| section | .lol\x0a\x09\x090 |
| section | .lol\x0a\x09\x091 |
| file | c:\PerfLogs .exe |
| file | c:\Windows .exe |
| file | c:\VC_RED.cab .exe |
| file | c:\pcwddvjebc .exe |
| file | c:\ProgramData .exe |
| file | c:\Documents and Settings .exe |
| file | c:\$Recycle.Bin .exe |
| file | c:\install.exe .exe |
| file | c:\eula.2052.txt .exe |
| file | c:\globdata.ini .exe |
| file | c:\360Downloads .exe |
| file | c:\gcoxh .exe |
| file | c:\install.res.2052.dll .exe |
| file | c:\Users .exe |
| file | c:\Python27 .exe |
| file | c:\Recovery .exe |
| file | C:\ProgramData\wxxjkk.exe |
| file | c:\vcredist.bmp .exe |
| file | c:\System Volume Information .exe |
| file | c:\VC_RED.MSI .exe |
| file | c:\Program Files (x86) .exe |
| file | c:\Program Files .exe |
| file | c:\install.ini .exe |
| file | c:\pagefile.sys .exe |
| file | C:\ProgramData\wxxjkk.exe |
| section | {'name': '.lol\\x0a\\x09\\x091', 'virtual_address': '0x0004b000', 'virtual_size': '0x00021a6d', 'size_of_data': '0x00021c00', 'entropy': 7.798763438893083} | entropy | 7.798763438893083 | description | 发现高熵的节 | |||||||||
| section | {'name': '.rsrc', 'virtual_address': '0x0006d000', 'virtual_size': '0x000067b8', 'size_of_data': '0x00006800', 'entropy': 6.96670500943082} | entropy | 6.96670500943082 | description | 发现高熵的节 | |||||||||
| entropy | 1.0 | description | 此PE文件的整体熵值较高 | |||||||||||
| host | 114.114.114.114 | |||
| reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Microsoftᆴ Windowsᆴ Operating System | reg_value | C:\ProgramData\wxxjkk.exe | ||||||
| Name | Virtual Address | Virtual Size | Size of Raw Data | Entropy |
|---|---|---|---|---|
| .text | 0x00001000 | 0x0003be78 | 0x00000000 | 0.0 |
| .data | 0x0003d000 | 0x00000260 | 0x00000000 | 0.0 |
| .rdata | 0x0003e000 | 0x000024a8 | 0x00000000 | 0.0 |
| .bss | 0x00041000 | 0x00004890 | 0x00000000 | 0.0 |
| .idata | 0x00046000 | 0x000008a4 | 0x00000000 | 0.0 |
| .lol\x0a\x09\x090 | 0x00047000 | 0x0000364a | 0x00000000 | 0.0 |
| .lol\x0a\x09\x091 | 0x0004b000 | 0x00021a6d | 0x00021c00 | 7.798763438893083 |
| .rsrc | 0x0006d000 | 0x000067b8 | 0x00006800 | 6.96670500943082 |
| Name | Offset | Size | Language | Sub-language | File type |
|---|---|---|---|---|---|
| RT_ICON | 0x00072fec | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x00072fec | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x00072fec | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x00072fec | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x00072fec | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x00072fec | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x00072fec | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x00072fec | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x00072fec | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_GROUP_ICON | 0x00073454 | 0x00000084 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_VERSION | 0x000734d8 | 0x000002e0 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| IP |
|---|
| 114.114.114.114 |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| dns.msftncsi.com | A 131.107.255.255 | 131.107.255.255 |
| dns.msftncsi.com | AAAA fd3e:4f5a:5b81::1 | 131.107.255.255 |
No TCP connections recorded.
| Source | Source Port | Destination | Destination Port |
|---|---|---|---|
| 192.168.56.101 | 53179 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 49642 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 137 | 192.168.56.255 | 137 |
| 192.168.56.101 | 61714 | 114.114.114.114 | 53 |
| 192.168.56.101 | 56933 | 114.114.114.114 | 53 |
| 192.168.56.101 | 138 | 192.168.56.255 | 138 |
No HTTP requests performed.
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts
| Name | b0334ae97eac7a29_programdata .exe |
|---|---|
| Filepath | C:\ProgramData .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | c579cbe5d7eabf39ef1ea8df59b2c3ef |
| SHA1 | 0f37eb5638dad1cf3fb2a2b2ac42ea833412a463 |
| SHA256 | b0334ae97eac7a29ac750b76a8c9f8bb79af30370ad0cd8be84a6e8263a86124 |
| CRC32 | CCFA79A5 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 748e26fbb9a068db_vcredist.bmp .exe |
|---|---|
| Filepath | C:\vcredist.bmp .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 9b0908e2cbca8451e0c0f479772c53de |
| SHA1 | f8ca37695be10ce648355fc1830c464a4e8be62c |
| SHA256 | 748e26fbb9a068db81fb68d24786f4dce6cfab1d1d43f316e11cd21ebe24c21c |
| CRC32 | 3261A441 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 3f87975224a45e4a_windows .exe |
|---|---|
| Filepath | C:\Windows .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | d8c583711bdb067ded134c794f86cda0 |
| SHA1 | 470544a4cb464a9a95a60b59ee8cc374bbc5d3a4 |
| SHA256 | 3f87975224a45e4a1023e580163440e8b6ba1a0fe0d7368089c844f8318349d1 |
| CRC32 | D0F5FAEF |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 6b7de58b3af491fc_program files .exe |
|---|---|
| Filepath | C:\Program Files .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 9d5f3e1b665f6bdbcc12d36cd1376a20 |
| SHA1 | 5f8fe7d2ef226b100481ddeda734b61a557d8abe |
| SHA256 | 6b7de58b3af491fc9d8fd15b90e5c8edaec0c8d3bbdc1421e1a814fedfb1d8a4 |
| CRC32 | F283FFE1 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 5c191320854e919f_wxxjkk.exe |
|---|---|
| Filepath | C:\ProgramData\wxxjkk.exe |
| Size | 258.5KB |
| Processes | 844 (0248c50ade6eafcfb097190e6c3dabbf9f835212f1c7a07a12a7f71e909a0109.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 01fe4c2c22f2f08853448735c4c94fb7 |
| SHA1 | 295bf92af934bf79576b5dcd1d27ab8c92d0062d |
| SHA256 | 5c191320854e919fefad79599076ddb8f4b4f7bc162bad2edd42be62bf9ccfdb |
| CRC32 | 21CD5116 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 451a63e5cf92b3de_install.exe .exe |
|---|---|
| Filepath | C:\install.exe .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 532718f86adae5b79dc808ec4b169e9a |
| SHA1 | 318f0456f408830adb6ad159e62bf26082376eca |
| SHA256 | 451a63e5cf92b3de86eb3c14ecc7b3ed4c8d6c22f08129d1dc10b232cd87377d |
| CRC32 | 8018A95B |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 93aedcec87bd5ab3_vc_red.cab .exe |
|---|---|
| Filepath | C:\VC_RED.cab .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 9eb833013cdfc3f8052c485093f98c0d |
| SHA1 | 19365d552b6819d838ebc7b0ce13d4ba93895f6f |
| SHA256 | 93aedcec87bd5ab34969555a02b909ddc5b40724cdf724cf7a1b1dce00d02bcc |
| CRC32 | 4A80EE6E |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | fc44606abeba0ceb_documents and settings .exe |
|---|---|
| Filepath | C:\Documents and Settings .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 92863f41cb6805f1d284332f3722fc58 |
| SHA1 | d6fb96c3fae84df3edb14ebdd799d6c7d544cb28 |
| SHA256 | fc44606abeba0ceb8d5b8d2613dd7f30c50819838e7a0150d04668df067493d5 |
| CRC32 | 385A8F2A |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | cff10c61d34bed2c_recovery .exe |
|---|---|
| Filepath | C:\Recovery .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | a97623ae37e4914d27f44b90ed80b1f5 |
| SHA1 | 9151d489726dddc81723cac75482dae46021f55c |
| SHA256 | cff10c61d34bed2c7ebb3549d84096d4ac59ed4264088847a7cde643033d4d00 |
| CRC32 | 0D9FD782 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 51d17de7f3f1e03f_install.res.2052.dll .exe |
|---|---|
| Filepath | C:\install.res.2052.dll .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | d04c60fd70d7586e0850ca30439590cf |
| SHA1 | d08a196113c69936016fb5f53e5aadb95d209075 |
| SHA256 | 51d17de7f3f1e03f32b74878421f642c929c85a4108ba17a753f52a06f83a133 |
| CRC32 | 36BE9251 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 495b5d194abba616_eula.2052.txt .exe |
|---|---|
| Filepath | C:\eula.2052.txt .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 548647476bd862dd3c5c8ddcb488a00a |
| SHA1 | 4a183e6a5a35910be4c4c00a6a4362f8f21f718c |
| SHA256 | 495b5d194abba61683e6e4af781f4d6a0ac47777fc8a18be37f90ef28092bd48 |
| CRC32 | 2765C4D5 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | e3b0c44298fc1c14_Miraa |
|---|---|
| Size | 0.0B |
| Type | empty |
| MD5 | d41d8cd98f00b204e9800998ecf8427e |
| SHA1 | da39a3ee5e6b4b0d3255bfef95601890afd80709 |
| SHA256 | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 |
| CRC32 | 00000000 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 19efebb704dc7fdd_vc_red.msi .exe |
|---|---|
| Filepath | C:\VC_RED.MSI .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 080cda2229655e0b2eccca2806659df6 |
| SHA1 | 06117712e731b9ed8b3fe841ed2b9406b82a7d53 |
| SHA256 | 19efebb704dc7fdd25271990844fabfd56ae9eaa651e1bc27f10eb4ab471c124 |
| CRC32 | CEFD1F36 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 047c1e4158ca885a_users .exe |
|---|---|
| Filepath | C:\Users .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | d945a51bf849ef763c36b707a6c575c7 |
| SHA1 | 0a9aa49ebae285068e96476b5862820aa0e00635 |
| SHA256 | 047c1e4158ca885a3b518ef52d4e84ddb2e2f38658490238b49f1982823a02a2 |
| CRC32 | 750192EF |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 4d2c9d8f6ba422c7_$recycle.bin .exe |
|---|---|
| Filepath | C:\$Recycle.Bin .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | b248575c1b210c78863f4226f27c0362 |
| SHA1 | 3c5c50371460b01875f563c3de42fc649552e690 |
| SHA256 | 4d2c9d8f6ba422c77f7dc8d87caf383434045460245705bb80520877a8c83c63 |
| CRC32 | 862FF722 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | f8d2c17bdf34ccfb_mira.h |
|---|---|
| Filepath | C:\ProgramData\Saaaalamm\Mira.h |
| Size | 136.7KB |
| Processes | 844 (0248c50ade6eafcfb097190e6c3dabbf9f835212f1c7a07a12a7f71e909a0109.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | cb4c442a26bb46671c638c794bf535af |
| SHA1 | 8a742d0b372f2ddd2d1fdf688c3c4ac7f9272abf |
| SHA256 | f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 |
| CRC32 | AEE8DC88 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 5e0643520669d142_perflogs .exe |
|---|---|
| Filepath | C:\PerfLogs .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 245a752f469aaa32680601b02bbc3afe |
| SHA1 | 2eb87a444871a98958da604b650fbd53ebc3365f |
| SHA256 | 5e0643520669d142dd5f789cb82ad10b19d854bbca3fb065b829ffc24c6a12e8 |
| CRC32 | 19C4B40D |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 8bf1f3cd883d7666_pagefile.sys .exe |
|---|---|
| Filepath | C:\pagefile.sys .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | cc5f512c0a1fe9d4699a194031613745 |
| SHA1 | 0f1caab8320a7b98582c53f1bda9b083b8f13b7b |
| SHA256 | 8bf1f3cd883d76665cd88758e7ca5ccd95657ad218e55444250fe0470f86ebab |
| CRC32 | C9F8400F |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 6797f79258e89b0c_python27 .exe |
|---|---|
| Filepath | C:\Python27 .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | e3e59acc6d43dda88ba625b85cd3ecaf |
| SHA1 | d5dbaa6735b8bf65ff7ca407208e608bf5acf0df |
| SHA256 | 6797f79258e89b0cc4ba282d791acf5cc04848bfad1f16ebe15876b5db7e7a57 |
| CRC32 | 1886F762 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | f892a05ba8e537c1_gcoxh .exe |
|---|---|
| Filepath | C:\gcoxh .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | ab44cbfe37a09757d7701b3f2ca1393e |
| SHA1 | 6006f5dd1991600effaccb35a95cdb07730e3bae |
| SHA256 | f892a05ba8e537c15e8e62aa221b391c2763de37718fdb8652fce8291e554389 |
| CRC32 | DB602166 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | e81de85dc1771fe0_360downloads .exe |
|---|---|
| Filepath | C:\360Downloads .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 7e970d094cac229d730b6fef4ca64461 |
| SHA1 | 40c8eb31d76a7ce94cd8797b75f4105b615875d4 |
| SHA256 | e81de85dc1771fe06bdc17bcce82b1064901aa6f0b8d40b2b67526668cffcfc5 |
| CRC32 | 4B343284 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 5a285ec92f8ae4b6_install.ini .exe |
|---|---|
| Filepath | C:\install.ini .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | cdb1224f18f1c130a805cccdc06545d7 |
| SHA1 | e1ace61c4500b9fcccf0a9ce2ef11db1d4499656 |
| SHA256 | 5a285ec92f8ae4b69c571e1cea2c9e38fbdbcdf2828a387186c2014b3e6c525e |
| CRC32 | 5C85F8CB |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | b770674bcc5274e9_program files (x86) .exe |
|---|---|
| Filepath | C:\Program Files (x86) .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | f946244eb076194fab4652ed32878544 |
| SHA1 | f4bb45595bccdc680fddeacc3f2ece02efa7e209 |
| SHA256 | b770674bcc5274e91a7eb4bbd7718896c77027eb262c252276197f45b3c71fac |
| CRC32 | B4FA1DE2 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | f9388d375a09ec50_pcwddvjebc .exe |
|---|---|
| Filepath | C:\pcwddvjebc .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 59085e6a9ae0ed546540d25300c91746 |
| SHA1 | 4a99b530415261962865cb67768b62a3d31453b5 |
| SHA256 | f9388d375a09ec50db74e62a96636567f5fc097b75e3b3d5c1be10602519b5b5 |
| CRC32 | D9231094 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 8245481e5f734388_system volume information .exe |
|---|---|
| Filepath | C:\System Volume Information .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | f96d2367aeffbf17881927c3ee1824b6 |
| SHA1 | 0e7245e5b8a804d4346d6adc034d145788e5a8bb |
| SHA256 | 8245481e5f7343888a3f4a1088ca325f6ac15776bc3dd972bb61e956f65504c7 |
| CRC32 | 18768D1E |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 19c6c2c93299e7eb_globdata.ini .exe |
|---|---|
| Filepath | C:\globdata.ini .exe |
| Size | 395.2KB |
| Processes | 2736 (wxxjkk.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 32bd683ff9f308cbef390fdd88e69421 |
| SHA1 | 9c001c8543cbd6f68e8f32d1bb7a23a590526b65 |
| SHA256 | 19c6c2c93299e7eb6074ae40efe2c5f1103cc06ab72e7a8aa773550a5bdc4302 |
| CRC32 | 62FF7848 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |