| description | 0de5c83d56cc3003bdf935546f1955dbdf3ecf15654be7db5494043eb8228857.exe 试图睡眠 257.715 秒,实际延迟分析时间 257.715 秒 | |||
| file | C:\Users\Administrator\AppData\Local\Temp\tmp2D24.tmp |
| file | C:\Users\Administrator\AppData\Local\Temp\tmp3BA5.tmp |
| file | C:\Users\Administrator\AppData\Local\Temp\tmpDD1C.tmp |
| section | {'name': 'UPX1', 'virtual_address': '0x00007000', 'virtual_size': '0x00005000', 'size_of_data': '0x00004600', 'entropy': 7.897902341253568} | entropy | 7.897902341253568 | description | 发现高熵的节 | |||||||||
| entropy | 0.8974358974358975 | description | 此PE文件的整体熵值较高 | |||||||||||
| section | UPX0 | description | 节名称指示UPX | ||||||
| section | UPX1 | description | 节名称指示UPX | ||||||
| host | 166.77.247.144 | |||
| host | 114.114.114.114 | |||
| host | 162.40.225.206 | |||
| host | 16.115.202.50 | |||
| host | 8.8.8.8 | |||
| host | 15.255.131.30 | |||
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Traybar | reg_value | C:\Windows\lsass.exe | ||||||
| registry | HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts |
| dead_host | 166.77.247.144:1042 |
| dead_host | 162.40.225.206:1042 |
| dead_host | 10.130.29.165:1042 |
| dead_host | 16.115.202.50:1042 |
| dead_host | 15.255.131.30:1042 |
| Name | Virtual Address | Virtual Size | Size of Raw Data | Entropy |
|---|---|---|---|---|
| UPX0 | 0x00001000 | 0x00006000 | 0x00000000 | 0.0 |
| UPX1 | 0x00007000 | 0x00005000 | 0x00004600 | 7.897902341253568 |
| .rsrc | 0x0000c000 | 0x00001000 | 0x00000800 | 2.6495694551935207 |
| Name | Offset | Size | Language | Sub-language | File type |
|---|---|---|---|---|---|
| RT_ICON | 0x0000c3c4 | 0x00000128 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x0000c3c4 | 0x00000128 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_GROUP_ICON | 0x0000c4f0 | 0x00000022 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| IP |
|---|
| 166.77.247.144 |
| 114.114.114.114 |
| 162.40.225.206 |
| 16.115.202.50 |
| 8.8.8.8 |
| 15.255.131.30 |
| 50.223.129.194 |
| 108.62.122.56 |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| dns.msftncsi.com | A 131.107.255.255 | 131.107.255.255 |
| dns.msftncsi.com | AAAA fd3e:4f5a:5b81::1 | 131.107.255.255 |
| mozilla.org.xpi | ||
| mx.mozilla.org.xpi | ||
| mail.mozilla.org.xpi | ||
| smtp.mozilla.org.xpi | ||
| bounce2.pobox.com |
MX pb-bounce4.pobox.com MX pb-bounce5.pobox.com MX pb-bounce4.pobox.com MX pb-bounce5.pobox.com |
64.147.108.75 |
| ietf.org | MX mail.ietf.org | 104.16.45.99 |
| shore.net |
MX mailfilter02.leaseweb.us MX mailfilter01.leaseweb.us |
85.17.96.111 |
| dom.ain | ||
| cmu.edu |
MX alt3.aspmx.l.google.com MX alt4.aspmx.l.google.com MX alt2.aspmx.l.google.com MX alt1.aspmx.l.google.com MX aspmx.l.google.com |
128.2.42.10 |
| freebsd.org |
MX mx66.freebsd.org MX mx1.freebsd.org MX mx66.freebsd.org MX mx1.freebsd.org |
96.47.72.84 |
| dd.org | MX mxg.dd.org | 69.54.28.11 |
| python-pillow.org |
MX alt1.aspmx.l.google.com MX aspmx2.googlemail.com MX aspmx4.googlemail.com MX aspmx5.googlemail.com MX alt2.aspmx.l.google.com MX aspmx3.googlemail.com |
185.199.111.153 |
| acm.org | MX mail.mailroute.net | 104.17.79.30 |
| mail.ietf.org | A 50.223.129.194 | 50.223.129.194 |
| mailfilter02.leaseweb.us | A 108.62.122.56 | 108.62.122.56 |
No TCP connections recorded.
| Source | Source Port | Destination | Destination Port |
|---|---|---|---|
| 192.168.56.101 | 53179 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 49642 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 137 | 192.168.56.255 | 137 |
| 192.168.56.101 | 61714 | 114.114.114.114 | 53 |
| 192.168.56.101 | 56933 | 114.114.114.114 | 53 |
| 192.168.56.101 | 138 | 192.168.56.255 | 138 |
| 192.168.56.101 | 58485 | 114.114.114.114 | 53 |
| 192.168.56.101 | 57665 | 114.114.114.114 | 53 |
| 192.168.56.101 | 51758 | 114.114.114.114 | 53 |
| 192.168.56.101 | 52215 | 114.114.114.114 | 53 |
| 192.168.56.101 | 62361 | 114.114.114.114 | 53 |
| 192.168.56.101 | 62362 | 114.114.114.114 | 53 |
| 192.168.56.101 | 62363 | 114.114.114.114 | 53 |
| 192.168.56.101 | 62364 | 8.8.8.8 | 53 |
| 192.168.56.101 | 62365 | 114.114.114.114 | 53 |
| 192.168.56.101 | 62366 | 8.8.8.8 | 53 |
| 192.168.56.101 | 62367 | 8.8.8.8 | 53 |
| 192.168.56.101 | 62368 | 114.114.114.114 | 53 |
| 192.168.56.101 | 62369 | 8.8.8.8 | 53 |
| 192.168.56.101 | 62370 | 114.114.114.114 | 53 |
| 192.168.56.101 | 62371 | 8.8.8.8 | 53 |
| 192.168.56.101 | 58985 | 114.114.114.114 | 53 |
| 192.168.56.101 | 58985 | 8.8.8.8 | 53 |
| 192.168.56.101 | 50075 | 8.8.8.8 | 53 |
| 192.168.56.101 | 50075 | 114.114.114.114 | 53 |
| 192.168.56.101 | 58624 | 114.114.114.114 | 53 |
| 192.168.56.101 | 58624 | 8.8.8.8 | 53 |
| 192.168.56.101 | 62044 | 114.114.114.114 | 53 |
| 192.168.56.101 | 62515 | 114.114.114.114 | 53 |
| 192.168.56.101 | 60330 | 114.114.114.114 | 53 |
| 192.168.56.101 | 61322 | 114.114.114.114 | 53 |
| 192.168.56.101 | 62306 | 114.114.114.114 | 53 |
| 192.168.56.101 | 55142 | 114.114.114.114 | 53 |
| 192.168.56.101 | 55143 | 114.114.114.114 | 53 |
| 192.168.56.101 | 56111 | 114.114.114.114 | 53 |
| 192.168.56.101 | 56112 | 8.8.8.8 | 53 |
| 192.168.56.101 | 56113 | 114.114.114.114 | 53 |
| 192.168.56.101 | 56114 | 8.8.8.8 | 53 |
| 192.168.56.101 | 58005 | 114.114.114.114 | 53 |
| 192.168.56.101 | 62044 | 8.8.8.8 | 53 |
| 192.168.56.101 | 58005 | 8.8.8.8 | 53 |
| 192.168.56.101 | 64558 | 8.8.8.8 | 53 |
| 192.168.56.101 | 64559 | 8.8.8.8 | 53 |
| 192.168.56.101 | 64560 | 8.8.8.8 | 53 |
| 192.168.56.101 | 49986 | 8.8.8.8 | 53 |
| 192.168.56.101 | 65527 | 8.8.8.8 | 53 |
| 192.168.56.101 | 62324 | 8.8.8.8 | 53 |
No HTTP requests performed.
| Source | Destination | ICMP Type | Data |
|---|---|---|---|
| 192.168.56.101 | 114.114.114.114 | 3 |
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts
| Name | e3b0c44298fc1c14_lsass.exe |
|---|---|
| Size | 0.0B |
| Type | empty |
| MD5 | d41d8cd98f00b204e9800998ecf8427e |
| SHA1 | da39a3ee5e6b4b0d3255bfef95601890afd80709 |
| SHA256 | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 |
| CRC32 | 00000000 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | b4af72159e212424_gpban1l3.txt |
|---|---|
| Filepath | C:\Users\Administrator\AppData\Local\Temp\gpban1l3.txt |
| Size | 38.9KB |
| Processes | 2948 (0de5c83d56cc3003bdf935546f1955dbdf3ecf15654be7db5494043eb8228857.exe) |
| Type | data |
| MD5 | f544c9b9569fcfbaece2274b59419113 |
| SHA1 | e7f71d7c4fc65ce2dd3163f996d93bad34900b31 |
| SHA256 | b4af72159e2124243720c2948af8065cb2ba28f43dbe2f42d22d0bd6ca4d4cde |
| CRC32 | 052F3D70 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 7e3d15207e96edce_tmp5048.tmp |
|---|---|
| Filepath | C:\Users\Administrator\AppData\Local\Temp\tmp5048.tmp |
| Size | 59.7KB |
| Processes | 2948 (0de5c83d56cc3003bdf935546f1955dbdf3ecf15654be7db5494043eb8228857.exe) |
| Type | Zip archive data, at least v1.0 to extract, compression method=store |
| MD5 | d6cb7de967dbba92df17d1847eff46aa |
| SHA1 | 38c3ba12d59604d17c0395d600e60e74da675caa |
| SHA256 | 7e3d15207e96edce7af6836843ba3d24e7d929daab34b0118ffb9d2260360da9 |
| CRC32 | 2CF7BE01 |
| ssdeep | None |
| Yara |
|
| VirusTotal | Search for analysis |
| Name | f198230b55708a68_tmp2DB2.tmp |
|---|---|
| Filepath | C:\Users\Administrator\AppData\Local\Temp\tmp2DB2.tmp |
| Size | 59.8KB |
| Processes | 2948 (0de5c83d56cc3003bdf935546f1955dbdf3ecf15654be7db5494043eb8228857.exe) |
| Type | Zip archive data, at least v1.0 to extract, compression method=store |
| MD5 | c88c6ebb8764fd90a05fe6953a5a26f2 |
| SHA1 | b0dc1b4df1429fc7b93952e26e9e2d430092cc22 |
| SHA256 | f198230b55708a680c6dc669007c4f15036c2d1f66ca931121b5a83e8b2cc858 |
| CRC32 | F81B285C |
| ssdeep | None |
| Yara |
|
| VirusTotal | Search for analysis |
| Name | 8ac9139ec5f7bc2d_tmp2D24.tmp |
|---|---|
| Filepath | C:\Users\Administrator\AppData\Local\Temp\tmp2D24.tmp |
| Size | 59.4KB |
| Processes | 2948 (0de5c83d56cc3003bdf935546f1955dbdf3ecf15654be7db5494043eb8228857.exe) |
| Type | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5 | 3972abaa6da1407320d51d07754ae0bf |
| SHA1 | ea77c1a6c7a595cbe5be952a908b5c650bcf75b3 |
| SHA256 | 8ac9139ec5f7bc2d260fce87e8be68c653ccde5dd43c52db83e4606d4f3323be |
| CRC32 | 6CA96960 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 1b6be2c35bf4ba51_tmp3ba5.tmp |
|---|---|
| Filepath | C:\Users\Administrator\AppData\Local\Temp\tmp3BA5.tmp |
| Size | 59.4KB |
| Processes | 2948 (0de5c83d56cc3003bdf935546f1955dbdf3ecf15654be7db5494043eb8228857.exe) |
| Type | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5 | de402092a72ecd1bc23147dcb38d556b |
| SHA1 | e7bdb4ecf77e6309af499e420024325b5ca6b39c |
| SHA256 | 1b6be2c35bf4ba51800535b03d16999fc812b0f810f85df6c817fe62dd3143ff |
| CRC32 | D30CADDB |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | bd30b62ae8682c6a_tmpDD1C.tmp |
|---|---|
| Filepath | C:\Users\Administrator\AppData\Local\Temp\tmpDD1C.tmp |
| Size | 59.4KB |
| Processes | 2948 (0de5c83d56cc3003bdf935546f1955dbdf3ecf15654be7db5494043eb8228857.exe) |
| Type | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5 | 4ff545628650659046e59eddfeb0aca8 |
| SHA1 | 5d3ed25226276b9711a359d8f4e683b23ac05ef2 |
| SHA256 | bd30b62ae8682c6a5738c137ff4914bf0a68ea8743867eb9ed520fd25e5d0ec2 |
| CRC32 | 9A8EC237 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |