section | \x00 |
section | .idata |
section | |
section | ipsvfnxo |
section | bwxzvnjx |
resource name | CSGD |
name | RT_MENU | language | LANG_CHINESE | offset | 0x0020c5d0 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000036 | ||||||||||||||||||
name | RT_MENU | language | LANG_CHINESE | offset | 0x0020c5d0 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000036 | ||||||||||||||||||
name | RT_MENU | language | LANG_CHINESE | offset | 0x0020c5d0 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000036 | ||||||||||||||||||
name | RT_MENU | language | LANG_CHINESE | offset | 0x0020c5d0 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000036 | ||||||||||||||||||
name | RT_MENU | language | LANG_CHINESE | offset | 0x0020c5d0 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000036 | ||||||||||||||||||
name | RT_MENU | language | LANG_CHINESE | offset | 0x0020c5d0 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000036 | ||||||||||||||||||
name | RT_MENU | language | LANG_CHINESE | offset | 0x0020c5d0 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000036 | ||||||||||||||||||
name | RT_MENU | language | LANG_CHINESE | offset | 0x0020c5d0 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000036 | ||||||||||||||||||
name | RT_MENU | language | LANG_CHINESE | offset | 0x0020c5d0 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000036 |
entropy | 7.98030225818421 | section | {'size_of_data': '0x000f6000', 'virtual_address': '0x00001000', 'entropy': 7.98030225818421, 'name': ' \\x00 ', 'virtual_size': '0x00209000'} | description | A section with a high entropy has been found | |||||||||
entropy | 7.907160799888821 | section | {'size_of_data': '0x000fd000', 'virtual_address': '0x00396000', 'entropy': 7.907160799888821, 'name': 'ipsvfnxo', 'virtual_size': '0x000fd000'} | description | A section with a high entropy has been found | |||||||||
entropy | 0.9822834645669292 | description | Overall entropy of this PE file is high |
host | 172.217.24.14 |
dead_host | 192.168.56.101:49194 |
dead_host | 74.86.17.48:443 |
dead_host | 172.217.24.14:443 |
dead_host | 103.42.176.244:443 |
dead_host | 192.168.56.101:49208 |
dead_host | 154.83.15.45:443 |
dead_host | 192.168.56.101:49186 |
dead_host | 192.168.56.101:49183 |
Ordinal | Address | Name |
---|---|---|
1 | 0x40df60 | _EXECryptor_GetHardwareID@0 |
2 | 0x40df40 | _EXECryptor_IsAppProtected@0 |
No hosts contacted.
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 49183 | 172.217.161.174 clients2.google.com | 443 |
192.168.56.101 | 49186 | 172.217.161.174 clients2.google.com | 443 |
192.168.56.101 | 49194 | 172.217.161.174 clients2.google.com | 443 |
192.168.56.101 | 49199 | 172.217.161.174 clients2.google.com | 443 |
192.168.56.101 | 49208 | 172.217.161.174 clients2.google.com | 443 |
192.168.56.101 | 49218 | 172.217.161.174 clients2.google.com | 443 |
192.168.56.101 | 49184 | 31.13.83.4 s3-ap-southeast-1.amazonaws.com | 443 |
192.168.56.101 | 49190 | 31.13.83.4 s3-ap-southeast-1.amazonaws.com | 443 |
192.168.56.101 | 49189 | 52.217.64.222 s3.amazonaws.com | 443 |
192.168.56.101 | 49213 | 52.217.64.222 s3.amazonaws.com | 443 |
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 62913 | 103.43.164.244 | 53 |
192.168.56.101 | 60222 | 110.167.212.58 | 53 |
192.168.56.101 | 60222 | 112.14.182.120 | 53 |
192.168.56.101 | 62913 | 112.8.141.133 | 53 |
192.168.56.101 | 51378 | 114.114.114.114 | 53 |
192.168.56.101 | 51963 | 114.114.114.114 | 53 |
192.168.56.101 | 57756 | 114.114.114.114 | 53 |
192.168.56.101 | 60123 | 114.114.114.114 | 53 |
192.168.56.101 | 60215 | 114.114.114.114 | 53 |
192.168.56.101 | 63429 | 114.114.114.114 | 53 |
192.168.56.101 | 65004 | 114.114.114.114 | 53 |
192.168.56.101 | 62913 | 123.129.212.212 | 53 |
192.168.56.101 | 62913 | 124.128.162.102 | 53 |
192.168.56.101 | 60222 | 175.43.126.202 | 53 |
192.168.56.101 | 60222 | 183.234.8.90 | 53 |
192.168.56.101 | 137 | 192.168.56.255 | 137 |
192.168.56.101 | 138 | 192.168.56.255 | 138 |
192.168.56.101 | 123 | 20.189.79.72 time.windows.com | 123 |
192.168.56.101 | 62913 | 202.120.47.22 | 53 |
192.168.56.101 | 62913 | 222.36.125.223 | 53 |
No HTTP requests performed.
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts