1.3
低危

17eeba2675a5496e9ecafa81661e3c549259b68a409f38c355fde196e2e6b27e

17eeba2675a5496e9ecafa81661e3c549259b68a409f38c355fde196e2e6b27e.exe

分析耗时

192s

最近分析

366天前

文件大小

42.7KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN GENERICKDZ
鹰眼引擎
DACN 0.12
FACILE 1.00
IMCLNet 0.69
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba None 20190527 0.3.0.5
Avast Win32:Malware-gen 20190926 18.4.3895.0
Baidu None 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (D) 20190702 1.0
Kingsoft None 20190926 2013.8.14.323
McAfee GenericRXGP-KT!1868E9CD987A 20190926 6.0.6.653
Tencent None 20190926 1.0.0.1
静态指标
行为判定
动态指标
该二进制文件可能包含加密或压缩数据,表明使用了打包工具 (2 个事件)
section {'name': 'UPX1', 'virtual_address': '0x0000f000', 'virtual_size': '0x00007000', 'size_of_data': '0x00006200', 'entropy': 7.8382833206000795} entropy 7.8382833206000795 description 发现高熵的节
entropy 0.98 description 此PE文件的整体熵值较高
可执行文件使用UPX压缩 (3 个事件)
section UPX0 description 节名称指示UPX
section UPX1 description 节名称指示UPX
section UPX2 description 节名称指示UPX
网络通信
与未执行 DNS 查询的主机进行通信 (1 个事件)
host 114.114.114.114
文件已被 VirusTotal 上 52 个反病毒引擎识别为恶意 (50 out of 52 个事件)
ALYac Trojan.GenericKDZ.53029
APEX Malicious
AVG Win32:Malware-gen
Acronis suspicious
Ad-Aware Trojan.GenericKDZ.53029
AhnLab-V3 Malware/RL.Generic.R246075
Antiy-AVL Trojan/Win32.AGeneric
Arcabit Trojan.Generic.DCF25
Avast Win32:Malware-gen
Avira HEUR/AGEN.1004962
BitDefender Trojan.GenericKDZ.53029
CAT-QuickHeal Trojan.Mauvaise.SL1
ClamAV Win.Malware.Cmifao2i9nl-6825052-0
Comodo Virus.Win32.Agent.VP@8ek9ga
CrowdStrike win/malicious_confidence_100% (D)
Cybereason malicious.48fe6f
Cylance Unsafe
Cyren W32/Trojan.ECUA-4313
DrWeb Trojan.DownLoader23.51365
ESET-NOD32 a variant of Win32/Agent.NCK
Emsisoft Trojan.GenericKDZ.53029 (B)
Endgame malicious (moderate confidence)
F-Prot W32/Trojan2.PZDI
F-Secure Heuristic.HEUR/AGEN.1004962
FireEye Generic.mg.7888be948fe6fbfe
Fortinet W32/Agent.NCK!tr
GData Trojan.GenericKDZ.53029
Ikarus Virus.Win32.CeeInject
Invincea heuristic
Jiangmin Trojan.Agent.brls
K7AntiVirus Trojan ( 0000e1321 )
K7GW Trojan ( 0000e1321 )
Kaspersky Trojan.Win32.Agent.neyndy
MAX malware (ai score=83)
Malwarebytes Trojan.Agent
MaxSecure Trojan.Malware.300983.susgen
McAfee GenericRXGP-KT!1868E9CD987A
McAfee-GW-Edition BehavesLike.Win32.PWSOnlineGames.pc
MicroWorld-eScan Trojan.GenericKDZ.53029
Microsoft Trojan:Win32/Wacatac.B!ml
NANO-Antivirus Trojan.Win32.RP.fkilpx
Qihoo-360 HEUR/QVM11.1.268B.Malware.Gen
Rising Ransom.Satan!1.B5F1 (CLASSIC)
SentinelOne DFI - Malicious PE
Sophos W32/CTSInf-B
Symantec ML.Attribute.HighConfidence
TACHYON Trojan/W32.Agent.77544.D
Trapmine malicious.high.ml.score
VBA32 Trojan.Agent
Yandex Trojan.Agent!BgCNgJOEhBE
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2015-05-05 21:45:31

PE Imphash

f1a539a5b71ad53ac586f053145f08ec

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x0000e000 0x00000000 0.0
UPX1 0x0000f000 0x00007000 0x00006200 7.8382833206000795
UPX2 0x00016000 0x00001000 0x00000200 2.9046664760200502

Imports

Library ADVAPI32.dll:
0x416064 RegCloseKey
Library KERNEL32.DLL:
0x41606c LoadLibraryA
0x416070 ExitProcess
0x416074 GetProcAddress
0x416078 VirtualProtect
Library ntdll.dll:
0x416080 NtClose
Library USER32.dll:
0x416088 wsprintfW

L!This program cannot be run in DOS mode.
F.'}'}'}>>}'}><}'}>?}'}_b}'}'}'}
=}'}Rich'}
&2>{<L`6|
"2yBXj4y
<2Hb|<
*>Vnyyzy
MBkIgv
CorExitProcesD
r:uVfsB
a *es"c`
?Jha C.
a"a?7vknVxeRekmxm.l
i&oJk5=
9ltZ=
?eG2*2
#;5>;prnu
1yA^tmt#pwem33p
}'ak?<8\
*f3m_3_[$sM
LzmWdmW
gsby00X
ssSkcv/r
%WfKLO-i
c /*l)4
sD'Mvi!
i? {xDXg[-Ca5v<TcO
8gS3G7TnOBS;G
n/mO ?
0w|\]f
l]cKgd!
aB:Ek<+
<uOMs_
kr'l-
7FlsAlloc
GetValu
S|AIniti
izeCrc
|k4c"onEx
maphof
"WpTh.dStackGuamranFeW5poolTimehO>_)WaF/
Clbsvsn
sh;WeBuffs
wpILibryWhenp!
RurnBxC
~Numbaw16Logw7
JnkWg~Defaul
Dir`ieZ
EnZsdm[
omp6tHngw
DFYpCn?U rUNa@Is
id)LCMh
We&ui.
s[7{Nn
jv('J.eA
c_&ygrzgsz
sC~?88s01
PMM/dd/yd
(,HH:mm:=pW
TeW3hyp"
nnks#B'r#
l?eR9X>vNv
Vmr#Zh=l/~
#J{SH
gD)pBoA_W
Wdowas'
kPopuxwObjJ
H ( *9 H
_[A #B
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`?!T
ABCDEFGHIJKLMNOPHQRSTUVWXYZ?
[./'*p*x*
#G !"9r#$%&=
6 7(89r098>@?H@#G
PAXC`Dhr
FpGxIJG
#VWZ^~9re
#G,%8&D'
9rP)\*h+t,#G-/29r
4567/G
94A@CLDdE
#pF|GI
9rJKLN
e k0l@A
&|yB 3qgrl
9r@LXCd
$09r<HT`#G
l&\8r
Lv.?,s
9rDP\Mh9
Gtg>6%
9rN8/t
#gGoZ(
P+_~878
r#GH1(x:G&4
/?@#gg
PS/P2\y6'7&
hgg$?9qvtf
#G>;@0v
T9q6r9
(V#gGh
#Ho`x8;r
]73z@
|W #G_$b
4<OT{'
ut+aOijN.k
onnpvp_r/rh|9k
h%0ruF!o
o\p;ell_f_
Vw{*zoum.fn
ooiOs?vk
6anolk;?ySv/
E2'GZ/
E?-rR'
[.r/h_;>
?-UGu/S
bO.pPxXNgRW
uUr`RoKwtiKA.vE&ttT
rRqyKOdDw9iUeYl]
vvBNOM7
NM>6Zxv
oEwokO
7NtKTe//s*YkZ
h$wb=mO&
4iK/t
ekW7gl
rwwsm_Mcg
GrilcS
mSEg_g/
:8VnC[1yNe
GLnBTHmC
OI2bCo*
SM_;6EP/fG
SqgY6'B_\vOgn
GTsR+OBW
CGK/nH?
WqLGAU7kf/B_P/Q
O7{3q-
wKgyz1;
c/WXl/b
/_ioadf
er!y/ypduvwt7e4Vbruo
w.qA<W
qpw[*e
.nnrm/
1KGns;G
hmB?S
liocBnok?jj.nsEql
p/_yWv
guGpwGup"
fu`-$/B
jRTIK#
5MKPRrhD%^T^VVXZ
Zj>l{MX
_q!tpv&xRz
@c2527
^.6 ?w
%p6Wg=<(RFzCxke&yZI
PF{xT2wro2Ds
jr478^H
l6/0tP
+&= QTI
Q`ME><x@,
9]vWF_G'm
;}r_^[D
XX_[]XPSGw
KW#DY?
xA@#@28
jD4vlZP,
#ISp>G
0{hSP
`FEQ`d$/
p,-:&jvFb
C/|2iaQ
'Xwa?x
^f|$<.tJ&<3
$`8G<i
}56LqF,uh
!3W0 %T
>|OHcH
H|(o\h_` <
xH = I
W4QQJ/
Ju{fm>S
V'0|:c
8+F:^|u
<!POEj
EQO`YY
euZ0r}
Ska]Wa%
e4)C=dD7
o}Genuu_
ineIuV
luM\@_WE%?
N8csmu%x
S^`F`y
_F\pjd
9J~dFd
,*A&u di*4S
?x<vdj
~$jv$eK0g
r@DDHn\H~H
q&zvl#QjY;'s
i&Va{}p
L`fYNGh
g$&t3V
pjCXfh{
4\p0(l6_;
bl:hYc0x#
5W6\uah
]md$'x
uP"_wY_}8h
;HghrR^h
pnp-;}
{3jXh~
7"Sf*I=#Z
@VAy}pXu)@*<v5}!
-%iRp+
IBx@_{t'W7-u{h:
ho-|~tIU
_3^8~F|[S
v/j@j _
tDk[}
} wE }?Z^=[UU
vM`jG@z
6>r!0@
"Sxa/8
4Xu;`%p
&_y98j
~a"f;5\
tDwYdX
zukdgx0
lYP^Ge
N@-zILt
+WtGqER6
]}%;d6t
VHQVxzu
~~wYCg%
e@0pD
2 ,<=u\_
]6,K+C9*v
?Vj ^yw
vTG~hT-/Mi([
^21,"6!t
Mufd]D8\pd
Q@x8ug
WQeR0mh
pp|[>K;~N
6Q<P_)
hx?4+\VL
S\)H!k
d--*0z
@pPV1sP
W3dKT<'Y2
8N3sBh=7[
P?I/||j
j3N(Jg7
Nst6rxt
-|Du}~
Q4_[@a
/pl []
FlP\kFg?]k
t4J0;t(W8m
>v;-(t&
WtA@I9,SG
'fO$fMc
V].!;VfIGh[lUe8
;aqnh {
po33S{qxt`
M,A3)}
VZfm.s_W~W
9$[/+rA0(=}b3
>4J{02#S%
FP-^r&
n9]vO}]t!PV
xvlUh$
[s^MUgFk0
t5ADt+
|C;vf9x
ROuk`]_^%[(
Rn8cchY
FWD__5
sGlmV"cS
/j(P3MP
) v$mT6i
%#HMra
5w<Cw6
/y&>t1
vYJHrp$0w
^{DluHPU
0~^w\VzQ
-EzIR=
G`pg`VM1uA
D(r@;}&kVdU
bA?9:C
tAa0r2"
J_Bild
9u&z3r
3v%O +*
_[t.|
WK~?(m$
?)$9}t
;tO9=0G%iSJM0
ZUe(hu
|b#?nT$
;v.4v\
(QBJ(U1L
lRQ2tG
8"1w{H
$V5714
YO;r"D
Ufg*YH]@
>Z6B0s$[
"WtL)||$R
OVdgkL;=
0gh>(n00
en+o 0}l
<|DD<<<;(hB
Wt1|9Wp+
';;22+hCd
FqkOHgbNZ
,'wAWS3
nP}>v`~p0g&
FFJu8O
lZIu$t
!++Qc`/?
YkVX!#
(}^ZKu
FV4crCu^
% $$r88<<\r@@DD.\.HHLL
$(,0''''4
DHLP\prTX
\`dhlptx|K
L2$2$$L&`2e
dIdI&I&I&d
$dI&(,0I&48<@`@eDH$L2LPTL2X\`
|$9E8RNJX8
~KYAr?
&&QSc($
-,*SYE
t, H)U@
u`sop1z~B
0xu|!h
s=~AQiw9]=3
 +]#LYD)
NjA[jZZ+U
t"ff5n
8x$;ag
<#6ic}Ou[Y/
!a0O`pY
r!}9%R
5C;0SGYDG
A$A$]6
5=fZg0
UQPX^Y[
^}SD\v
AuAApKu:7
@X fV+rZ/J<xifcZ
x?F}5$
ttW(J=N?<8(
nA_e!M5* ]+6ae
8cV7v_x
}?)LV DpY
d3FVv@D
<,!3~9U
.>!8K
RRP>m3TY
;Cg!$
Pe~,8n=?
vZh]@9H4W&
!]SZej%tVDxmQ
$QPcIM
j\B~<]
T@y=RtU$<
*B%H@1%
(S#_#!C
j<Cf>%;
vtL>T1%abWwu
/=+Hs;\.>$
Y^0k48|*
VVhU.12(
rbRlXq
i?18Q.$
L<.YCwP
5*o lRB$e
t7;t57
^^DVQpzA)qT
';_t|%
V(n1ci
8lh1'q
<0} U_!xV
lLY/7N2
Z2-(FS
'=aOV"x|?[ev
o?qCNw
;QqOHpDc
djR'L&Bv
/?_U[mP?
X\<`dhlpx<<<
y ,4@LPyT`t
4<D<LT\dlyt|^<y
0DyLTh~
v{giv_
_j2r1~#
??cU1<
/!5ACPgRvn/S
WYl/ymV p
?\pr)
XzxrTyp.-eW
1YkiiFile
<-{{+B
S;P[:;of
]Yv&dNexAW5Fm
xpaREnvinmeAfvC*sonm
roVaabg;[F[
dH6l}o
ModCP
mmfK;{VLIsw;[<
I^kedkKk
cFm+De
FliiwF10I{h
E+7Addr/
M<tiBy oWivCha>"xq-
XuZ`tER`
ZYUn}9,
|V+1Unh
S9+*km$T.m-""P
,ASveV
CCUagA`
NbugNrG
Rtl`wi
g1Key9+S
tnRJX9/o_:W=Acqu
N+/tWI{
8afQq6
Wwspdtf
,&1/$-7(
,!*2vw
\K.reJf!;-N"Bw
XPTPSWXaD$j
ADVAPI32.dll
KERNEL32.DLL
ntdll.dll
USER32.dll
RegCloseKey
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
NtClose
wsprintfW
p<a7q/
@'Q3t4jc
:SD4'EX*Qv]
@4Lg8Lq%Z DSG
2}#kR9
,Fe&}_
ri(|Q[K
hFc4FDzg
x!1lf'"\
vjSy^wY"]N-Fo
8c.kC./
xcb$`H
pzgJ9&=*/
SOW?3!zOdG
BsvS}T
ZLnti~
lu?Ogc9v<dS
;p?qB{|S
1/3;lllB
Y2(L s*
j'PS|CAG
0ct|B&
#rRds5
t.?ix_r
'jJb@7RQI8
<mZ|9
"G%&gEM.rL
mRn$-8
5((4ATf
`<w3-Vcm>@sAT0.}VV
0@Y$e*
kdxG/|J%h
fyk;C;
ee7W) Y},
P%(oau}
5}Q8s6
@)e8/
n5"qM^(I.
4t%|(T
vKR/2nx
CQqR,5Ltb2;V3l
j5~wl\
]udDY}8rqgr
\%gC'-0R
l)6`*}o
XQu?ti
_7%YZVe,-
`KcJ/X"e
xFRM6$gb>
VU`eQx~hAW0~
v(+lfDMIh*}S#
.;Dca>P/
rvw]Skq
u'Himddx*l.l@k
RKU3FF~
5|#"A5%_
rQ%;0g
AATN#kvDK
O+3s!xKUNx
KH[Yn75uF,
6-RmB'(
vx)A(*Cy
'1*n~Y=
/;om%Z1
lr#*oj\t523kD|#N
0F?@YQeyrfq$
cRq"(X
y6V\nJ
uCf^1E4
K=;@)_'U
C?27W+<p
F<)/#ZX+B&xf[
+7w~PP
<K!/(s%|
E#uOk(
|N)f9h[bJ
.p l
$9vI#<e`-
$*`:m'_u#
":GWWw<J;S
PC)IMxTrW\=*
De/1vJv
*F;f'r
da2]ZN
(.@.)h4<
js%}s2>
5ZY4Ld
c&C}'e(/7
:]VXX>:
?'Z|,sF 6_
%l_4~r
$3+`=y
ie>IsGtc4
=mMZU}5F
qAMNkz>
4K{,,P
4.xy]r
Z(A3L+]?M)hzrU.
aNW9qk-,vPy~`wL
Nwtra>_E$
,oHcdf
jLNdYw
C-6A2GM
ep9i}1
>o:*}<;w6
{rOz5BB
"UHF7]
";1d,7
XjtPpR
0bo+4|L5P
FB7_l@v],
C1ft7eM
8Q{3}q`
YlT4Z9Iz
s!.8hC
~*V*&*^w
hgK=5w_uTM
6@%>:~G
waL\M_
<<VYs7\
vv75w/8H$V
J\Id$^Or?z
~VsWb0$
avu vq{hk/
45m*~03
E6`;B${[
/URj";4
AgkbNy
D}MD9X
+"9lq?
@q`oQEeV
^}tofL#Y6
1Y>rJQ
>[@!!C"h:
k]*muBKX
zOjG w
};8WN{
6*he.l
.eNB&d
1?UTQ=r
_J|lrk:N
~HLehD_
C*W]]1
d;Xz!
vKa%k(
1!1:(9
2@"(\A)s~\:O
wPd|O\#s
TZsn8z
>5(8!Bs
+uo#G.V
R-jDQ1
l'ah"GO6
#-kwoH
.TXeABgp
pSlC16
RcpfY;WB"1>$
4Lg+BQ
[XOH|dq
U*Uu.$R
&1~%];G_x
HM`2_,)
h6$N|{.B
"TPjA|k+ywp
O&y?afFh
Ew>zhr-
j?!L(6X]GPa
e}}eGu
A!>/ybb\"P*
q\;!ED#
+.KXX)
tTs`GL)
dV3l9
I65j.I
4;XWvp:GprH
8c+*j
w9#HZ$Teg
Kc\K\,
a\ff&SlD
0MN,tYn
{~x$55
]\|M(eX:&sf)
WP3Q?)
*(P'q&%
rv;NNO
%6@A-Y6`h@
I!*Rw2:k
k~\Pd&
Zx%*Z%
S-/Pnt
^}E_8x/T
hma@g
n."4I1Q4L!D
e))_(4
M`94K7zxWR
_Kb?oF6<
\fOwF@E4J%[
H]~cV#ew
HbFJM?5
+"OvLh6fg
\=gz`:j&
*Fc7*kP@~rp
h_H$#BeOO$
QE+Jw:nee
aj{>'$C
d0!QtI.[
KzuQBnZ+)ZuQy-
&3t}E*Nx
2M|':1vB
&8(!oD4
(AQ'Ve.bIC#]
IxSyuX'w
V'tflG6=
opWG][
,i5NV4Tj
IJznb;n#
-@Yr)Z
%eEJ'iV?F8@`$
CDF%# d<*
Y+cBglA4
8&YdN:
OKX^^,
]_**dz
&l.\_w!
/n;{>
@nfeBolbMT
B/.ur;|
|gUe[N7Xk5}aL4zq@n0
M<SKzMq
q [l.7Q(SSO u
n$,0ORl2
&{`6G3xJ
f4.tj5
E60QN;
5ZB!7@
@=+m{!Gyre
[xGmXv F84
NUk .c
:KMD G
2"GhAo~p
_[Mp2B}GPf
e}#1q`
m%K7#]&
1Q~cjGd!
uSzTIx3
eZ%?j)
-aZun6
Ot5UPk
f9Z*_-Bq
E'=.]]0e>E
+n\*MQ/
!sG90Z
>Wtz1w
xuxz(
[F,r 5C\
xq'Z\9
>h@Q5u5
nTUN%Kl]f
CIq1SVSDi
8s`$r<uY
6rOOU{Y
"G)WVFy
MGHGL>y
+$X]6_5
4"?(g2,tb"
4bi5Utvf
jElDik
GL"ueb
DdTLA
IO:hFm
yVcC%Z76W]<)_
Qc>/djo
Q?-si]E
rTXl;]ya
F'UpKHYJ
Gvsq}J
d[_EL.
c q16;3R8#4YBX
uB5FvW$[d
[0<O-k{l&.n
XBp-ZG,6o+;
[vqtXu".
k(oi1r
v&saJOt]Vsm
3p6<SZp]i
v% @gVaS
Y@zXcP5%G
A>D!)(4
f9T_![od@
EqSWj1b
K$=g^&&
eBoj&!/_
W!2+Cy
Z}z;Qaw(!5
bIJ 5v1R?
7cxM}(
Y]r%mbM
u9RZN^P
iS4a_z
M^@?nD
Wb^C /%9
^^A's()WN#1wdeu8T|?<]{P
! -g3L
x;NrE
+z}(_\Ywr$=
cEfNB"V
Dj%gzfX
WnFo?#8tp
Rag-/GGk__
Qj_eck4v\J
<L+z2, :wi`&Y
i%q4Tb
zZ3Q^u|%g,Z
]3P`F7
+\e"oJ
)pe"1.
^7{kTjf
HU{zJAH{! f
OfV2Tk+
C*6<@cE
&;DH28hn*{"Jy
ZQ,N@j0ng}BIK0Ce`2? ^hZ|(m
TlC4k,0;
T:p{n,
E.Wo3w/jCTS

DNS

Name Response Post-Analysis Lookup
dns.msftncsi.com A 131.107.255.255 131.107.255.255
dns.msftncsi.com AAAA fd3e:4f5a:5b81::1 131.107.255.255

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 56933 114.114.114.114 53
192.168.56.101 138 192.168.56.255 138

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.