\d42216f6b24b16b36d643b7bc8cb6e1448dea2edc670e042e5757cbd946d097b
C:\Users\Lisa\Desktop\J3OSjuwp.exe
C:\Users\admin\Downloads\d81d6ffacb90c7f9174a2d85ded9959feebdd08946ea2319f3e904f8725efcc8.exe

Process Tree


01f206ce6de06e57e8e3eb383a08f637a4f4197414c56d27f9fe203812800945.exe, PID: 3028, Parent PID: 2600

default registry file network process services synchronisation iexplore office pdf

hhcbrnaff.exe, PID: 2736, Parent PID: 3028

default registry file network process services synchronisation iexplore office pdf

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 61714 8.8.8.8 53
192.168.56.101 56933 8.8.8.8 53
192.168.56.101 138 192.168.56.255 138
192.168.56.101 58485 114.114.114.114 53
192.168.56.101 58485 8.8.8.8 53
192.168.56.101 57665 114.114.114.114 53

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Name 177ddc4d1d5b9e99_hhcbrnaff.exe
Filepath C:\Users\Administrator\AppData\Local\Temp\hhcbrnaff.exe
Size 52.8KB
Processes 3028 (01f206ce6de06e57e8e3eb383a08f637a4f4197414c56d27f9fe203812800945.exe)
Type MS-DOS executable PE32 executable (GUI) Intel 80386, for MS Windows, MZ for MS-DOS
MD5 5bfb1eebbadd6a3284b0170d34a6a5d9
SHA1 0375f54c86dcf41fdd59c8ec5014a3b512d346a6
SHA256 177ddc4d1d5b9e99d15e9db0c0e39d93ba64d0946f5206759e052abd59063e41
CRC32 0B5D6E06
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 06a9ad9f438bc7042361e5bfecc26d3b0e70d13f
Size 4.5KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 373ff9f9ae3aa84057dc941235b736b3
SHA1 06a9ad9f438bc7042361e5bfecc26d3b0e70d13f
SHA256 88a084e2b02bd1c1e862284a1ebebdc1e6bcce2dacd72ec48d301b4ab8dc5b2d
CRC32 103485D7
ssdeep None
Yara None matched
VirusTotal Search for analysis