1.4
低危

b6d31653cb94012c2361ffd10cf78e63605db7399c20290bba26bbc186cb240d

482b1a0df780800d77196572c6700e6c.exe

分析耗时

18s

最近分析

文件大小

182.5KB
静态报毒 动态报毒 JGKF MALICIOUS
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
CrowdStrike 20210203 1.0
Alibaba 20190527 0.3.0.5
Baidu 20190318 1.0.0.2
Avast 20210409 21.1.5827.0
Kingsoft 20210409 2017.9.26.565
McAfee 20210409 6.0.6.653
Tencent 20210409 1.0.0.1
静态指标
Checks if process is being debugged by a debugger (1 个事件)
Time & API Arguments Status Return Repeated
1620726219.836465
IsDebuggerPresent
failed 0 0
Command line console output was observed (8 个事件)
Time & API Arguments Status Return Repeated
1620726220.477465
WriteConsoleA
buffer: {"SysInfoVersion":"
console_handle: 0x00000007
success 1 0
1620726220.477465
WriteConsoleA
buffer: "Vendor":"
console_handle: 0x00000007
success 1 0
1620726220.477465
WriteConsoleA
buffer: Microsoft Corporation
console_handle: 0x00000007
success 1 0
1620726220.477465
WriteConsoleA
buffer: "Renderer":"
console_handle: 0x00000007
success 1 0
1620726220.477465
WriteConsoleA
buffer: GDI Generic
console_handle: 0x00000007
success 1 0
1620726220.477465
WriteConsoleA
buffer: "Version":"
console_handle: 0x00000007
success 1 0
1620726220.477465
WriteConsoleA
buffer: "Extensions":"
console_handle: 0x00000007
success 1 0
1620726220.477465
WriteConsoleA
buffer: GL_WIN_swap_hint GL_EXT_bgra GL_EXT_paletted_texture
console_handle: 0x00000007
success 1 0
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2020-08-28 15:33:07

Imports

Library OPENGL32.dll:
0x41e13c glGetString
0x41e140 wglMakeCurrent
0x41e144 wglCreateContext
0x41e148 wglDeleteContext
Library KERNEL32.dll:
0x41e00c GetProcessHeap
0x41e010 SetStdHandle
0x41e014 GetLastError
0x41e018 GetModuleHandleA
0x41e024 HeapSize
0x41e028 GetOEMCP
0x41e02c GetACP
0x41e030 IsValidCodePage
0x41e034 FindNextFileW
0x41e038 FindFirstFileExW
0x41e03c FindClose
0x41e040 CreateFileW
0x41e048 GetCurrentThreadId
0x41e04c WideCharToMultiByte
0x41e05c MultiByteToWideChar
0x41e060 EncodePointer
0x41e064 DecodePointer
0x41e068 SetLastError
0x41e070 SwitchToThread
0x41e074 TlsAlloc
0x41e078 TlsGetValue
0x41e07c TlsSetValue
0x41e080 TlsFree
0x41e088 GetModuleHandleW
0x41e08c GetProcAddress
0x41e090 CompareStringW
0x41e094 LCMapStringW
0x41e098 GetLocaleInfoW
0x41e09c GetStringTypeW
0x41e0a0 GetCPInfo
0x41e0ac GetCurrentProcess
0x41e0b0 TerminateProcess
0x41e0bc GetCurrentProcessId
0x41e0c0 WriteConsoleW
0x41e0c4 InitializeSListHead
0x41e0c8 IsDebuggerPresent
0x41e0cc GetStartupInfoW
0x41e0d0 RaiseException
0x41e0d4 RtlUnwind
0x41e0d8 FreeLibrary
0x41e0dc LoadLibraryExW
0x41e0e0 GetStdHandle
0x41e0e4 WriteFile
0x41e0e8 GetModuleFileNameW
0x41e0ec ExitProcess
0x41e0f0 GetModuleHandleExW
0x41e0f4 GetCommandLineA
0x41e0f8 GetCommandLineW
0x41e0fc HeapFree
0x41e100 IsValidLocale
0x41e104 GetUserDefaultLCID
0x41e108 EnumSystemLocalesW
0x41e10c HeapAlloc
0x41e110 GetFileType
0x41e114 CloseHandle
0x41e118 FlushFileBuffers
0x41e11c GetConsoleCP
0x41e120 GetConsoleMode
0x41e124 ReadFile
0x41e128 GetFileSizeEx
0x41e12c SetFilePointerEx
0x41e130 ReadConsoleW
0x41e134 HeapReAlloc
Library USER32.dll:
0x41e150 DefWindowProcA
0x41e154 DestroyWindow
0x41e158 CreateWindowExA
0x41e15c GetDC
0x41e160 ReleaseDC
0x41e164 RegisterClassA
0x41e168 UnregisterClassA
Library GDI32.dll:
0x41e000 ChoosePixelFormat
0x41e004 SetPixelFormat

Hosts

No hosts contacted.

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 49235 114.114.114.114 53
192.168.56.101 50534 114.114.114.114 53
192.168.56.101 56539 114.114.114.114 53
192.168.56.101 65004 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 51378 224.0.0.252 5355
192.168.56.101 51808 224.0.0.252 5355
192.168.56.101 55368 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 60123 224.0.0.252 5355
192.168.56.101 62191 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900
192.168.56.101 51809 239.255.255.250 3702
192.168.56.101 51811 239.255.255.250 3702
192.168.56.101 56540 239.255.255.250 3702
192.168.56.101 56807 239.255.255.250 1900
192.168.56.101 58707 239.255.255.250 3702

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.