17eeba2675a5496e9ecafa81661e3c549259b68a409f38c355fde196e2e6b27e
17eeba2675a5496e9ecafa81661e3c549259b68a409f38c355fde196e2e6b27e.exe
静态报毒
动态报毒
CVE
FAMILY
METATYPE
PLATFORM
TYPE
UNKNOWN
WIN32
TROJAN
GENERICKDZ
DACN
0.12
FACILE
1.00
IMCLNet
0.69
MFGraph
0.00
引擎 |
描述 |
特征 |
威胁分数 |
可能家族 |
检测耗时 |
DACN
|
基于动态分析和胶囊网络的可视化恶意软件检测
|
API调用、DLL以及注册表的修改情况
|
0.12
|
Unknown
|
0.21s
|
FACILE
|
利用改进的层次胶囊网络对二进制恶意软件图像进行识别分类
|
二进制图像映射为的灰度图像
|
1.00
|
Unknown
|
0.03s
|
IMCLNet
|
轻量化深度卷积网络模型实现恶意软件家族检测
|
原始二进制映射而成的可视化图像
|
0.69
|
Unknown
|
0.19s
|
MFGraph
|
利用静态特征构建图网络以检测恶意软件
|
原始二进制PE文件的静态特征节点
|
0.00
|
Unknown
|
0.00s
|
查杀引擎 |
查杀结果 |
查杀时间 |
查杀版本 |
Alibaba
|
None
|
20190527
|
0.3.0.5
|
Avast
|
Win32:Malware-gen
|
20190926
|
18.4.3895.0
|
Baidu
|
None
|
20190318
|
1.0.0.2
|
CrowdStrike
|
win/malicious_confidence_100% (D)
|
20190702
|
1.0
|
Kingsoft
|
None
|
20190926
|
2013.8.14.323
|
McAfee
|
GenericRXGP-KT!1868E9CD987A
|
20190926
|
6.0.6.653
|
Tencent
|
None
|
20190926
|
1.0.0.1
|
该二进制文件可能包含加密或压缩数据,表明使用了打包工具
(2 个事件)
section |
{'name': 'UPX1', 'virtual_address': '0x0000f000', 'virtual_size': '0x00007000', 'size_of_data': '0x00006200', 'entropy': 7.8382833206000795} |
entropy |
7.8382833206000795 |
description |
发现高熵的节 |
entropy |
0.98 |
description |
此PE文件的整体熵值较高 |
可执行文件使用UPX压缩
(3 个事件)
section |
UPX0 |
description |
节名称指示UPX |
section |
UPX1 |
description |
节名称指示UPX |
section |
UPX2 |
description |
节名称指示UPX |
与未执行 DNS 查询的主机进行通信
(1 个事件)
文件已被 VirusTotal 上 52 个反病毒引擎识别为恶意
(50 out of 52 个事件)
ALYac |
Trojan.GenericKDZ.53029 |
APEX |
Malicious |
AVG |
Win32:Malware-gen |
Acronis |
suspicious |
Ad-Aware |
Trojan.GenericKDZ.53029 |
AhnLab-V3 |
Malware/RL.Generic.R246075 |
Antiy-AVL |
Trojan/Win32.AGeneric |
Arcabit |
Trojan.Generic.DCF25 |
Avast |
Win32:Malware-gen |
Avira |
HEUR/AGEN.1004962 |
BitDefender |
Trojan.GenericKDZ.53029 |
CAT-QuickHeal |
Trojan.Mauvaise.SL1 |
ClamAV |
Win.Malware.Cmifao2i9nl-6825052-0 |
Comodo |
Virus.Win32.Agent.VP@8ek9ga |
CrowdStrike |
win/malicious_confidence_100% (D) |
Cybereason |
malicious.48fe6f |
Cylance |
Unsafe |
Cyren |
W32/Trojan.ECUA-4313 |
DrWeb |
Trojan.DownLoader23.51365 |
ESET-NOD32 |
a variant of Win32/Agent.NCK |
Emsisoft |
Trojan.GenericKDZ.53029 (B) |
Endgame |
malicious (moderate confidence) |
F-Prot |
W32/Trojan2.PZDI |
F-Secure |
Heuristic.HEUR/AGEN.1004962 |
FireEye |
Generic.mg.7888be948fe6fbfe |
Fortinet |
W32/Agent.NCK!tr |
GData |
Trojan.GenericKDZ.53029 |
Ikarus |
Virus.Win32.CeeInject |
Invincea |
heuristic |
Jiangmin |
Trojan.Agent.brls |
K7AntiVirus |
Trojan ( 0000e1321 ) |
K7GW |
Trojan ( 0000e1321 ) |
Kaspersky |
Trojan.Win32.Agent.neyndy |
MAX |
malware (ai score=83) |
Malwarebytes |
Trojan.Agent |
MaxSecure |
Trojan.Malware.300983.susgen |
McAfee |
GenericRXGP-KT!1868E9CD987A |
McAfee-GW-Edition |
BehavesLike.Win32.PWSOnlineGames.pc |
MicroWorld-eScan |
Trojan.GenericKDZ.53029 |
Microsoft |
Trojan:Win32/Wacatac.B!ml |
NANO-Antivirus |
Trojan.Win32.RP.fkilpx |
Qihoo-360 |
HEUR/QVM11.1.268B.Malware.Gen |
Rising |
Ransom.Satan!1.B5F1 (CLASSIC) |
SentinelOne |
DFI - Malicious PE |
Sophos |
W32/CTSInf-B |
Symantec |
ML.Attribute.HighConfidence |
TACHYON |
Trojan/W32.Agent.77544.D |
Trapmine |
malicious.high.ml.score |
VBA32 |
Trojan.Agent |
Yandex |
Trojan.Agent!BgCNgJOEhBE |
288x288
224x224
192x192
160x160
128x128
96x96
64x64
32x32
👋 欢迎使用 ChatHawk
我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!
🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
PE Compile Time
2015-05-05 21:45:31
PE Imphash
f1a539a5b71ad53ac586f053145f08ec
Sections
Name |
Virtual Address |
Virtual Size |
Size of Raw Data |
Entropy |
UPX0 |
0x00001000 |
0x0000e000 |
0x00000000 |
0.0 |
UPX1 |
0x0000f000 |
0x00007000 |
0x00006200 |
7.8382833206000795 |
UPX2 |
0x00016000 |
0x00001000 |
0x00000200 |
2.9046664760200502 |
L!This program cannot be run in DOS mode.
F.'}'}'}>>}'}><}'}>?}'}_b}'}'}'}
=}'}Rich'}
&2>{<L`6|
"2yBXj4y
<2Hb|<
*>Vnyyzy
MBkIgv
CorExitProcesD
r:uVfsB
a *es"c`
?Jha C.
a"a?7vknVxeRekmxm.l
i&oJk5=
9ltZ=
?eG2*2
#;5>;prnu
1yA^tmt#pwem33p
}'ak?<8\
*f3m_3_[$sM
LzmWdmW
gsby00X
ssSkcv/r
%WfKLO-i
c /*l)4
sD'Mvi!
i? {xDXg[-Ca5v<TcO
8gS3G7TnOBS;G
n/mO ?
0w|\]f
l]cKgd!
aB:Ek<+
<uOMs_
kr'l-
7FlsAlloc
GetValu
S|AIniti
izeCrc
|k4c"onEx
maphof
"WpTh.dStackGuamranFeW5poolTimehO>_)WaF/
Clbsvsn
sh;WeBuffs
wpILibryWhenp!
RurnBxC
~Numbaw16Logw7
JnkWg~Defaul
Dir`ieZ
EnZsdm[
omp6tHngw
DFYpCn?U rUNa@Is
id)LCMh
We&ui.
s[7{Nn
jv('J.eA
c_&ygrzgsz
sC~?88s01
PMM/dd/yd
(,HH:mm:=pW
TeW3hyp"
nnks#B'r#
l?eR9X>vNv
Vmr#Zh=l/~
#J{SH
gD)pBoA_W
Wdowas'
kPopuxwObjJ
H ( *9 H
_[A #B
!"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`?!T
ABCDEFGHIJKLMNOPHQRSTUVWXYZ?
[./'*p*x*
#G !"9r#$%&=
6 7(89r098>@?H@#G
PAXC`Dhr
FpGxIJG
#VWZ^~9re
#G,%8&D'
9rP)\*h+t,#G-/29r
4567/G
94A@CLDdE
#pF|GI
9rJKLN
e k0l@A
&|yB 3qgrl
9r@LXCd
$09r<HT`#G
l&\8r
Lv.?,s
9rDP\Mh9
Gtg>6%
9rN8/t
#gGoZ(
P+_~878
r#GH1(x:G&4
/?@#gg
PS/P2\y6'7&
hgg$?9qvtf
#G>;@0v
T9q6r9
(V#gGh
#Ho`x8;r
]73z@
|W #G_$b
4<OT{'
ut+aOijN.k
onnpvp_r/rh|9k
h%0ruF!o
o\p;ell_f_
Vw{*zoum.fn
ooiOs?vk
6anolk;?ySv/
E2'GZ/
E?-rR'
[.r/h_;>
?-UGu/S
bO.pPxXNgRW
uUr`RoKwtiKA.vE&ttT
rRqyKOdDw9iUeYl]
vvBNOM7
NM>6Zxv
oEwokO
7NtKTe//s*YkZ
h$wb=mO&
4iK/t
ekW7gl
rwwsm_Mcg
GrilcS
mSEg_g/
:8VnC[1yNe
GLnBTHmC
OI2bCo*
SM_;6EP/fG
SqgY6'B_\vOgn
GTsR+OBW
CGK/nH?
WqLGAU7kf/B_P/Q
O7{3q-
wKgyz1;
c/WXl/b
/_ioadf
er!y/ypduvwt7e4Vbruo
w.qA<W
qpw[*e
.nnrm/
1KGns;G
hmB?S
liocBnok?jj.nsEql
p/_yWv
guGpwGup"
fu`-$/B
jRTIK#
5MKPRrhD%^T^VVXZ
Zj>l{MX
_q!tpv&xRz
@c2527
^.6 ?w
%p6Wg=<(RFzCxke&yZI
PF{xT2wro2Ds
jr478^H
l6/0tP
+&= QTI
Q`ME><x@,
9]vWF_G'm
;}r_^[D
XX_[]XPSGw
KW#DY?
xA@#@28
jD4vlZP,
#ISp>G
0{hSP
`FEQ`d$/
p,-:&jvFb
C/|2iaQ
'Xwa?x
^f|$<.tJ&<3
$`8G<i
}56LqF,uh
!3W0 %T
>|OHcH
H|(o\h_` <
xH = I
W4QQJ/
Ju{fm>S
V'0|:c
8+F:^|u
<!POEj
EQO`YY
euZ0r}
Ska]Wa%
e4)C=dD7
o}Genuu_
ineIuV
luM\@_WE%?
N8csmu%x
S^`F`y
_F\pjd
9J~dFd
,*A&u di*4S
?x<vdj
~$jv$eK0g
r@DDHn\H~H
q&zvl#QjY;'s
i&Va{}p
L`fYNGh
g$&t3V
pjCXfh{
4\p0(l6_;
bl:hYc0x#
5W6\uah
]md$'x
uP"_wY_}8h
;HghrR^h
pnp-;}
{3jXh~
7"Sf*I=#Z
@VAy}pXu)@*<v5}!
-%iRp+
IBx@_{t'W7-u{h:
ho-|~tIU
_3^8~F|[S
v/j@j _
tDk[}
} wE }?Z^=[UU
vM`jG@z
6>r!0@
"Sxa/8
4Xu;`%p
&_y98j
~a"f;5\
tDwYdX
zukdgx0
lYP^Ge
N@-zILt
+WtGqER6
]}%;d6t
VHQVxzu
~~wYCg%
e@0pD
2 ,<=u\_
]6,K+C9*v
?Vj ^yw
vTG~hT-/Mi([
^21,"6!t
Mufd]D8\pd
Q@x8ug
WQeR0mh
pp|[>K;~N
6Q<P_)
hx?4+\VL
S\)H!k
d--*0z
@pPV1sP
W3dKT<'Y2
8N3sBh=7[
P?I/||j
j3N(Jg7
Nst6rxt
-|Du}~
Q4_[@a
/pl []
FlP\kFg?]k
t4J0;t(W8m
>v;-(t&
WtA@I9,SG
'fO$fMc
V].!;VfIGh[lUe8
;aqnh {
po33S{qxt`
M,A3)}
VZfm.s_W~W
9$[/+rA0(=}b3
>4J{02#S%
FP-^r&
n9]vO}]t!PV
xvlUh$
[s^MUgFk0
t5ADt+
|C;vf9x
ROuk`]_^%[(
Rn8cchY
FWD__5
sGlmV"cS
/j(P3MP
) v$mT6i
%#HMra
5w<Cw6
/y&>t1
vYJHrp$0w
^{DluHPU
0~^w\VzQ
-EzIR=
G`pg`VM1uA
D(r@;}&kVdU
bA?9:C
tAa0r2"
J_Bild
9u&z3r
3v%O +*
_[t.|
WK~?(m$
?)$9}t
;tO9=0G%iSJM0
ZUe(hu
|b#?nT$
;v.4v\
(QBJ(U1L
lRQ2tG
8"1w{H
$V5714
YO;r"D
Ufg*YH]@
>Z6B0s$[
"WtL)||$R
OVdgkL;=
0gh>(n00
en+o 0}l
<|DD<<<;(hB
Wt1|9Wp+
';;22+hCd
FqkOHgbNZ
,'wAWS3
nP}>v`~p0g&
FFJu8O
lZIu$t
!++Qc`/?
YkVX!#
(}^ZKu
FV4crCu^
% $$r88<<\r@@DD.\.HHLL
$(,0''''4
DHLP\prTX
\`dhlptx|K
L2$2$$L&`2e
dIdI&I&I&d
$dI&(,0I&48<@`@eDH$L2LPTL2X\`
|$9E8RNJX8
~KYAr?
&&QSc($
-,*SYE
t, H)U@
u`sop1z~B
0xu|!h
s=~AQiw9]=3
+]#LYD)
NjA[jZZ+U
t"ff5n
8x$;ag
<#6ic}Ou[Y/
!a0O`pY
r!}9%R
5C;0SGYDG
A$A$]6
5=fZg0
UQPX^Y[
^}SD\v
AuAApKu:7
@X fV+rZ/J<xifcZ
x?F}5$
ttW(J=N?<8(
nA_e!M5* ]+6ae
8cV7v_x
}?)LV DpY
d3FVv@D
<,!3~9U
.>!8K
RRP>m3TY
;Cg!$
Pe~,8n=?
vZh]@9H4W&
!]SZej%tVDxmQ
$QPcIM
j\B~<]
T@y=RtU$<
*B%H@1%
(S#_#!C
j<Cf>%;
vtL>T1%abWwu
/=+Hs;\.>$
Y^0k48|*
VVhU.12(
rbRlXq
i?18Q.$
L<.YCwP
5*o lRB$e
t7;t57
^^DVQpzA)qT
';_t|%
V(n1ci
8lh1'q
<0} U_!xV
lLY/7N2
Z2-(FS
'=aOV"x|?[ev
o?qCNw
;QqOHpDc
djR'L&Bv
/?_U[mP?
X\<`dhlpx<<<
y ,4@LPyT`t
4<D<LT\dlyt|^<y
0DyLTh~
v{giv_
_j2r1~#
??cU1<
/!5ACPgRvn/S
WYl/ymV p
?\pr)
XzxrTyp.-eW
1YkiiFile
<-{{+B
S;P[:;of
]Yv&dNexAW5Fm
xpaREnvinmeAfvC*sonm
roVaabg;[F[
dH6l}o
ModCP
mmfK;{VLIsw;[<
I^kedkKk
cFm+De
FliiwF10I{h
E+7Addr/
M<tiBy oWivCha>"xq-
XuZ`tER`
ZYUn}9,
|V+1Unh
S9+*km$T.m-""P
,ASveV
CCUagA`
NbugNrG
Rtl`wi
g1Key9+S
tnRJX9/o_:W=Acqu
N+/tWI{
8afQq6
Wwspdtf
,&1/$-7(
,!*2vw
\K.reJf!;-N"Bw
XPTPSWXaD$j
ADVAPI32.dll
KERNEL32.DLL
ntdll.dll
USER32.dll
RegCloseKey
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
NtClose
wsprintfW
p<a7q/
@'Q3t4jc
:SD4'EX*Qv]
@4Lg8Lq%Z DSG
2}#kR9
,Fe&}_
ri(|Q[K
hFc4FDzg
x!1lf'"\
vjSy^wY"]N-Fo
8c.kC./
xcb$`H
pzgJ9&=*/
SOW?3!zOdG
BsvS}T
ZLnti~
lu?Ogc9v<dS
;p?qB{|S
1/3;lllB
Y2(L s*
j'PS|CAG
0ct|B&
#rRds5
t.?ix_r
'jJb@7RQI8
<mZ|9
"G%&gEM.rL
mRn$-8
5((4ATf
`<w3-Vcm>@sAT0.}VV
0@Y$e*
kdxG/|J%h
fyk;C;
ee7W) Y},
P%(oau}
5}Q8s6
@)e8/
n5"qM^(I.
4t%|(T
vKR/2nx
CQqR,5Ltb2;V3l
j5~wl\
]udDY}8rqgr
\%gC'-0R
l)6`*}o
XQu?ti
_7%YZVe,-
`KcJ/X"e
xFRM6$gb>
VU`eQx~hAW0~
v(+lfDMIh*}S#
.;Dca>P/
rvw]Skq
u'Himddx*l.l@k
RKU3FF~
5|#"A5%_
rQ%;0g
AATN#kvDK
O+3s!xKUNx
KH[Yn75uF,
6-RmB'(
vx)A(*Cy
'1*n~Y=
/;om%Z1
lr#*oj\t523kD|#N
0F?@YQeyrfq$
cRq"(X
y6V\nJ
uCf^1E4
K=;@)_'U
C?27W+<p
F<)/#ZX+B&xf[
+7w~PP
<K!/(s%|
E#uOk(
|N)f9h[bJ
.p l
$9vI#<e`-
$*`:m'_u#
":GWWw<J;S
PC)IMxTrW\=*
De/1vJv
*F;f'r
da2]ZN
(.@.)h4<
js%}s2>
5ZY4Ld
c&C}'e(/7
:]VXX>:
?'Z|,sF 6_
%l_4~r
$3+`=y
ie>IsGtc4
=mMZU}5F
qAMNkz>
4K{,,P
4.xy]r
Z(A3L+]?M)hzrU.
aNW9qk-,vPy~`wL
Nwtra>_E$
,oHcdf
jLNdYw
C-6A2GM
ep9i}1
>o:*}<;w6
{rOz5BB
"UHF7]
";1d,7
XjtPpR
0bo+4|L5P
FB7_l@v],
C1ft7eM
8Q{3}q`
YlT4Z9Iz
s!.8hC
~*V*&*^w
hgK=5w_uTM
6@%>:~G
waL\M_
<<VYs7\
vv75w/8H$V
J\Id$^Or?z
~VsWb0$
avu vq{hk/
45m*~03
E6`;B${[
/URj";4
AgkbNy
D}MD9X
+"9lq?
@q`oQEeV
^}tofL#Y6
1Y>rJQ
>[@!!C"h:
k]*muBKX
zOjG w
};8WN{
6*he.l
.eNB&d
1?UTQ=r
_J|lrk:N
~HLehD_
C*W]]1
d;Xz!
vKa%k(
1!1:(9
2@"(\A)s~\:O
wPd|O\#s
TZsn8z
>5(8!Bs
+uo#G.V
R-jDQ1
l'ah"GO6
#-kwoH
.TXeABgp
pSlC16
RcpfY;WB"1>$
4Lg+BQ
[XOH|dq
U*Uu.$R
&1~%];G_x
HM`2_,)
h6$N|{.B
"TPjA|k+ywp
O&y?afFh
Ew>zhr-
j?!L(6X]GPa
e}}eGu
A!>/ybb\"P*
q\;!ED#
+.KXX)
tTs`GL)
dV3l9
I65j.I
4;XWvp:GprH
8c+*j
w9#HZ$Teg
Kc\K\,
a\ff&SlD
0MN,tYn
{~x$55
]\|M(eX:&sf)
WP3Q?)
*(P'q&%
rv;NNO
%6@A-Y6`h@
I!*Rw2:k
k~\Pd&
Zx%*Z%
S-/Pnt
^}E_8x/T
hma@g
n."4I1Q4L!D
e))_(4
M`94K7zxWR
_Kb?oF6<
\fOwF@E4J%[
H]~cV#ew
HbFJM?5
+"OvLh6fg
\=gz`:j&
*Fc7*kP@~rp
h_H$#BeOO$
QE+Jw:nee
aj{>'$C
d0!QtI.[
KzuQBnZ+)ZuQy-
&3t}E*Nx
2M|':1vB
&8(!oD4
(AQ'Ve.bIC#]
IxSyuX'w
V'tflG6=
opWG][
,i5NV4Tj
IJznb;n#
-@Yr)Z
%eEJ'iV?F8@`$
CDF%# d<*
Y+cBglA4
8&YdN:
OKX^^,
]_**dz
&l.\_w!
/n;{>
@nfeBolbMT
B/.ur;|
|gUe[N7Xk5}aL4zq@n0
M<SKzMq
q [l.7Q(SSO u
n$,0ORl2
&{`6G3xJ
f4.tj5
E60QN;
5ZB!7@
@=+m{!Gyre
[xGmXv F84
NUk .c
:KMD G
2"GhAo~p
_[Mp2B}GPf
e}#1q`
m%K7#]&
1Q~cjGd!
uSzTIx3
eZ%?j)
-aZun6
Ot5UPk
f9Z*_-Bq
E'=.]]0e>E
+n\*MQ/
!sG90Z
>Wtz1w
xuxz(
[F,r 5C\
xq'Z\9
>h@Q5u5
nTUN%Kl]f
CIq1SVSDi
8s`$r<uY
6rOOU{Y
"G)WVFy
MGHGL>y
+$X]6_5
4"?(g2,tb"
4bi5Utvf
jElDik
GL"ueb
DdTLA
IO:hFm
yVcC%Z76W]<)_
Qc>/djo
Q?-si]E
rTXl;]ya
F'UpKHYJ
Gvsq}J
d[_EL.
c q16;3R8#4YBX
uB5FvW$[d
[0<O-k{l&.n
XBp-ZG,6o+;
[vqtXu".
k(oi1r
v&saJOt]Vsm
3p6<SZp]i
v% @gVaS
Y@zXcP5%G
A>D!)(4
f9T_![od@
EqSWj1b
K$=g^&&
eBoj&!/_
W!2+Cy
Z}z;Qaw(!5
bIJ 5v1R?
7cxM}(
Y]r%mbM
u9RZN^P
iS4a_z
M^@?nD
Wb^C /%9
^^A's()WN#1wdeu8T|?<]{P
! -g3L
x;NrE
+z}(_\Ywr$=
cEfNB"V
Dj%gzfX
WnFo?#8tp
Rag-/GGk__
Qj_eck4v\J
<L+z2, :wi`&Y
i%q4Tb
zZ3Q^u|%g,Z
]3P`F7
+\e"oJ
)pe"1.
^7{kTjf
HU{zJAH{! f
OfV2Tk+
C*6<@cE
&;DH28hn*{"Jy
ZQ,N@j0ng}BIK0Ce`2? ^hZ|(m
TlC4k,0;
T:p{n,
E.Wo3w/jCTS
TCP
No TCP connections recorded.
UDP
Source |
Source Port |
Destination |
Destination Port |
192.168.56.101 |
53179 |
224.0.0.252 |
5355 |
192.168.56.101 |
49642 |
224.0.0.252 |
5355 |
192.168.56.101 |
137 |
192.168.56.255 |
137 |
192.168.56.101 |
61714 |
114.114.114.114 |
53 |
192.168.56.101 |
56933 |
114.114.114.114 |
53 |
192.168.56.101 |
138 |
192.168.56.255 |
138 |
HTTP & HTTPS Requests
No HTTP requests performed.
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts
Sorry! No dropped buffers.