1.0
低危

140a0c29d55bae8d2606fdba472185e555ee4a302c4b1cdd24a652299c95acc8

140a0c29d55bae8d2606fdba472185e555ee4a302c4b1cdd24a652299c95acc8.exe

分析耗时

193s

最近分析

377天前

文件大小

98.3KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN DOWNLOADER BUBLIK
鹰眼引擎
DACN 0.12
FACILE 1.00
IMCLNet 0.49
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba None 20190527 0.3.0.5
Avast Win32:Malware-gen 20200501 18.4.3895.0
Baidu None 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (D) 20190702 1.0
Kingsoft None 20200503 2013.8.14.323
McAfee Downloader-FWF!7D0F82C7839A 20200503 6.0.6.653
Tencent Malware.Win32.Gencirc.10b59472 20200503 1.0.0.1
行为判定
动态指标
网络通信
与未执行 DNS 查询的主机进行通信 (1 个事件)
host 114.114.114.114
文件已被 VirusTotal 上 61 个反病毒引擎识别为恶意 (50 out of 61 个事件)
ALYac Trojan.GenericKD.1395615
APEX Malicious
AVG Win32:Malware-gen
Acronis suspicious
Ad-Aware Trojan.GenericKD.1395615
AhnLab-V3 HEUR/Fakon.apf.X1353
Antiy-AVL Trojan/Win32.Bublik
Arcabit Trojan.Generic.D154B9F
Avast Win32:Malware-gen
Avira TR/Crypt.XPACK.Gen3
BitDefender Trojan.GenericKD.1395615
BitDefenderTheta Gen:NN.ZexaF.34108.gCZ@aG7cxsci
Bkav W32.AIDetectVM.malware
CAT-QuickHeal TrojanPWS.Zbot.Gen
ClamAV Win.Downloader.Upatre-5744087-0
Comodo TrojWare.Win32.Injector.KXE@5415yx
CrowdStrike win/malicious_confidence_100% (D)
Cybereason malicious.7839a0
Cylance Unsafe
Cyren W32/Trojan.SHKH-0622
DrWeb Trojan.DownLoad.64691
ESET-NOD32 Win32/TrojanDownloader.Small.AAB
Emsisoft Trojan.GenericKD.1395615 (B)
Endgame malicious (high confidence)
F-Prot W32/Trojan3.GLR
F-Secure Trojan.TR/Crypt.XPACK.Gen3
FireEye Generic.mg.7d0f82c7839a0697
Fortinet W32/Small.ABS!tr
GData Trojan.GenericKD.1395615
Ikarus Trojan-Downloader.Win32.Upatre
Invincea heuristic
Jiangmin Trojan/Bublik.gff
K7AntiVirus Trojan ( 0001140e1 )
K7GW Trojan ( 0001140e1 )
Kaspersky Trojan.Win32.Bublik.bkgg
MAX malware (ai score=84)
Malwarebytes Trojan.Email
MaxSecure Trojan.Malware.121218.susgen
McAfee Downloader-FWF!7D0F82C7839A
McAfee-GW-Edition BehavesLike.Win32.Sivis.nt
MicroWorld-eScan Trojan.GenericKD.1395615
Microsoft TrojanDownloader:Win32/Upatre.A
NANO-Antivirus Trojan.Win32.Bublik.cocjal
Panda Trj/Zbot.M
Qihoo-360 HEUR/QVM20.1.F8BC.Malware.Gen
Rising Downloader.Small!8.B41 (TFE:dGZlOgJ7lvWZ5RsfNA)
Sangfor Malware
SentinelOne DFI - Malicious PE
Sophos Troj/Agent-AERJ
Symantec Trojan.Gen
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2013-11-12 14:13:45

PE Imphash

1355c8b0fadb1935e414f47fa976fffa

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00002016 0x00002200 6.4469927459582825
.rdata 0x00004000 0x0000035c 0x00000400 4.365743423683014
.data 0x00005000 0x00000430 0x00000600 4.739945098226479
idata 0x00006000 0x00000358 0x00000400 3.5468724718567737
pdata 0x00007000 0x000000dc 0x00000200 0.0
xdata 0x00008000 0x000004ee 0x00000600 5.495730287182584
.rsrc 0x00009000 0x00002990 0x00002a00 4.681513805480964

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000090ec 0x00002734 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_GROUP_ICON 0x0000b820 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_MANIFEST 0x0000b834 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US None

Imports

Library KERNEL32.dll:
0x504008 GetCurrentProcess
0x50400c GetLastError
0x504010 GetLocalTime
0x504014 GetModuleHandleW
0x504018 FormatMessageW
0x50401c HeapAlloc
0x504020 HeapFree
0x504024 lstrcmpW
0x504028 lstrlenW
0x50402c GetProcessHeap
0x504030 ExitProcess
Library USER32.dll:
0x504038 DefWindowProcW
0x50403c CreateWindowExW
0x504040 EndPaint
0x504044 GetMessageW
0x504048 GetSystemMetrics
0x50404c GetWindowTextW
0x504050 MessageBoxW
0x504054 PostQuitMessage
0x504058 RegisterClassExW
0x50405c SetCursor
0x504060 SetWindowTextW
0x504064 ShowWindow
0x504068 TranslateMessage
0x50406c BeginPaint
0x504070 DispatchMessageW
Library GDI32.dll:
0x504000 TextOutW

L!This program cannot be run in DOS mode.
*%y%y%yy!y%yy
y$yRich%y
`.rdata
@.data
#U-,TP
Uuv3#;
UR$-u|v5
#32hP
3;_\_M
PUWSV5
zVZ3@P
cJUbjj
`UQn`]M
U5EUUM
EEUWSVM
U?@>??>PRQE5
UVSWt$
UUQUUQI
SZyWZ]
+H;ub#
WWRRRRh
SY5+hP
s#JMpod<t
WSV0EU]
n5E#0h
Pd"UAE3
MU~235P
E+33EMMEMME
&3RRVD
}AEUv\gE
UM.3K
sEnPE&
egQHJP
jjAMPjUA
_oMUA5
xOMxUU
R(vMMU
qAYBA3!q8A
UUpkAxv
UjbAE\n$
EE;L"E
QU4.?E
U~j{EM
EVWE@3
jPMj)IU
UU$6F{EUXm
y1MKQMQ
`TQM.[
Y\UyU3AAQ;n
UEQ|AUE
DAEE$'ME
ABOQZUE
]UMUP4&AU4:hMM5=8
PI<9QU0X
oj_4jMX
$MUAN=PAx
LP. |Qj~gMMUU
Y^QMPjlQBMU~U
ExitProcess
FormatMessageW
GetCurrentProcess
GetLastError
GetLocalTime
GetModuleHandleW
GetProcessHeap
HeapAlloc
HeapFree
lstrcmpW
lstrlenW
KERNEL32.dll
BeginPaint
CreateWindowExW
DefWindowProcW
DispatchMessageW
EndPaint
GetMessageW
GetSystemMetrics
GetWindowTextW
MessageBoxW
PostQuitMessage
RegisterClassExW
SetCursor
SetWindowTextW
ShowWindow
TranslateMessage
USER32.dll
TextOutW
GDI32.dll
p@M#[E
!dEYQd.
U+AJAU
PME.BQM
MUgeEUhF(,
kujFXAYm&
heDU5("Mj
QE%0P
\QEjAs#A
M^q$kjj
unARf|UUMs =UAU
1jj)UQ
'VEEUP
PMUAE@
M3-JUE
EEEElJBU
EnjM~rgL
(QUEz3A.
EAsnEM
P&[yEjEM{jM@\EjC
E$%M}_
smKAQU4lPU
yCU6nB@
V;GJ:P
EAjV'U/6
U&mzJj4~U
YEAG*hEA
8|MPSS
UMJ\fyp
xxxyyy
---------F:--SH------------*
. . . . . . . . F:. F:. . ,
- . . . . . . . ,
. 0!0!0!0!0!0!0!0!~t0!WK0!0!dX0!0!0!0!0!0!0!.
0!1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"1"0!
2#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#3#2#
4$I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;I;4$
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGE
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
Error: %s
Failed to create secondary thread
The GLFW library is not initialized
There is no current context
Invalid argument for enum parameter
Invalid value for parameter
Out of memory
The requested client API is unavailable
The requested client API version is unavailable
A platform-specific error occurred
The requested format is unavailable
ERROR: UNKNOWN ERROR TOKEN PASSED TO glfwErrorString
Invalid window size
Invalid window hint
Full screen windows cannot be moved
Invalid window attribute
Invalid cursor mode
Invalid input mode
Invalid input mode
Invalid key
Invalid mouse button
Invalid standard cursor
Invalid joystick
Invalid joystick
Invalid joystick
Invalid joystick
Invalid time
glGetIntegerv
glGetString
glClear
glGetStringi
Entry point retrieval is broken
GL_ARB_debug_output
GL_ARB_compatibility
GL_ARB_robustness
GL_EXT_robustness
GL_KHR_context_flush_control
Failed to retrieve extension string %i
Failed to retrieve extension string
OpenGL ES-CM
OpenGL ES-CM
OpenGL ES-CL
OpenGL ES-CL
OpenGL ES
OpenGL ES
Failed to retrieve context version string
%d.%d.%d
Borland C++ - Copyright 2002 Borland
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
.?AVbad_cast@std@@
.?AVbad_typeid@std@@
.?AV__non_rtti_object@std@@
Ix@oGAkU'9p|B
~QCv)/&D(
uuvHMXB
9;5SM]=];Z] T7aZ%]g']
console_exe
Retrieving module name
PYTHONSCRIPT
Could not locate script resource:
Could not
.?AVtype_info@@
.?AV_Iostream_error_category@std@@
.?AV_System_error_category@std@@
.?AVerror_category@std@@
.?AV_Generic_error_H
Hfloat
double
mahalanobis
[ %10f %10f ]
[ %10f %10f ]
det(M) = %f
det(U) = %f
det(V) = %f
det(S) = %f
cyggcc_s-1.dll
__register_frame_info
cyggcj-11.dll
_Jv_RegisterClasses
__deregister_frame_info
closing %s (fd=%d)
%s==> %s <==
write error
error reading %s
%s: cannot seek to offset %s
%s: cannot seek to relative offset %s
%s: cannot seek to end-relative offset %s
standard input
valid_file_spec (f)
/usr/src/coreutils-8.15-1/src/coreutils-8.15/src/tail.c
%s has become inaccessible
%s has been replaced
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVResolverThunk@sandbox@@
.?AVService64ResolverThunk@sandbox@@
.?AVtype_info@@
.?AVbad_exception@std@@
0123456789abcdef
0123456789ABCDEF
%a %b %d %H:%M:%S %Z %Y
Runtime error at 00000000
?q<Ga7B_
|Wz6@Ek
MS Sans Serif
.?AVCComModule@ATL@@
.?AV?$CAtlModuleT@VCComModule@ATL@@@ATL@@
.?AVCAtlModule@ATL@@
.?AU_ATL_MODULE70@ATL@@
.?AVCAtlException@ATL@@
.?AVCRegObject@ATL@@
.?AUIRegistrarBase@@
.?AUIUnknown@@
.?AV_com_error@@
.?AVtype_info@@
new_graph
Agnodeinfo_t
cluster1
@Borland C++ - Copyright 1999 Inprise Corporation
Syntax: adjust filename scale
Unable to open file!
Invalid file format!
Not enough memory!
Done !
borlndmm
hrdir_b.c: LoadLibrary != mmdll borlndmm failed
borlndmm
@Borlndmm@SysGetMem$qqri
@Borlndmm@SysFreeMem$qqrpv
@Borlndmm@SysReallocMem$qqrpvi
<notype>
id->tpName
xxtype.cpp
xxtype.cpp
xxtype.cpp
tp1->tpName
xxtype.cpp
tp2->tpName
xxtype.cpp
IS_STRUC(base->tpMask)
xxtype.cpp
IS_STRUC(derv->tpMask)
xxtype.cpp
derv->tpClass.tpcFlags & CF_HAS_BASES
xxtype.cpp
((unsigned __far *)vtablePtr)[-1] == 0
xxtype.cpp
<notype>
topTypPtr != 0 && IS_STRUC(topTypPtr->tpMask)
xxtype.cpp
tgtTypPtr != 0 && IS_STRUC(tgtTypPtr->tpMask)
xxtype.cpp
srcTypPtr == 0 || IS_STRUC(srcTypPtr->tpMask)
xxtype.cpp
__isSameTypeID(srcTypPtr, tgtTypPtr) == 0
xxtype.cpp
tgtTypPtr != 0 && __isSameTypeID(topTypPtr, tgtTypPtr) == 0
xxtype.cpp
srcTypPtr
xxtype.cpp
((unsigned __far *)vtablePtr)[-1] == 0
xxtype.cpp
xxtype.cpp
Can't adjust class address (no base class entry found)
!"Can't adjust class address (no base class entry found)"
xxtype.cpp
___CPPdebugHook
Stack Overflow!
),(((((),(((
Error 0
Invalid function number
No such file or directory
Path not found
Too many open files
Permission denied
Bad file number
Memory arena trashed
Not enough memory
Invalid memory block address
Invalid environment
Invalid format
Invalid access code
Invalid data
Bad address
No such device
Attempted to remove current directory
Not same device
No more files
Invalid argument
Arg list too big
Exec format error
Cross-device link
Too many open files
No child processes
Inappropriate I/O control operation
Executable file in use
File too large
No space left on device
Illegal seek
Read-only file system
Too many links
Broken pipe
Math argument
Result too large
File already exists
Possible deadlock
Operation not permitted
No such process
Interrupted function call
Input/output error
No such device or address
Resource temporarily unavailable
Block device required
Resource busy
Not a directory
Is a directory
Directory not empty
Unknown error
(null)
0console_exe
Retrieving module name
PYTHONSCRIPT
Could not locate script resource:
Could not load s2-+
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AV_Iostream_error_category@std@@
.?AV_System_error_category@std@@
.?AVCAbout@@
.?AVCDialog@acWindow@@
.?AVCWindow@acWindow@@
.?AVcImage@@
.?AVCListView@acWindow@@
.?AVCStatic@acWindow@@
.?AVCStatusBar@acWindow@@
.?AVruntime_error@std@@
.?AVexception@std@@
.?AVfailure@ios_base@std@@
.?AVsystem_error@std@@
.?AVbad_cast@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_iostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_stringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV_Facet_base@std@@
.?AVfacet@locale@std@@
.?AUctype_base@std@@
.?AV?$ctype@D@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$numpunct@D@std@@
.?AVCCharWin@@
.?AVCChooseFont@@
.?AVCExportDlg@@
.?AVCIconImageDlg@@
.?AVCImageMgr@@
.?AVcImageWnd@@
Application was compiled with png.h from libpng-%.20s
Application is running with png.c from libpng-%.20s
Incompatible libpng version in application and library
zlib memory error
zlib version error
Unknown zlib error
1.0.6 or earlier
Application was compiled with png.h from libpng-%.20s
Application is running with png.c from libpng-%.20s
The png struct allocated by the application for reading is too small.
The info struct allocated by application for reading is too small.
Application uses deprecated png_read_init() and should be recompiled.
zlib memory
zlib version
Unknown zlib error
Not a PNG file
PNG file corrupted by ASCII conversion
Missing IHDR before IDAT
Missing PLTE before IDAT
Missing IHDR before IDAT
Missing PLTE before IDAT
Ignoring extra png_read_update_info() call; row buffer not reallocated
Invalid attempt to read row data
Not enough image data
Extra compressed data
Decompression error
Too many IDAT's found
Too many IDAT's found
Image is too high to process with png_read_png()
MNG features are not allowed in a PNG datastream
Writing zero-length unknown chunk
Valid palette required for paletted images
Unable to write international text
No IDATs written into file
Unable to write international text
Application was compiled with png.h from libpng-%.20s
Application is running with png.c from libpng-%.20s
Incompatible libpng version in application and library
1.0.6 or earlier
Application was compiled with png.h from libpng-%.20s
Application is running with png.c from libpng-%.20s
The png struct allocated by the application for writing is too small.
The info struct allocated by the application for writing is too small.
Application uses deprecated png_write_init() and should be recompiled.
png_write_info was never called before png_write_row.
zlib error
Unknown row filter for method 0
Can't add Up filter after starting
Can't add Average filter after starting
Can't add Paeth filter after starting
Unknown custom filter method
Unknown filter heuristic method
Only compression windows <= 32k supported by PNG
Only compression windows >= 256 supported by PNG
Compression window is being reset to 512
Only compression method 8 is supported by PNG
Too many bytes for PNG signature.
Potential overflow in png_zalloc()
Unknown freer parameter in png_data_freer.
%d %s %d %02d:%02d:%02d +0000
libpng version 1.2.29 - May 8, 2008
Copyright (c) 1998-2008 Glenn Randers-Pehrson
Copyright (c) 1996-1997 Andreas Dilger
Copyright (c) 1995-1996 Guy Eric Schalnat, Group 42, Inc.
1.2.29
1.2.29
libpng version 1.2.29 - May 8, 2008
Invalid bit depth
Invalid color type
Invalid image width
Invalid image height
Width too large for libpng to process image data.
Ignoring attempt to set all-zero chromaticity values
Ignoring attempt to set negative chromaticity value
Ignoring attempt to set chromaticity value exceeding 21474.83
Ignoring attempt to set all-zero chromaticity values
Ignoring attempt to set negative chromaticity value
Ignoring attempt to set chromaticity value exceeding 21474.83
Limiting gamma to 21474.83
Setting gamma=0
Limiting gamma to 21474.83
Setting negative gamma to zero
Setting gamma=0
Invalid palette size, hIST allocation skipped.
Insufficient memory for hIST chunk data.
Image width or height is zero in IHDR
image size exceeds user limits in IHDR
Invalid image size in IHDR
Width is too large for libpng to process pixels
Invalid bit depth in IHDR
Invalid color type in IHDR
Invalid color type/bit depth combination in IHDR
Unknown interlace method in IHDR
Unknown compression method in IHDR
MNG features are not allowed in a PNG datastream
Unknown filter method in IHDR
Invalid filter method in IHDR
Insufficient memory for pCAL purpose.
Insufficient memory for pCAL units.
Insufficient memory for pCAL params.
Insufficient memory for pCAL parameter.
Invalid palette length
Invalid palette length
Insufficient memory to process iCCP chunk.
Insufficient memory to process iCCP profile.
Insufficient memory to store text
iTXt chunk not supported.
tRNS chunk has out-of-range samples for bit_depth
No memory for sPLT palettes.
Out of memory while processing sPLT chunk
Out of memory while processing sPLT chunk
Out of memory while processing unknown chunk.
Out of memory while processing unknown chunk.
Call to NULL read function
Read Error
It's an error to set both read_data_fn and write_data_fn in the
same structure. Resetting write_data_fn to NULL.
incorrect header check
unknown compression method
invalid window size
unknown compression method
unknown header flags set
header crc mismatch
invalid block type
invalid stored block lengths
too many length or distance symbols
invalid code lengths set
invalid bit length repeat
invalid bit length repeat
invalid literal/lengths set
invalid distances set
invalid literal/length code
invalid distance code
invalid distance too far back
incorrect data check
?33>33>
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVdataflow_exception@iterators@archive@boost@@
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_stringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_iostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AVruntime_error@std@@
.?AVclone_base@exception_detail@boost@@
.?AVplaceholder@any@boost@@
.?AVptree_error@property_tree@boost@@
.?AVptree_bad_data@property_tree@boost@@
.?AVptree_bad_path@property_tree@boost@@
.?AVbad_lexical_cast@boost@@
.?AVbad_cast@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AVexception@boost@@
.?AV?$numpunct@D@std@@
.?AVfacet@locale@std@@
.?AU?$error_info_injector@Vbad_lexical_cast@boost@@@exception_detail@boost@@
.?AU?$error_info_injector@Vptree_bad_path@property_tree@boost@@@exception_detail@boost@@
.?AU?$error_info_injector@Vptree_bad_data@property_tree@boost@@@exception_detail@boost@@
.?AV?$clone_impl@U?$error_info_injector@Vbad_lexical_cast@boost@@@exception_detail@boost@@@exception_detail@boost@@
.?AV?$clone_impl@U?$error_info_injector@Vptree_bad_path@property_tree@boost@@@exception_detail@boost@@@exception_detail@boost@@
.?AV?$clone_impl@U?$error_info_injector@Vptree_bad_data@property_tree@boost@@@exception_detail@boost@@@exception_detail@boost@@
.?AVfile_parser_error@property_tree@boost@@
.?AU?$error_info_injector@Vxml_parser_error@xml_parser@property_tree@boost@@@exception_detail@boost@@
.?AVxml_parser_error@xml_parser@property_tree@boost@@
.?AV?$holder@V?$string_path@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@U?$id_translator@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@property_tree@boost@@@property_tree@boost@@@any@boost@@
.?AV?$string_path@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@U?$id_translator@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@property_tree@boost@@@property_tree@boost@@
.?AV?$holder@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@any@boost@@
.?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_ofstream@DU?$char_traits@D@std@@@std@@
.?AV?$clone_impl@U?$error_info_injector@Vxml_parser_error@xml_parser@property_tree@boost@@@exception_detail@boost@@@exception_detail@boost@@
.$$BY09$$CBD
.$$BY00$$CBD
.$$BY0CK@$$CBD
.?AVparse_error@rapidxml@detail@property_tree@boost@@
.?AV?$basic_ifstream@DU?$char_traits@D@std@@@std@@
.?AVbad_exception@std@@
.?AVlogic_error@std@@
.?AVsp_counted_base@detail@boost@@
.?AVthread_exception@boost@@
.?AVlock_error@boost@@
.?AVthread_resource_error@boost@@
.?AUthread_data_base@detail@boost@@
.?AVvalue_semantic@program_options@boost@@
.?AVtyped_value_base@program_options@boost@@
.?AVabstract_variables_map@program_options@boost@@
.?AV?$sp_counted_impl_p@Udir_itr_imp@detail@filesystem3@boost@@@detail@boost@@
.?AV?$sp_counted_impl_p@Urecur_dir_itr_imp@detail@filesystem3@boost@@@detail@boost@@
.?AVbad_any_cast@boost@@
.?AV?$vector@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$allocator@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@std@@
.?AV?$sp_counted_impl_p@V?N@
.?AVtype_info@@
.?AV_Iostream_error_category@std@@
.?AV_System_error_category@std@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
Failed at line %d
Usage: %s <old root> <new root> <file> [<old_oldrootlen>]
Error flushing to %s ?!
Error writing to %s ?!
Could not open fil
.?AVListException@@
.?AVListIndexOutOfRangeException@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AV_Iostream_error_category@std@@
.?AV_System_error_category@std@@
Kramivo
Jkadsuxicni
E:\DOCUME~1\NILESH~1.SER\LOCALS~1\Temp\7zO1C0.tmp\HMRC_Message.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MHg1n4mXg.exe
C:\wwkVM4pG.exe
C:\3Sq4mdhY.exe
C:\6WzVbaZA.exe
C:\M6jQGzhb.exe
@@@@@@
((((( H
@@@@@@@@@@@@@@@@@
%.*d@@@@@@@@@@@@@@@@
@@@@@@@
@@@@@@@
@@@@@@@@
@@@@@@@@@
@@@@@@@
(null)
((((( H
C:\Users\admin\Downloads\ftc.exe
C:\a001ab701d02e6f16523320a9380b2ed7cc147436a45158588ea891aa1fdbf92
C:\Users\admin\Downloads\ftc.exe
C:\Documents and Settings\Administrator\Desktop\yQKrzIFB.exe
C:\1849b87c7517affac374693359cab8e6b8d8e48f45e78f6d4795fc6f4e438de6
C:\Users\Petra\AppData\Local\Temp\ftc.pe32
C:\d0471083bc916892b8438089d9d43763c08432b106c3343e5c7d35d4bf4fa44e
C:\Users\Petra\AppData\Local\Temp\ftc.pe32
C:\Users\admin\Downloads\910b920dec9ec44a_ftc.exe
C:\b22251df51557c8b0f8dc0d86789fec6836234fd53a7a8e18dbbc3569fde6cb8
C:\Users\admin\Downloads\ftc.exe
C:\1d902357029dbd89e8c9272d460a734eded050bd97088d44e0785527a0684498
C:\Users\admin\Downloads\ftc.exe
C:\3b3dde22b254ef09f1d8d3cce979073a6b07fb00e11883e01ad982e79c8fd021
C:\db29b0e6289c14ae4c6f506643a7dd7f9ac90368612990734893756183071bfe
C:\5d383623f7a3555ec0e02f59c8c7c9bca9ae315a5e3692b02c8f9d2297c40a3b
C:\Users\admin\Downloads\ftc.exe
C:\224d2e647b4396c0118c710f74a8379b22629f017174e078fdba7b75be9c0f7d
C:\83bc0f36b2f28f1a643ca3c2383ab79a79121e427aa8e4221a52e0f0743f2e96
C:\Documents and Settings\luser\Desktop\lCeBayVl.exe
C:\Users\admin\Downloads\beb5f928a99071d7bb802c04fc2efdc46225ce99f20a899792ac532b3548e3f4.exe
C:\Documents and Settings\Administrator\Desktop\1L8Y9V7j.exe
C:\775ec69078c70405a039ba1386b8ed9c0151f7f200945ae4228e9ce1bdf2f479
C:\Users\admin\Downloads\ftc.exe
C:\dce0fda9307333c83996a75793bd4d242097bd725e3905cfe1aeebf51a340c6d
C:\8f1e8581826ee191c907b1256be67f63b646ffd8308c4780502419602ba3b91e
C:\Users\admin\Downloads\ftc.exe
C:\09de25cf79c2745eda04c0c1980b5d272d63e49a55fb1a07bddedcce19a6f200
C:\e931dd10de00fbff0fbb808f9a33b045578bea66529967cbe79242806f32a339
C:\Users\admin\Downloads\ftc.exe
C:\0ed4c0079cf366659c053c45e40c59fb67b00cb70c84b822577211a31300b43b
C:\Users\admin\Downloads\ftc.exe
C:\Documents and Settings\Administrator\Desktop\TctuVMOe.exe
C:\e230c67b65b71536768b855715042f2561ce6e3af849140fed9c1da3eb4f4f5c
C:\b8cea30e1c5f3d9c24d4b92818d560a6ed2aefd4331a43e21ee6c4277e3e0bee
C:\b44f69a4e0f45a388182f2e4b2d57b16219f4e44958b870aae81dc4897bb3bb6
c:\task\1C9AD4A6914312B863BAED51504AFE1E.exe
C:\f489ce85a0da05c093e77e0b97b6793feba00524d4088984bd2dd138d2a654ca
C:\Users\admin\Downloads\ftc.exe
C:\c6793705797f5959ea9b5d34eb97c8fcb77d066629ec69e08f6472588aa01eca
C:\5491f2cdee7a959c4d0e28fd7ddbd07222b47029d79a948d663597525e5d86a2
C:\Documents and Settings\Administrator\Desktop\VwDWd5r7.exe
C:\800ee1e88a533f798a41f4ecb3045c51f81ac66ac65846ade2880bfab86b72e0
C:\Documents and Settings\Administrator\Desktop\K2vHIirD.exe
C:\Users\admin\Downloads\0d34e34bb11450d6c8f1da95cbfe95af5d012e38a8095595a0288679e82ba719.exe
C:\a6e73ced045280eb60b31fdcc26d6d058e4e372e47d87f6afbbd40ce704ffbfe
c:\task\A540A9F263A23753322634BC7EE8D811.exe
c:\task\4DAB656EC2F05F202130DE734EBA851F.exe
c:\task\7DC60B9DD24FA42F169B9B1A29676A22.exe
c:\task\49B897C19B4B53D21DD04B30993AF7A1.exe
c:\task\6928170176A4766ABB525ACDC40392BF.exe
C:\83377e6aa502c29dc0791f0848a755043add8bc27dbe6c4c8190ce896bd439af
C:\fb4a3aca92b40f219bd3c387ee97c592fcb2028112fc7bf06eed70a1ae567d61
C:\b4681da1cb8f3a10b08ab4b5832d3ac302e65b1c05c80cf3e3187c28f4ccf3a6
C:\Users\admin\Downloads\ftc.exe
C:\Users\admin\Downloads\7dd2b1db6f83048d1aea68acd8bd0fd5d932b0f31ac2e1a04f1519c7f3526ba2.exe
C:\ef4dbcf3f2628ac3c72c0af1caf0bcb364f710a69ceece1b4ea7e820497300bf
C:\Users\Petra\AppData\Local\Temp\ftc.pe32
C:\b04fbb9e1cbd7db4c5c255c6fc94aa44f61be5dcfff56a59f64beeba7c4f8bb2
C:\e9135e87aa290deb44fbb685be49ed23623b62a68d46cf751c5a4ebb273db5cd
C:\a99c6967221baa698ad0a092ebb5f93b78fe9cc2edfc47720c9d62644d2d45b5
C:\5b899f17f6f31e3ad60115e9d522bf793d6e4fd63569167e9ec81555cf760415
C:\Users\Petra\AppData\Local\Temp\ftc.pe32
C:\0bcbc56ea34c9bf340b0e58543c55559d8f8ac1cdc752ccdac576d176ea2e597
C:\c74f2e785f6335d4f69017c2aa16c0f249eb97464bcdd9b8bd5ca6da5be10624
C:\Users\Petra\AppData\Local\Temp\ftc.pe32

DNS

Name Response Post-Analysis Lookup
dns.msftncsi.com A 131.107.255.255 131.107.255.255
dns.msftncsi.com AAAA fd3e:4f5a:5b81::1 131.107.255.255

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 56933 114.114.114.114 53
192.168.56.101 138 192.168.56.255 138

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.