3.8
中危

7683af3c5c611eb0443b9c71eebf6dafbd7c9fd097e36dd5035f10ec4fcf89ec

7619d5b91fcc14a6f17a3b8d7d419051.exe

分析耗时

85s

最近分析

文件大小

255.2KB
静态报毒 动态报毒 INSTALLCORE
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
McAfee 20190811 6.0.6.653
Alibaba 20190527 0.3.0.5
Baidu 20190318 1.0.0.2
Tencent 20190812 1.0.0.1
Kingsoft 20190812 2013.8.14.323
CrowdStrike 20190212 1.0
行为判定
动态指标
Foreign language identified in PE resource (17 个事件)
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x000cbc48 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x000cbc48 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x000cbc48 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x000cbc48 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name PNG language LANG_CHINESE offset 0x000cb188 filetype PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000003c8
name PNG language LANG_CHINESE offset 0x000cb188 filetype PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000003c8
name PNG language LANG_CHINESE offset 0x000cb188 filetype PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000003c8
name PNG language LANG_CHINESE offset 0x000cb188 filetype PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000003c8
name PNG language LANG_CHINESE offset 0x000cb188 filetype PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000003c8
name PNG language LANG_CHINESE offset 0x000cb188 filetype PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000003c8
name PNG language LANG_CHINESE offset 0x000cb188 filetype PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000003c8
name PNG language LANG_CHINESE offset 0x000cb188 filetype PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000003c8
name RT_DIALOG language LANG_CHINESE offset 0x000cba10 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000104
name RT_DIALOG language LANG_CHINESE offset 0x000cba10 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000104
name RT_DIALOG language LANG_CHINESE offset 0x000cba10 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000104
name RT_DIALOG language LANG_CHINESE offset 0x000cba10 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000104
name RT_DIALOG language LANG_CHINESE offset 0x000cba10 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000104
File has been identified by one AntiVirus engine on VirusTotal as malicious (1 个事件)
Microsoft PUA:Win32/InstallCore
The binary likely contains encrypted or compressed data indicative of a packer (2 个事件)
entropy 7.217586196813697 section {'size_of_data': '0x00016800', 'virtual_address': '0x000c0000', 'entropy': 7.217586196813697, 'name': '.rsrc', 'virtual_size': '0x000167f0'} description A section with a high entropy has been found
entropy 0.36363636363636365 description Overall entropy of this PE file is high
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2019-04-26 20:19:34

Imports

Library WINMM.dll:
0x140018b18 timeGetTime
Library DSOUND.dll:
0x140018470
0x140018478
Library mfc140u.dll:
0x140018d88
0x140018d90
0x140018d98
0x140018da0
0x140018da8
0x140018db0
0x140018db8
0x140018dc0
0x140018dc8
0x140018dd0
0x140018dd8
0x140018de0
0x140018de8
0x140018df0
0x140018df8
0x140018e00
0x140018e08
0x140018e10
0x140018e18
0x140018e20
0x140018e28
0x140018e30
0x140018e38
0x140018e40
0x140018e48
0x140018e50
0x140018e58
0x140018e60
0x140018e68
0x140018e70
0x140018e78
0x140018e80
0x140018e88
0x140018e90
0x140018e98
0x140018ea0
0x140018ea8
0x140018eb0
0x140018eb8
0x140018ec0
0x140018ec8
0x140018ed0
0x140018ed8
0x140018ee0
0x140018ee8
0x140018ef0
0x140018ef8
0x140018f00
0x140018f08
0x140018f10
0x140018f18
0x140018f20
0x140018f28
0x140018f30
0x140018f38
0x140018f40
0x140018f48
0x140018f50
0x140018f58
0x140018f60
0x140018f68
0x140018f70
0x140018f78
0x140018f80
0x140018f88
0x140018f90
0x140018f98
0x140018fa0
0x140018fa8
0x140018fb0
0x140018fb8
0x140018fc0
0x140018fc8
0x140018fd0
0x140018fd8
0x140018fe0
0x140018fe8
0x140018ff0
0x140018ff8
0x140019000
0x140019008
0x140019010
0x140019018
0x140019020
0x140019028
0x140019030
0x140019038
0x140019040
0x140019048
0x140019050
0x140019058
0x140019060
0x140019068
0x140019070
0x140019078
0x140019080
0x140019088
0x140019090
0x140019098
0x1400190a0
0x1400190a8
0x1400190b0
0x1400190b8
0x1400190c0
0x1400190c8
0x1400190d0
0x1400190d8
0x1400190e0
0x1400190e8
0x1400190f0
0x1400190f8
0x140019100
0x140019108
0x140019110
0x140019118
0x140019120
0x140019128
0x140019130
0x140019138
0x140019140
0x140019148
0x140019150
0x140019158
0x140019160
0x140019168
0x140019170
0x140019178
0x140019180
0x140019188
0x140019190
0x140019198
0x1400191a0
0x1400191a8
0x1400191b0
0x1400191b8
0x1400191c0
0x1400191c8
0x1400191d0
0x1400191d8
0x1400191e0
0x1400191e8
0x1400191f0
0x1400191f8
0x140019200
0x140019208
0x140019210
0x140019218
0x140019220
0x140019228
0x140019230
0x140019238
0x140019240
0x140019248
0x140019250
0x140019258
0x140019260
0x140019268
0x140019270
0x140019278
0x140019280
0x140019288
0x140019290
0x140019298
0x1400192a0
0x1400192a8
0x1400192b0
0x1400192b8
0x1400192c0
0x1400192c8
0x1400192d0
0x1400192d8
0x1400192e0
0x1400192e8
0x1400192f0
0x1400192f8
0x140019300
0x140019308
0x140019310
0x140019318
0x140019320
0x140019328
0x140019330
0x140019338
0x140019340
0x140019348
0x140019350
0x140019358
0x140019360
0x140019368
0x140019370
0x140019378
0x140019380
0x140019388
0x140019390
0x140019398
0x1400193a0
0x1400193a8
0x1400193b0
0x1400193b8
0x1400193c0
0x1400193c8
0x1400193d0
0x1400193d8
0x1400193e0
0x1400193e8
0x1400193f0
0x1400193f8
0x140019400
0x140019408
0x140019410
0x140019418
0x140019420
0x140019428
0x140019430
0x140019438
0x140019440
0x140019448
0x140019450
0x140019458
Library KERNEL32.dll:
0x140018700 GetDriveTypeW
0x140018708 GetDiskFreeSpaceExW
0x140018710 VerifyVersionInfoW
0x140018718 GetFileSizeEx
0x140018720 ReadFile
0x140018728 FlushFileBuffers
0x140018730 FindClose
0x140018738 GetFileTime
0x140018740 SetFileTime
0x140018748 GetSystemTime
0x140018750 SystemTimeToFileTime
0x140018758 CreateDirectoryW
0x140018760 CreateProcessW
0x140018768 GetModuleFileNameW
0x140018770 FormatMessageW
0x140018778 GetLogicalDrives
0x140018780 WaitForSingleObject
0x140018788 GetCurrentProcess
0x140018790 LocalFree
0x140018798 VerSetConditionMask
0x1400187a0 GlobalFree
0x1400187a8 lstrlenW
0x1400187b0 CreateEventW
0x1400187b8 SetThreadPriority
0x1400187c0 Sleep
0x1400187c8 GlobalLock
0x1400187d0 GlobalAlloc
0x1400187d8 OutputDebugStringW
0x1400187e0 GetSystemTimeAsFileTime
0x1400187e8 GetLocalTime
0x1400187f0 TerminateProcess
0x140018800 GetStartupInfoW
0x140018810 UnhandledExceptionFilter
0x140018818 IsDebuggerPresent
0x140018820 RtlVirtualUnwind
0x140018828 RtlLookupFunctionEntry
0x140018830 RtlCaptureContext
0x140018838 InitializeSListHead
0x140018840 GlobalHandle
0x140018848 GetCurrentProcessId
0x140018850 QueryPerformanceCounter
0x140018858 GetModuleHandleW
0x140018860 WaitForSingleObjectEx
0x140018868 ResetEvent
0x140018870 SetEvent
0x140018878 WideCharToMultiByte
0x140018880 MultiByteToWideChar
0x140018888 MoveFileW
0x140018890 CopyFileW
0x140018898 FindNextFileW
0x1400188a0 FindFirstFileW
0x1400188a8 DeleteFileW
0x1400188b0 GetFileAttributesW
0x1400188b8 SetFileAttributesW
0x1400188c0 GetCurrentThreadId
0x1400188c8 SetFilePointer
0x1400188d0 GetLastError
0x1400188d8 SetEndOfFile
0x1400188e0 CloseHandle
0x1400188e8 MulDiv
0x1400188f0 CreateFileW
0x1400188f8 GetFileSize
0x140018900 WriteFile
0x140018908 GetVolumeInformationW
0x140018910 LoadLibraryW
0x140018918 GetProcAddress
0x140018920 FreeLibrary
0x140018930 LeaveCriticalSection
0x140018938 EnterCriticalSection
0x140018940 DeleteCriticalSection
0x140018948 GlobalUnlock
0x140018950 RemoveDirectoryW
Library USER32.dll:
0x140018988 TranslateMessage
0x140018998 SystemParametersInfoW
0x1400189a0 SetCursor
0x1400189a8 ReleaseCapture
0x1400189b0 SetCapture
0x1400189b8 SetWindowRgn
0x1400189c0 DispatchMessageW
0x1400189c8 OpenClipboard
0x1400189d0 CloseClipboard
0x1400189d8 SetClipboardData
0x1400189e0 EmptyClipboard
0x1400189e8 ExitWindowsEx
0x1400189f0 SendMessageW
0x1400189f8 PeekMessageW
0x140018a00 EnableWindow
0x140018a08 CopyRect
0x140018a10 RegisterHotKey
0x140018a18 ShowWindow
0x140018a20 UpdateWindow
0x140018a28 PostMessageW
0x140018a30 UnregisterHotKey
0x140018a38 InflateRect
0x140018a40 FillRect
0x140018a48 IsRectEmpty
0x140018a50 ReleaseDC
0x140018a58 wsprintfW
0x140018a60 GetCursorPos
0x140018a68 GetDC
0x140018a70 DefWindowProcW
0x140018a78 LoadIconW
0x140018a80 LoadCursorW
0x140018a88 RegisterClassW
0x140018a90 CreateWindowExW
0x140018a98 GetIconInfo
0x140018aa0 DrawIcon
Library GDI32.dll:
0x140018630 PatBlt
0x140018638 DeleteObject
0x140018640 CreateCompatibleBitmap
0x140018648 RoundRect
0x140018650 BitBlt
0x140018658 CreateCompatibleDC
0x140018660 GetStockObject
0x140018668 GetTextExtentPointW
0x140018670 SetTextColor
0x140018678 SetBkColor
0x140018680 SetBkMode
0x140018688 ExtTextOutW
0x140018690 DeleteDC
0x140018698 GetDeviceCaps
0x1400186a0 CreatePen
0x1400186a8 CreateSolidBrush
0x1400186b0 CreateHatchBrush
0x1400186b8 SelectObject
0x1400186c0 Rectangle
0x1400186c8 Ellipse
0x1400186d0 GetObjectW
0x1400186d8 GetDIBits
0x1400186e0 CreateRectRgn
0x1400186e8 CombineRgn
0x1400186f0 OffsetRgn
Library ADVAPI32.dll:
0x140018000 RegQueryValueExA
0x140018008 RegCloseKey
0x140018010 RegCreateKeyExA
0x140018018 RegCreateKeyExW
0x140018020 RegDeleteKeyA
0x140018028 RegDeleteKeyW
0x140018030 RegDeleteValueA
0x140018038 RegDeleteValueW
0x140018040 RegOpenKeyExA
0x140018048 RegOpenKeyExW
0x140018050 RegQueryValueExW
0x140018058 RegSetValueExA
0x140018060 RegSetValueExW
0x140018068 OpenProcessToken
0x140018070 AdjustTokenPrivileges
0x140018078 AllocateAndInitializeSid
0x140018080 FreeSid
0x140018088 LookupPrivilegeValueW
0x140018090 CheckTokenMembership
Library SHELL32.dll:
0x140018960 SHFileOperationW
0x140018968 ShellExecuteW
0x140018970 SHGetSpecialFolderPathW
0x140018978 ShellExecuteExW
Library COMCTL32.dll:
0x140018460 InitCommonControlsEx
Library ole32.dll:
0x140019468 CoCreateInstance
0x140019470 CoInitialize
0x140019478 CoUninitialize
0x140019480 CoTaskMemFree
Library gdiplus.dll:
0x140018cb0 GdipCreateFont
0x140018cb8 GdipCreatePath
0x140018cc0 GdipDeletePath
0x140018cc8 GdipDeleteFontFamily
0x140018cd0 GdipGetFamily
0x140018cd8 GdipAddPathString
0x140018ce0 GdipGetFontSize
0x140018ce8 GdipGetFontStyle
0x140018cf0 GdipGetPathWorldBounds
0x140018cf8 GdipCreateFromHDC
0x140018d00 GdipDeleteGraphics
0x140018d08 GdipSetSmoothingMode
0x140018d10 GdipSetInterpolationMode
0x140018d20 GdipCreateStringFormat
0x140018d28 GdipDeleteStringFormat
0x140018d38 GdipDeleteFont
0x140018d40 GdipAddPathStringI
0x140018d48 GdipCreatePen1
0x140018d50 GdipDeletePen
0x140018d58 GdipSetPenLineJoin
0x140018d60 GdipDrawPath
0x140018d68 GdipCreateSolidFill
0x140018d70 GdipDeleteBrush
0x140018d78 GdipFillPath
Library BCGCBPRO2500u140X64.dll:
0x1400180e0 ??0CBCGPEdit@@QEAA@XZ
0x1400180e8 ??1CBCGPEdit@@UEAA@XZ
0x1400182d0 ??1CBCGPWinApp@@UEAA@XZ
0x1400182d8 ??1CBCGPDialog@@UEAA@XZ
0x140018420 ??0CBCGPWinApp@@QEAA@H@Z
Library FTCoreX64.dll:
0x140018608 ?gFTCore@@3VCFTCore@@A
0x140018618 ?gpCfg@@3PEAVCCfg@@EA
Library VCRUNTIME140.dll:
0x140018ab0 __std_terminate
0x140018ab8 _purecall
0x140018ac0 strchr
0x140018ac8 strrchr
0x140018ad0 wcschr
0x140018ad8 wcsrchr
0x140018ae0 __CxxFrameHandler3
0x140018ae8 memset
0x140018af0 memcmp
0x140018af8 memcpy
0x140018b00 __C_specific_handler
Library api-ms-win-crt-stdio-l1-1-0.dll:
0x140018c28 __stdio_common_vsscanf
0x140018c30 __stdio_common_vswscanf
0x140018c38 __stdio_common_vsprintf
0x140018c50 _set_fmode
0x140018c58 __p__commode
0x140018c60 __stdio_common_vswprintf
Library api-ms-win-crt-math-l1-1-0.dll:
0x140018b70 __setusermatherr
0x140018b78 round
0x140018b80 sqrt
Library api-ms-win-crt-string-l1-1-0.dll:
0x140018c70 _wcsnicmp
0x140018c78 isalpha
0x140018c80 strcat_s
0x140018c88 strcpy_s
0x140018c90 wcscpy_s
Library api-ms-win-crt-heap-l1-1-0.dll:
0x140018b38 free
0x140018b40 malloc
0x140018b48 _set_new_mode
0x140018b50 calloc

Hosts

No hosts contacted.

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 51963 114.114.114.114 53
192.168.56.101 58367 114.114.114.114 53
192.168.56.101 60123 114.114.114.114 53
192.168.56.101 62912 114.114.114.114 53
192.168.56.101 63429 114.114.114.114 53
192.168.56.101 63497 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 123 20.189.79.72 time.windows.com 123
192.168.56.101 49235 224.0.0.252 5355
192.168.56.101 50002 224.0.0.252 5355
192.168.56.101 50534 224.0.0.252 5355
192.168.56.101 53657 224.0.0.252 5355
192.168.56.101 56539 224.0.0.252 5355
192.168.56.101 57756 224.0.0.252 5355
192.168.56.101 57874 224.0.0.252 5355
192.168.56.101 60215 224.0.0.252 5355
192.168.56.101 60384 224.0.0.252 5355
192.168.56.101 61680 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.