1.3
低危

240136f6e9c54fd2533ba26cfb77a12d12d8de2b81224ce39d9a4ca7b66dbad0

240136f6e9c54fd2533ba26cfb77a12d12d8de2b81224ce39d9a4ca7b66dbad0.exe

分析耗时

195s

最近分析

374天前

文件大小

78.0KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN DOWNLOADER UPATRE
鹰眼引擎
DACN 0.12
FACILE 1.00
IMCLNet 0.67
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba None 20190527 0.3.0.5
Avast Win32:TrojanX-gen [Trj] 20200405 18.4.3895.0
Baidu Win32.Trojan.Kryptik.ld 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (D) 20190702 1.0
Kingsoft None 20200407 2013.8.14.323
McAfee Upatre-FACH!4D473C25CAE2 20200406 6.0.6.653
Tencent Malware.Win32.Gencirc.10b85db8 20200407 1.0.0.1
静态指标
行为判定
动态指标
在 PE 资源中识别到外语 (10 个事件)
name RT_CURSOR language LANG_KOREAN filetype None sublanguage SUBLANG_KOREAN offset 0x00013b20 size 0x00000134
name RT_CURSOR language LANG_KOREAN filetype None sublanguage SUBLANG_KOREAN offset 0x00013b20 size 0x00000134
name RT_BITMAP language LANG_KOREAN filetype None sublanguage SUBLANG_KOREAN offset 0x0000f648 size 0x000000e0
name RT_BITMAP language LANG_KOREAN filetype None sublanguage SUBLANG_KOREAN offset 0x0000f648 size 0x000000e0
name RT_ICON language LANG_KOREAN filetype None sublanguage SUBLANG_KOREAN offset 0x0000f790 size 0x00004228
name RT_GROUP_CURSOR language LANG_KOREAN filetype None sublanguage SUBLANG_KOREAN offset 0x00013c58 size 0x00000014
name RT_GROUP_CURSOR language LANG_KOREAN filetype None sublanguage SUBLANG_KOREAN offset 0x00013c58 size 0x00000014
name RT_GROUP_ICON language LANG_KOREAN filetype None sublanguage SUBLANG_KOREAN offset 0x000139b8 size 0x00000014
name RT_VERSION language LANG_KOREAN filetype None sublanguage SUBLANG_KOREAN offset 0x0000f2e0 size 0x00000284
name RT_MANIFEST language LANG_KOREAN filetype None sublanguage SUBLANG_KOREAN offset 0x00013c70 size 0x0000020c
该二进制文件可能包含加密或压缩数据,表明使用了打包工具 (2 个事件)
section {'name': '.text', 'virtual_address': '0x00001000', 'virtual_size': '0x00007784', 'size_of_data': '0x00007800', 'entropy': 6.980068187899279} entropy 6.980068187899279 description 发现高熵的节
entropy 0.4225352112676056 description 此PE文件的整体熵值较高
网络通信
与未执行 DNS 查询的主机进行通信 (1 个事件)
host 114.114.114.114
文件已被 VirusTotal 上 59 个反病毒引擎识别为恶意 (50 out of 59 个事件)
APEX Malicious
AVG Win32:TrojanX-gen [Trj]
Acronis suspicious
Ad-Aware Trojan.Upatre.Gen.3
AhnLab-V3 Trojan/Win32.Upatre.R159277
Antiy-AVL Trojan/Win32.AGeneric
Arcabit Trojan.Upatre.Gen.3
Avast Win32:TrojanX-gen [Trj]
Avira HEUR/AGEN.1005641
Baidu Win32.Trojan.Kryptik.ld
BitDefender Trojan.Upatre.Gen.3
BitDefenderTheta Gen:NN.ZexaF.34104.eu1@ayhE4dpG
CAT-QuickHeal Trojan.Kadena.B4
ClamAV Win.Downloader.Upatre-5744092-0
Comodo TrojWare.Win32.TrojanDownloader.Upatre.EMD@5syzmz
CrowdStrike win/malicious_confidence_100% (D)
Cybereason malicious.5cae21
Cylance Unsafe
Cyren W32/Upatre.CC.gen!Eldorado
DrWeb Trojan.DownLoader15.25237
ESET-NOD32 a variant of Win32/Kryptik.DQWK
Emsisoft Trojan.Upatre.Gen.3 (B)
Endgame malicious (high confidence)
F-Prot W32/Upatre.CC.gen!Eldorado
F-Secure Heuristic.HEUR/AGEN.1005641
FireEye Generic.mg.4d473c25cae21a8d
Fortinet W32/Kryptik.DQAA!tr
GData Win32.Trojan.Kryptik.CE
Ikarus Trojan-Downloader.Win32.Waski
Invincea heuristic
Jiangmin Trojan/Generic.bhpht
K7AntiVirus Trojan ( 004ce6cb1 )
K7GW Trojan ( 004ce6cb1 )
Kaspersky HEUR:Trojan.Win32.Generic
MAX malware (ai score=87)
Malwarebytes Trojan.Upatre
MaxSecure Trojan.Upatre.Gen
McAfee Upatre-FACH!4D473C25CAE2
McAfee-GW-Edition BehavesLike.Win32.Upatre.lm
MicroWorld-eScan Trojan.Upatre.Gen.3
Microsoft TrojanDownloader:Win32/Upatre
NANO-Antivirus Trojan.Win32.Vundo.fnbwzl
Panda Trj/Genetic.gen
Qihoo-360 HEUR/QVM07.1.668B.Malware.Gen
Rising Downloader.Upatre!8.B5 (TFE:dGZlOgWNB69yeUSCFA)
SUPERAntiSpyware Trojan.Agent/Gen-Upatre
Sangfor Malware
SentinelOne DFI - Malicious PE
Sophos Troj/Dyreza-HP
Tencent Malware.Win32.Gencirc.10b85db8
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2014-03-18 21:35:14

PE Imphash

ebb8c8d8f5176e7424d974dd10acbc2f

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00007784 0x00007800 6.980068187899279
.rdata 0x00009000 0x00001238 0x00001400 4.8785156865574555
.data 0x0000b000 0x00003d9c 0x00003200 1.3706448310998167
.rsrc 0x0000f000 0x00004e80 0x00005000 5.094506921133087
.reloc 0x00014000 0x00000d5c 0x00000e00 3.516894690868984

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x00013b20 0x00000134 LANG_KOREAN SUBLANG_KOREAN None
RT_CURSOR 0x00013b20 0x00000134 LANG_KOREAN SUBLANG_KOREAN None
RT_BITMAP 0x0000f648 0x000000e0 LANG_KOREAN SUBLANG_KOREAN None
RT_BITMAP 0x0000f648 0x000000e0 LANG_KOREAN SUBLANG_KOREAN None
RT_ICON 0x0000f790 0x00004228 LANG_KOREAN SUBLANG_KOREAN None
RT_DIALOG 0x0000f728 0x00000066 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_CURSOR 0x00013c58 0x00000014 LANG_KOREAN SUBLANG_KOREAN None
RT_GROUP_CURSOR 0x00013c58 0x00000014 LANG_KOREAN SUBLANG_KOREAN None
RT_GROUP_ICON 0x000139b8 0x00000014 LANG_KOREAN SUBLANG_KOREAN None
RT_VERSION 0x0000f2e0 0x00000284 LANG_KOREAN SUBLANG_KOREAN None
RT_MANIFEST 0x00013c70 0x0000020c LANG_KOREAN SUBLANG_KOREAN None

Imports

Library USER32.dll:
0x409100 LoadStringA
0x409104 LoadIconA
0x409108 LoadCursorA
0x40910c RegisterClassExA
0x409110 GetMessageA
0x409114 TranslateMessage
0x409118 DispatchMessageA
0x40911c PostQuitMessage
0x409120 SendMessageA
0x409124 BeginPaint
0x409128 GetClientRect
0x40912c DrawTextA
0x409130 EndPaint
0x409134 DefWindowProcA
0x409138 DestroyWindow
0x40913c PostMessageA
0x409140 CreateWindowExA
0x409144 ShowWindow
0x409148 UpdateWindow
Library KERNEL32.dll:
0x409010 GetStringTypeW
0x409014 GetStringTypeA
0x409018 LCMapStringW
0x40901c LCMapStringA
0x409020 MultiByteToWideChar
0x409024 HeapReAlloc
0x409028 VirtualAlloc
0x40902c GlobalSize
0x409030 SizeofResource
0x409034 CreateThread
0x409038 WaitForSingleObject
0x40903c GlobalAlloc
0x409040 FindNextFileW
0x409044 Sleep
0x409048 FindFirstFileW
0x40904c FindClose
0x409050 LoadLibraryA
0x409054 GetModuleHandleA
0x409058 GetProcAddress
0x409060 GetOEMCP
0x409064 GetACP
0x409068 GetCPInfo
0x40906c GetStartupInfoA
0x409070 GetCommandLineA
0x409074 GetVersion
0x409078 ExitProcess
0x40907c TerminateProcess
0x409080 GetCurrentProcess
0x409088 GetModuleFileNameA
0x409094 WideCharToMultiByte
0x40909c SetHandleCount
0x4090a0 GetStdHandle
0x4090a4 GetFileType
0x4090a8 GetCurrentThreadId
0x4090ac TlsSetValue
0x4090b0 TlsAlloc
0x4090b4 SetLastError
0x4090b8 TlsGetValue
0x4090bc GetLastError
0x4090c4 GetVersionExA
0x4090c8 HeapDestroy
0x4090cc HeapCreate
0x4090d0 VirtualFree
0x4090d4 HeapFree
0x4090d8 RtlUnwind
0x4090dc WriteFile
0x4090e0 HeapAlloc
Library COMCTL32.dll:
Library MSIMG32.dll:
0x4090f4 AlphaBlend
0x4090f8 GradientFill

L!This program cannot be run in DOS mode.
7"aich
`.rdata
@.data
@.reloc
UHSVWh
Vjjdh
Vjjd@
zpR\"4*
o6A(
7/DS2V|8N%,P4\!9A 9Q
4:G99Pan
K30dRP7
J6\t'=N&9A
\e=1R
>9"&9dR
.G;.G %u&.NRN
K30c1\q"\a&9r7/Q
*5V19Q%5L&rF
2V7(q"(KR
"7.L=2L
V72F'9Q
2V7(a7
C7\k 2G
R3R&9ZR=R1=V}v"R
rtu=+Q
,R7>igo
R9N=0W7$G|m
?>M|9Z:9A|8[!rM}\
bd"|&Ker
cm"|&Kfr
jl"|&Keo
eo"|&Kcj
eh"|&Ker
gn"|&Ked
an"|&Kkh
el"|&Kjr
dh"|&K`r
cj"|&Kfr
R\+R\+R\+R\+R\+R\+R\+R\+R\+R\+R\+R\+R\+R\+R\+R\+R\+R\+R\+R\+R\+R\+R\+R\+R\+R\+R\+
R\+R\+
R\+R\+R\+R\+R\+R\+R\+R\+R\+
i^P\uTs
'fMy#):
TT"'}tg!
&4&UD3Y)sh}
d(vaD5.?"!}T/
sEw"P'
R5T=Q/
.pVlD3
:Em}:E
a:]#\.8
V'tz6%
*dR\"zZ
Wp"'"'q"
(XY]"VaV
<]R\"8^J
WlZ\"g
gaPzZ(
&XD3n(
Mh".mc:(
Xu}Vo(4
&fnn\W+4
.m}".V'.Y)
qlWw"'
bUez\"
'WJpRw
YeQTPo
W<R\"X)
IRgzJ) R\
oR$8ZM"
PWPzBo
o8F=;Y
r)).(T/?o.as
P]"zH\"
ZQ]"TP:"
\JHRwl)
TrzH\"
J_$<R\" R\u3
Ie_"r<
['ytTgzRw%
ZJFRFXu
tt0B=@
j@Y3`@
@;vAA9
Y_^[3j
_^]PuVF8%
MVWQ_3
GHuGHHGH
Au^H9E
v_^[]Ujh@
3;u>EPj
EPVh\@
E;tc]<
euWSVM
e33M;t)uVu
EPEPVLG
^]UQQS39
EPEPSSWV)
YEPEPE
YtF>"u
< v^Ujhh@
SVWe39=@
"WWSh\@
M]9}tfSuu
tMWWSuu
Mu;tVSuuu
8t9UWl/
YE?=t"Ur;Y
8u]5@
Mu^FF#
NMIIII
Virt^_
R9\(L(u
SV/un8H
k,u3!Eu
</uy8A
^[Ujh@
YYt&V5D@
UTVWEPE
jiVjdh@
YYt)V5D@
YY\WP\M%
@Y<v)\P:%
VW333;u3
SS@SSPVSSD$4
t#SSUPt$$VSS
;t<8t
u+@UY;u
3_^][YYUT3@_H
UWQ_t@
UQSVsvPu
^[]U$S]
3UUUUME}9;
URVMEj
BU;|(E
!E;tv;u2U
_ADAHE
[]UhSVF
W3U]}}
E;t&ESP
EHE0_O
Es_^3[]
t G};}
QPPEWS
RWSPQU
_^3[]j
3[]Vs W}
ujSQvEC
uRS9vEH
QRWVSF
_^3[]SC
E_^[]WSc3
3V}{rX
VqPVEz
_#E[^]
@"t)t%
F8"uF@C
@C8"u,
YY;t>j,P
Y;Yt0@8
[USVWUj
~]_^[]
Pjh4^@
t.;t$$t(4v
VC20XC00U
]_^[]UL$
^Yu3Ujh@
Wj@Y3`@
EVP5D@
t7SWU
BBBu_[j
VPVPV5d@
@AA;rI3
@;r^W|$
tAt2t$
r)$(f@
DDDDDDDDDDDDDD
uA};=@@
9]t^uH3
9]u>Vj
E9]u'9
u,9uv'E
B8t6t8t't
8t3^[_G^[_
^[_UWVSM
r;]uy;
;uY;]s
pD#U#ue
j #M_|
]#\D\D
VW3;u0DP
3_^][Vt$
^UQSV5@
YUQQSV5@
3_^[UQM
CF;sN;Eu
3_^[S39
VWuBhP@
;tg5X@
GIt%t)
Gt/KuD$
GKu[^D$
T [V$@
_^[UQ=@
DDDDDDDDDDDDDD
UV3PPPPPPPPU
$s ^UV3PPPPPPPPU
$sF ^UWVSu
F'G8t,A<
FG8tPS,
[^_UWVSM
uNAZ I
tFGQPS;
[^_SVD$
;^}%95X@
XXaB!"O&VHB<Q$Q)o
LoseUndoAbilityWarning
SaveCurrentModifWarning
ColumnModeTip
J6bHHc/&e/.^i;S(AQ
T]f[GZ/7$.ijc*>37E
;-_H1<cl
thought of it since then - that he had a charm
__GLOBAL_HEAP_SELECTED
__MSVCRT_HEAP_SELECT
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
H:mm:ss
dddd, MMMM dd, yyyy
M/d/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
UpdateWindow
ShowWindow
CreateWindowExA
PostMessageA
DestroyWindow
DefWindowProcA
EndPaint
DrawTextA
GetClientRect
BeginPaint
SendMessageA
PostQuitMessage
DispatchMessageA
TranslateMessage
GetMessageA
RegisterClassExA
LoadCursorA
LoadIconA
LoadStringA
USER32.dll
GlobalSize
SizeofResource
CreateThread
WaitForSingleObject
GlobalAlloc
FindNextFileW
FindFirstFileW
FindClose
LoadLibraryA
GetModuleHandleA
KERNEL32.dll
InitCommonControlsEx
COMCTL32.dll
GradientFill
AlphaBlend
MSIMG32.dll
GetStartupInfoA
GetCommandLineA
GetVersion
ExitProcess
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
GetModuleFileNameA
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
GetCurrentThreadId
TlsSetValue
TlsAlloc
SetLastError
TlsGetValue
GetLastError
GetEnvironmentVariableA
GetVersionExA
HeapDestroy
HeapCreate
VirtualFree
HeapFree
RtlUnwind
WriteFile
HeapAlloc
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
GetCPInfo
GetACP
GetOEMCP
VirtualAlloc
HeapReAlloc
GetProcAddress
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
InterlockedDecrement
InterlockedIncrement
bK_lsBhMRUVQhsK
CannotMoveDoc
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789_-+.,:?&@=/%#()
VEOfAdLJfIcre_rjAOlBHkMjqrFGp
PH[KQip[WMihh_SU^
Magnetick
Charge Window App
button
static
richedit
ABCDEFG
riched32.dll
ffffff
aGGDDV
tttDP`
twGD``awwGtu
PawwwGE
PffffffWP
GtwwwP
www30www
xwwwwwxwwwwrwwwwww
<6WQ</*
nsonmtzmsonontlonqnmtzmtznvzononsnonmsmr
onnrononns
onnuzrlonx{
e[{A2$
}qotwutxw|
}uxvtwugjihjhgjhhki|
+%!++' ++ &
+ ++-
twugligjhtxv
+++ $5'-
H=$++ $+ ++,!$, //
% +,"+/+
/+0 +%
$+,!/+!,"+!0 -
/ $// +-!++!-"+/
6/+!1/0+!/
*$%5
z+!/ /+!7
4,//"// 5 /'
2+5'2%+!+"2++!+"/
/ 2++!3++!+!,!/ -"2++!.$/0
,#/1!/ 4&/ / 3&/ .
y+!0"(
+0",#/ ,#/ '
/ / ,$5
,#>-2%2%3&2%2%0
2&/ /"2%2%2,2%3%2%,#5
,#=-2%2%3&2%8&1#2+0
]^uhp^r_C(7
4 3&\So\ocuhOB7
fap]nbuhvi\S1#5"5"4&5"2%6#5"3&0",#5!
5"4&0"0"1#0"0#2%2%0#4 4 >,2%3%1"2+2&2%8&0$4 5 0"0">,2%2+9'0"1#3%2%2&8&0"9'8&5#1"8&9'8&6
0"5$5"8&6
2%5"6"4 523+0"2&8&6
5"2+3,2%2&4 6
5!4 8&3,2%>-8&4 5#8&5"8'5"5"8&8&:&0"6
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.2.31"
processorArchitecture="X86"
name="TransOcean"
type="win32"/>
<description>TransOcean</description>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="asInvoker"
uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
=0C0e0y00000
1$191]1111111111
3.353S3]3{3333333333333
4"4'414R4_4l4s4~444444
5H5W5\5v555555
78888888
9*999Z9`999999999999+:2:A:d:j:w:::::::<<>>>>>>
?'?:?R?r???
0,00000%1@1Q1_1l1q1w1111
2U2Z2y222222222
30333394^4u444444(545>5b5666g7:::::
;@;E;O;k;;;;;;;
<)<E<<<<<<<<
=!=(=1=;=Z=_=g=m=|========*>2>L>R>c>>>>>>>>6?J?h?t?????????
0I00001111x2
:$:+:5:N:V:[:g:l::::*;o;R<k<<<
= =Y== >a>>>>
040B0000
1(1C1O1Y1d1n1x1~11111111h2n22222222
3/3;3M3[3
50575?5D5H5L5u55555555555"6(6,6064666666666
7M7T7X7\7`7d7h7l7p777777
8 8m8{88
999@:W:o::8=>=E=R=Y=a=g=m=x==???
0*050G0Z0e0k0p0v0000000000
113333333
4+444N4_4e4x4455555555
666666666
7$7\7i777d8j88:9G9V99
:]:;;;;;;;;;;;
<#<=====->_>s>>>
????????
0+0E0L0P0T0X0\0`0d0h000000*151P1W1\1`1d11111111111
2J2P2T2X2\23
4*4y44
5v56666$7
P1T1X1\1`1d1h1l1p1t1x1"5*52565:5F5J5R5Z5^555888
9l9p9x9|999
056d7l7t7|7777777777777777
8$8489999
999>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
? ?$?(?,?0?@?D?H?L?P?T?X?\?`?d?p?
@I@@@@@
online-document.html
Lose Undo Ability Waning
You should save t
he current modification.
All the saved modifications can not be undone.
Continue?
Save Current Modification
Summary
ranges
bytes) in
selected characters (
Current document length:
Lines:
Words:
Characters (without blanks):
File length (in byte):
Modified:
Created:
Full file path:
Please use "ALT+Mouse Se
K Instance
Move to New Instance
Clone to Other View
Move to Other View
Current Dir. Path to Clipboard
Filename to Clipboard
Full File Path to Clipboard
Clear Read-Only Flag
Read-Only
Move to Recycle Bin
Rename
Save As...
Close All to the Ri
Close All to the Left
Close All BUT This
Document is modified, save it then try again.
Move to new Notepad++ Instance
Clone to other View
Move to other view
sinhala.xml
bengali.xml
aragonese.xml
aragon
telugu.xml
uyghur.xml
sardinian.xml
hindi.xml
ligurian.xml
Zeneize
esperanto.xml
Esperanto
bosnian.xml
Bosanski
azerbaijani.xml
rbaycan dili
tamil.xml
((((( H
@@@@@@@@@
@@@@@@@
VS_VERSION_INFO
StringFileInfo
049BC8E0
CompanyName
TransOcean
FileDescription
TransOcean
FileVersion
1.1.4.37
InternalName
LegalCopyright
LegalTrademarks
OriginalFilename
ProductName
TransOcean
ProductVersion
VarFileInfo
Translation
TransOcean
MS Sans Serif
C:\43340cec82439a91dd4c5c80f9b890884a5390f734d01aa1a1942fc174af175d
c:\f78cd1f3adabd54a6e5c430e9f7c8acd3969bf02
C:\9fe758afe4441da768bb964c113de5cf64bea2137b790e41a4204d83a2c40dbb
C:\b19734c259322a3ecae69cd909bb1b73a7af0ce3399bbf58bcb76b7cfccd9bb5
C:\4948dd996380fb265316025e3fa7cb0bd49bd9b463fa1caa92b68486c72c36d3
C:\d88d77a647afbcfb401263c1f8e2b38ebc736cd5b04e9c0d2e8f12be9689464f
C:\45LvDL2K.exe
C:\9ELYRh_f.exe
C:\ZJJPQmug.exe
C:\33e1a2e420cdd54255a6c62d3b5b9b25aa2f234b81ed94f31341fb96ae77d250
C:\QlCKw99_.exe
C:\zJVi9_Fs.exe
C:\ZhDPBuZE.exe
C:\cd8442dc9bdd6e477ef27e4bcbf8e3462ec15dd45c84f656a83c34ebdd6e73f4
C:\acXYSflx.exe
C:\JV8fLmyp.exe
C:\OqIiyhkB.exe
C:\5PRybzmE.exe
C:\tUm95il7.exe
C:\dae912a5b1558d610c81acdfbedd12e249148c0667c413c7e2ecf122ee84390c
C:\k7lFJFJq.exe
C:\lCZBPGcY.exe
C:\gb9K4mRS.exe
C:\pj1ZTQIX.exe
C:\gQBx86r1.exe
C:\5jOfQzxI.exe
C:\9xWgBTYA.exe
C:\1rFJiUqB.exe
C:\yrUfBqjr.exe
C:\A5lALmtf.exe
C:\G4J9fXus.exe
C:\LD8tOBVR.exe
C:\1foCJ0FA.exe
C:\k2aQfBLF.exe
C:\JaWyPajG.exe
C:\QtNdgrid.exe
C:\5UJJPJYK.exe
C:\ooR5WLI_.exe
C:\uxYdicXH.exe
C:\cs9kuL2T.exe
C:\GHCV9UX5.exe
C:\JwUbPusw.exe
C:\LNXZCOPK.exe
C:\Xt1y_iX7.exe
C:\YrKTxhuu.exe
C:\9muaPkbI.exe
C:\D0hlvusj.exe
C:\IrwxYsyt.exe
C:\eCqsI7ts.exe
C:\rgTYzwbK.exe
C:\Zd55lkP5.exe
C:\dntW1dyi.exe
C:\RrQ76i2h.exe
C:\NYxcQuQd.exe
C:\Y089wCQO.exe
C:\J2sGCOtz.exe
C:\BRXljJGR.exe
C:\45RXJ3cL.exe
C:\E5CGgPNi.exe
C:\6Kyi0ZuS.exe
C:\H9cq8EXR.exe
C:\uUtQbEra.exe
C:\P7qKXA8f.exe
C:\HzzxyAEg.exe
C:\PUzF98co.exe
C:\1JVmi8lj.exe
C:\zNdAfEpu.exe
C:\DsCp7PuD.exe
C:\xWXvFQAM.exe
C:\fg3BC8mG.exe
C:\4733e25c671e91173d5f6b81434dcb0fac890cbf.exe
C:\284c395681e710d756a867ff640aba7231a782b7.exe
C:\CML70Fsc.exe
C:\3FaguERV.exe
C:\rnOE5DHq.exe
C:\oGXvCwpD.exe
C:\GVgFtbwM.exe
C:\qk7SgHGP.exe
C:\sGSLq7mT.exe
C:\_dCw45_a.exe
C:\IrLeK0J0.exe
C:\qFfMuQgC.exe
C:\JNsK3bio.exe
C:\FCnXVh9H.exe
C:\qiO1AXJV.exe
C:\KusU3u7a.exe
C:\42LrNB9f.exe
C:\iSV10AkB.exe
C:\OmwqYkYh.exe
C:\orRXJoqR.exe
C:\vt4BeQrP.exe
C:\0QhjJUyU.exe
C:\LheqzhCA.exe
C:\d06b0ee5fb38f89ea86b2a09a05ba1ae2238d50b.exe
C:\Ke4uecZ0.exe
C:\NR5q73dT.exe
C:\pakGD9Zv.exe
C:\TVRE10Ze.exe
C:\erpD1tBr.exe
C:\Users\Petra\AppData\Local\Temp\file.pe32
C:\Users\Petra\AppData\Local\Temp\elarvolume.pe32
C:\d74b6c5c49809e7fa141206e7bec79f86efcd35371f8298153fa18df9a473df9
C:\Users\admin\Downloads\elarvolume.exe
C:\Users\admin\Downloads\e5e6165af9af6f5a6c4c9428900d7f67663c668142b4715336a0b3b3432b7025.exe
C:\2aea9696c32db6da84561de5d0dc3ca78f51d26cdf425a1c1d55d5ffd2873c9e
C:\Users\Petra\AppData\Local\Temp\elarvolume.pe32
C:\fb9598d2818c8eda675188bd91f152266213962345f0622cf278a26c1d000dd5
C:\Users\admin\Downloads\elarvolume.exe
C:\Users\admin\Downloads\52c1c2ae03fe45380bfad412d2ca9c267560773480533ad0a91498ef58ca9ef1.exe
C:\4be79be4c511c53e8919409a3deaa93df65643774cea75676548fd2bbfa3027a
C:\Users\admin\Downloads\elarvolume.exe
C:\Users\RA491~1.VUL\AppData\Local\Temp\542b123d2e70e38972c43c54d13b3b16.exe
C:\Users\RA491~1.VUL\AppData\Local\Temp\542b123d2e70e38972c43c54d13b3b16.exe
C:\1d23cffec5ec83824c388b2b176da1f69879d70a92ac2776af349259d88915b0

DNS

Name Response Post-Analysis Lookup
dns.msftncsi.com A 131.107.255.255 131.107.255.255
dns.msftncsi.com AAAA fd3e:4f5a:5b81::1 131.107.255.255

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 56933 114.114.114.114 53
192.168.56.101 138 192.168.56.255 138

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.