2.4
中危

85553b0630298f6de71b49b0b635143cf8f76641fa2c6e31328a714ca93f254a

53d14d1c4170bef411147d33f750bd7a.exe

分析耗时

81s

最近分析

文件大小

6.9MB
静态报毒 动态报毒 DEALPLY
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
McAfee 20200717 6.0.6.653
Alibaba 20190527 0.3.0.5
Avast 20200717 18.4.3895.0
Baidu 20190318 1.0.0.2
Kingsoft 20200717 2013.8.14.323
Tencent 20200717 1.0.0.1
CrowdStrike 20190702 1.0
行为判定
动态指标
Foreign language identified in PE resource (50 out of 520 个事件)
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00637ec0 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name PNG language LANG_CHINESE offset 0x00167bd8 filetype PNG image data, 128 x 80, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00004eea
name PNG language LANG_CHINESE offset 0x00167bd8 filetype PNG image data, 128 x 80, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00004eea
name PNG language LANG_CHINESE offset 0x00167bd8 filetype PNG image data, 128 x 80, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00004eea
File has been identified by one AntiVirus engine on VirusTotal as malicious (1 个事件)
MaxSecure Adware.not-a-virus.WIN32.AdWare.DealPly.gen_186542
The binary likely contains encrypted or compressed data indicative of a packer (2 个事件)
entropy 7.527489935504683 section {'size_of_data': '0x00576a00', 'virtual_address': '0x0014c000', 'entropy': 7.527489935504683, 'name': '.rsrc', 'virtual_size': '0x00576978'} description A section with a high entropy has been found
entropy 0.7971644343117698 description Overall entropy of this PE file is high
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2019-04-26 20:17:24

Imports

Library Qt5Core.dll:
0x4e36c4 ??0QString@@QAE@XZ
0x4e36f4 ??0QFile@@QAE@XZ
0x4e36fc ??1QFile@@UAE@XZ
0x4e3734 ??1QDir@@QAE@XZ
0x4e3754 ??0QDate@@QAE@HHH@Z
0x4e3828 ?year@QDate@@QBEHXZ
0x4e3830 ?day@QDate@@QBEHXZ
0x4e3834 ?hour@QTime@@QBEHXZ
0x4e38dc ??1QString@@QAE@XZ
Library FFUILib.dll:
0x4e2ab0 ?GetUIScale@@YAMXZ
0x4e2bc0 ??1CPFMemDC@@UAE@XZ
0x4e2bc4 ??0CPFMemDC@@QAE@XZ
Library mfc140u.dll:
0x4e3d50
0x4e3d54
0x4e3d58
0x4e3d5c
0x4e3d60
0x4e3d64
0x4e3d68
0x4e3d6c
0x4e3d70
0x4e3d74
0x4e3d78
0x4e3d7c
0x4e3d80
0x4e3d84
0x4e3d88
0x4e3d8c
0x4e3d90
0x4e3d94
0x4e3d98
0x4e3d9c
0x4e3da0
0x4e3da4
0x4e3da8
0x4e3dac
0x4e3db0
0x4e3db4
0x4e3db8
0x4e3dbc
0x4e3dc0
0x4e3dc4
0x4e3dc8
0x4e3dcc
0x4e3dd0
0x4e3dd4
0x4e3dd8
0x4e3ddc
0x4e3de0
0x4e3de4
0x4e3de8
0x4e3dec
0x4e3df0
0x4e3df4
0x4e3df8
0x4e3dfc
0x4e3e00
0x4e3e04
0x4e3e08
0x4e3e0c
0x4e3e10
0x4e3e14
0x4e3e18
0x4e3e1c
0x4e3e20
0x4e3e24
0x4e3e28
0x4e3e2c
0x4e3e30
0x4e3e34
0x4e3e38
0x4e3e3c
0x4e3e40
0x4e3e44
0x4e3e48
0x4e3e4c
0x4e3e50
0x4e3e54
0x4e3e58
0x4e3e5c
0x4e3e60
0x4e3e64
0x4e3e68
0x4e3e6c
0x4e3e70
0x4e3e74
0x4e3e78
0x4e3e7c
0x4e3e80
0x4e3e84
0x4e3e88
0x4e3e8c
0x4e3e90
0x4e3e94
0x4e3e98
0x4e3e9c
0x4e3ea0
0x4e3ea4
0x4e3ea8
0x4e3eac
0x4e3eb0
0x4e3eb4
0x4e3eb8
0x4e3ebc
0x4e3ec0
0x4e3ec4
0x4e3ec8
0x4e3ecc
0x4e3ed0
0x4e3ed4
0x4e3ed8
0x4e3edc
0x4e3ee0
0x4e3ee4
0x4e3ee8
0x4e3eec
0x4e3ef0
0x4e3ef4
0x4e3ef8
0x4e3efc
0x4e3f00
0x4e3f04
0x4e3f08
0x4e3f0c
0x4e3f10
0x4e3f14
0x4e3f18
0x4e3f1c
0x4e3f20
0x4e3f24
0x4e3f28
0x4e3f2c
0x4e3f30
0x4e3f34
0x4e3f38
0x4e3f3c
0x4e3f40
0x4e3f44
0x4e3f48
0x4e3f4c
0x4e3f50
0x4e3f54
0x4e3f58
0x4e3f5c
0x4e3f60
0x4e3f64
0x4e3f68
0x4e3f6c
0x4e3f70
0x4e3f74
0x4e3f78
0x4e3f7c
0x4e3f80
0x4e3f84
0x4e3f88
0x4e3f8c
0x4e3f90
0x4e3f94
0x4e3f98
0x4e3f9c
0x4e3fa0
0x4e3fa4
0x4e3fa8
0x4e3fac
0x4e3fb0
0x4e3fb4
0x4e3fb8
0x4e3fbc
0x4e3fc0
0x4e3fc4
0x4e3fc8
0x4e3fcc
0x4e3fd0
0x4e3fd4
0x4e3fd8
0x4e3fdc
0x4e3fe0
0x4e3fe4
0x4e3fe8
0x4e3fec
0x4e3ff0
0x4e3ff4
0x4e3ff8
0x4e3ffc
0x4e4000
0x4e4004
0x4e4008
0x4e400c
0x4e4010
0x4e4014
0x4e4018
0x4e401c
0x4e4020
0x4e4024
0x4e4028
0x4e402c
0x4e4030
0x4e4034
0x4e4038
0x4e403c
0x4e4040
0x4e4044
0x4e4048
0x4e404c
0x4e4050
0x4e4054
0x4e4058
0x4e405c
0x4e4060
0x4e4064
0x4e4068
0x4e406c
0x4e4070
0x4e4074
0x4e4078
0x4e407c
0x4e4080
0x4e4084
0x4e4088
0x4e408c
0x4e4090
0x4e4094
0x4e4098
0x4e409c
0x4e40a0
0x4e40a4
0x4e40a8
0x4e40ac
0x4e40b0
0x4e40b4
0x4e40b8
0x4e40bc
0x4e40c0
0x4e40c4
0x4e40c8
0x4e40cc
0x4e40d0
0x4e40d4
0x4e40d8
0x4e40dc
0x4e40e0
0x4e40e4
0x4e40e8
0x4e40ec
0x4e40f0
0x4e40f4
0x4e40f8
0x4e40fc
0x4e4100
0x4e4104
0x4e4108
0x4e410c
0x4e4110
0x4e4114
0x4e4118
0x4e411c
0x4e4120
0x4e4124
0x4e4128
0x4e412c
0x4e4130
0x4e4134
0x4e4138
0x4e413c
0x4e4140
0x4e4144
0x4e4148
0x4e414c
0x4e4150
0x4e4154
0x4e4158
0x4e415c
0x4e4160
0x4e4164
0x4e4168
0x4e416c
0x4e4170
0x4e4174
0x4e4178
0x4e417c
0x4e4180
0x4e4184
0x4e4188
0x4e418c
0x4e4190
0x4e4194
0x4e4198
0x4e419c
0x4e41a0
0x4e41a4
0x4e41a8
0x4e41ac
0x4e41b0
0x4e41b4
0x4e41b8
0x4e41bc
0x4e41c0
0x4e41c4
0x4e41c8
0x4e41cc
0x4e41d0
0x4e41d4
0x4e41d8
0x4e41dc
0x4e41e0
0x4e41e4
0x4e41e8
0x4e41ec
0x4e41f0
0x4e41f4
0x4e41f8
0x4e41fc
0x4e4200
0x4e4204
0x4e4208
0x4e420c
0x4e4210
0x4e4214
0x4e4218
0x4e421c
0x4e4220
0x4e4224
0x4e4228
0x4e422c
0x4e4230
0x4e4234
0x4e4238
0x4e423c
0x4e4240
0x4e4244
0x4e4248
0x4e424c
0x4e4250
0x4e4254
0x4e4258
0x4e425c
0x4e4260
0x4e4264
0x4e4268
0x4e426c
0x4e4270
0x4e4274
0x4e4278
0x4e427c
0x4e4280
0x4e4284
0x4e4288
0x4e428c
0x4e4290
0x4e4294
0x4e4298
0x4e429c
0x4e42a0
0x4e42a4
0x4e42a8
0x4e42ac
0x4e42b0
0x4e42b4
0x4e42b8
0x4e42bc
0x4e42c0
0x4e42c4
0x4e42c8
0x4e42cc
0x4e42d0
0x4e42d4
0x4e42d8
0x4e42dc
0x4e42e0
0x4e42e4
0x4e42e8
0x4e42ec
0x4e42f0
0x4e42f4
0x4e42f8
0x4e42fc
0x4e4300
0x4e4304
0x4e4308
0x4e430c
0x4e4310
0x4e4314
0x4e4318
0x4e431c
0x4e4320
0x4e4324
0x4e4328
0x4e432c
0x4e4330
0x4e4334
0x4e4338
0x4e433c
0x4e4340
0x4e4344
0x4e4348
0x4e434c
0x4e4350
0x4e4354
0x4e4358
0x4e435c
0x4e4360
0x4e4364
0x4e4368
Library KERNEL32.dll:
0x4e34b8 ReleaseMutex
0x4e34bc GetLastError
0x4e34c0 CreateMutexW
0x4e34c4 GetTickCount
0x4e34c8 GetTempPathW
0x4e34cc FindResourceW
0x4e34d0 GetModuleFileNameW
0x4e34d4 lstrcpyW
0x4e34d8 MulDiv
0x4e34dc CloseHandle
0x4e34e0 GetStartupInfoW
0x4e34e4 IsDebuggerPresent
0x4e34e8 InitializeSListHead
0x4e34f0 GetCurrentProcessId
0x4e34fc TerminateProcess
0x4e3508 CreateEventW
0x4e3510 ResetEvent
0x4e3514 SetEvent
0x4e3518 MultiByteToWideChar
0x4e351c WideCharToMultiByte
0x4e3520 LocalFree
0x4e3524 VerifyVersionInfoW
0x4e3528 VerSetConditionMask
0x4e352c GetModuleHandleW
0x4e3534 GetDriveTypeW
0x4e3538 GetProcAddress
0x4e353c GetCurrentProcess
0x4e3544 OutputDebugStringW
0x4e3548 GetDiskFreeSpaceExW
0x4e354c CreateFileW
0x4e3550 CreateDirectoryW
0x4e3554 ReadFile
0x4e3558 WriteFile
0x4e355c SetFilePointer
0x4e3560 GetFileSizeEx
0x4e3564 SetEndOfFile
0x4e3568 CopyFileW
0x4e356c DeleteFileW
0x4e3570 GetSystemTime
0x4e3578 SetFileTime
0x4e357c RemoveDirectoryW
0x4e3580 GetFileAttributesW
0x4e3584 FindFirstFileW
0x4e3588 FindNextFileW
0x4e358c FindClose
0x4e3594 WaitForSingleObject
0x4e35a4 Sleep
0x4e35a8 GlobalSize
0x4e35ac GlobalUnlock
0x4e35b0 GlobalLock
0x4e35b4 GlobalAlloc
0x4e35b8 GetCurrentThreadId
0x4e35bc GetFileTime
Library USER32.dll:
0x4e3978 ModifyMenuW
0x4e397c LoadIconW
0x4e3980 InvalidateRect
0x4e3984 RedrawWindow
0x4e3988 GetSubMenu
0x4e398c PostMessageW
0x4e3990 SetRectEmpty
0x4e3994 EnableWindow
0x4e3998 ReleaseDC
0x4e399c GetDC
0x4e39a0 GetClipboardData
0x4e39a4 CloseClipboard
0x4e39a8 SetClipboardData
0x4e39ac EmptyClipboard
0x4e39b0 OpenClipboard
0x4e39b4 PeekMessageW
0x4e39b8 UpdateWindow
0x4e39c0 PostQuitMessage
0x4e39c4 SendMessageW
0x4e39c8 SetFocus
0x4e39cc GetFocus
0x4e39d0 GetMenu
0x4e39d4 GetParent
0x4e39d8 UnhookWindowsHookEx
0x4e39dc GetClientRect
0x4e39e0 TrackPopupMenu
0x4e39e4 SetForegroundWindow
0x4e39ec GetWindowRgn
0x4e39f0 DestroyIcon
0x4e39f4 IntersectRect
0x4e39f8 GetWindow
0x4e39fc GetDesktopWindow
0x4e3a00 GetClassInfoW
0x4e3a04 GetWindowDC
0x4e3a08 SetCaretPos
0x4e3a0c IsRectEmpty
0x4e3a10 CallWindowProcW
0x4e3a14 CloseWindow
0x4e3a18 RegisterHotKey
0x4e3a1c UnregisterHotKey
0x4e3a20 GetSystemMetrics
0x4e3a28 FindWindowExW
0x4e3a2c LoadAcceleratorsW
0x4e3a30 GetKeyState
0x4e3a34 InflateRect
0x4e3a38 ClientToScreen
0x4e3a3c SetWindowPos
0x4e3a40 SetWindowLongW
0x4e3a44 GetWindowLongW
0x4e3a48 IsZoomed
0x4e3a4c IsIconic
0x4e3a50 DeleteMenu
0x4e3a54 LockWindowUpdate
0x4e3a58 IsWindowVisible
0x4e3a5c KillTimer
0x4e3a60 SetTimer
0x4e3a64 GetWindowRect
0x4e3a68 SetCursor
0x4e3a6c CopyRect
0x4e3a70 FrameRect
0x4e3a74 FillRect
0x4e3a78 GetMenuState
0x4e3a7c LoadMenuW
0x4e3a80 PtInRect
0x4e3a84 ScreenToClient
0x4e3a88 GetCursorPos
0x4e3a8c OffsetRect
0x4e3a90 SetRect
0x4e3a94 CreateIconIndirect
0x4e3a98 LoadCursorW
0x4e3a9c LoadBitmapW
0x4e3aa4 BringWindowToTop
0x4e3aa8 IsWindow
Library GDI32.dll:
0x4e3414 Rectangle
0x4e3418 SetPixel
0x4e3420 GetObjectW
0x4e3424 DeleteDC
0x4e3428 DeleteObject
0x4e342c GetDIBits
0x4e3430 PlayEnhMetaFile
0x4e3434 ExtTextOutW
0x4e3438 SetBkColor
0x4e343c SelectObject
0x4e3440 GetDeviceCaps
0x4e3444 CreateCompatibleDC
0x4e3450 CreatePalette
0x4e3454 CreateSolidBrush
0x4e3458 CreateFontIndirectW
0x4e3460 BitBlt
0x4e3464 RoundRect
0x4e3468 SetPixelV
0x4e346c StretchBlt
0x4e3470 CreatePen
0x4e3474 SetBkMode
0x4e3478 MoveToEx
0x4e347c LineTo
0x4e3480 Ellipse
0x4e3484 GetTextMetricsW
0x4e3488 GetCurrentObject
0x4e348c CreateRectRgn
0x4e3490 OffsetRgn
0x4e3494 GetStockObject
0x4e3498 GetPixel
Library ADVAPI32.dll:
0x4e1000 RegQueryValueExW
0x4e1004 RegDeleteValueW
0x4e1008 RegSetValueExW
0x4e100c RegCloseKey
0x4e1010 RegCreateKeyExW
0x4e1014 RegOpenKeyExW
Library SHELL32.dll:
0x4e3958 ShellExecuteExW
0x4e395c ShellExecuteW
0x4e3960 DragFinish
0x4e3968 DragQueryFileW
0x4e396c DragAcceptFiles
0x4e3970 Shell_NotifyIconW
Library COMCTL32.dll:
0x4e264c ImageList_Remove
0x4e2654 ImageList_Replace
0x4e2658 _TrackMouseEvent
0x4e265c ImageList_AddMasked
Library ole32.dll:
0x4e4370 CoTaskMemFree
0x4e4374 CoCreateInstance
Library OLEAUT32.dll:
0x4e36a0 SysFreeString
0x4e36a8 SysStringLen
0x4e36ac SysAllocString
0x4e36b0 VariantClear
Library gdiplus.dll:
0x4e3ca8 GdipCreatePen1
0x4e3cac GdipAddPathLineI
0x4e3cb0 GdipFillRectangleI
0x4e3cb8 GdipCloneBrush
0x4e3cbc GdipDeleteBrush
0x4e3cc0 GdipAddPathEllipse
0x4e3cc8 GdipDeleteGraphics
0x4e3ccc GdipDeletePath
0x4e3cd0 GdipCreateFromHDC
0x4e3cd4 GdipDrawPath
0x4e3cd8 GdipFillPath
0x4e3ce0 GdipAlloc
0x4e3ce4 GdipFree
0x4e3ce8 GdipCreateSolidFill
0x4e3cf0 GdipDeletePen
0x4e3cf8 GdipCreateFont
0x4e3cfc GdipDeleteFont
0x4e3d14 GdipDrawString
0x4e3d18 GdipDrawImageRect
0x4e3d1c GdipAddPathLine2I
0x4e3d20 GdipFillRectangle
0x4e3d24 GdipDrawRectangleI
0x4e3d28 GdipDrawEllipseI
0x4e3d38 GdipDrawLineI
0x4e3d3c GdipSetPenStartCap
0x4e3d40 GdipSetPenEndCap
0x4e3d44 GdipSetPenDashStyle
0x4e3d48 GdipCreatePath
Library BCGCBPRO2500u140.dll:
Library MSVCP140.dll:
0x4e3638 _Xtime_get_ticks
0x4e363c _Mtx_current_owns
0x4e3640 _Cnd_timedwait
0x4e3644 _Thrd_detach
0x4e364c _Cnd_init_in_situ
0x4e3650 _Cnd_init
0x4e3654 _Mtx_init
0x4e365c _Cnd_signal
0x4e3660 _Cnd_destroy
0x4e3664 _Mtx_destroy
0x4e3668 _Thrd_start
0x4e3670 _Cnd_wait
0x4e3674 _Thrd_id
0x4e3678 _Thrd_join
0x4e3688 _Mtx_unlock
0x4e3690 _Mtx_lock
0x4e3694 _Mtx_init_in_situ
Library FFImage.dll:
0x4e28f4 ??1CxImage@@UAE@XZ
0x4e28f8 ??0CxImage@@QAE@I@Z
0x4e2908 ??1CFFPen@@UAE@XZ
0x4e2948 ??1CxIOFile@@UAE@XZ
0x4e29b8 ??0CFFImage@@QAE@XZ
0x4e29bc ??1CFFImage@@UAE@XZ
Library IMM32.dll:
0x4e34a0 ImmGetContext
0x4e34a8 ImmReleaseContext
Library WS2_32.dll:
0x4e3af4 recv
0x4e3af8 connect
0x4e3afc __WSAFDIsSet
0x4e3b00 WSACleanup
0x4e3b04 select
0x4e3b08 send
0x4e3b0c socket
0x4e3b10 inet_addr
0x4e3b14 htons
0x4e3b18 inet_ntoa
0x4e3b1c WSAGetLastError
0x4e3b20 ioctlsocket
0x4e3b24 gethostbyname
0x4e3b28 closesocket
0x4e3b2c WSAStartup

Hosts

No hosts contacted.

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 50534 114.114.114.114 53
192.168.56.101 51963 114.114.114.114 53
192.168.56.101 56539 114.114.114.114 53
192.168.56.101 58367 114.114.114.114 53
192.168.56.101 65004 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 123 20.189.79.72 time.windows.com 123
192.168.56.101 49235 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 60123 224.0.0.252 5355
192.168.56.101 62191 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900
192.168.56.101 56540 239.255.255.250 3702
192.168.56.101 56807 239.255.255.250 1900
192.168.56.101 58368 239.255.255.250 3702
192.168.56.101 58370 239.255.255.250 3702
192.168.56.101 58707 239.255.255.250 3702

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.