3.2
中危

0381a28bab68001828580a925d01e0fd6dcc6ffbfd0a3f017fbba365268c34ed

8b4c02511fce1d8fd0059d4e9a2ce382.exe

分析耗时

140s

最近分析

文件大小

2.2MB
静态报毒 动态报毒 4TF6CL8NLLC AI SCORE=100 ARTEMIS ATTRIBUTE CONFIDENCE DELF EBHC GEN@1QLOJK GENERICKD GENETIC HIGHCONFIDENCE JACKSERVN KRSERV NBEO OCCAMY R002C0PFQ19 RWWI SUSPICIOUS PE XDUTN 更多
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
McAfee Artemis!8B4C02511FCE 20190802 6.0.6.653
Alibaba Trojan:Win32/JackServn.9c66a700 20190527 0.3.0.5
Baidu 20190318 1.0.0.2
Kingsoft 20190802 2013.8.14.323
Tencent Win32.Trojan.Generic.Ebhc 20190802 1.0.0.1
CrowdStrike win/malicious_confidence_70% (W) 20190212 1.0
行为判定
动态指标
Allocates read-write-execute memory (usually to unpack itself) (1 个事件)
Time & API Arguments Status Return Repeated
1620962047.735125
NtAllocateVirtualMemory
process_identifier: 2772
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003f0000
success 0 0
网络通信
Communicates with host for which no DNS query was performed (1 个事件)
host 172.217.24.14
Generates some ICMP traffic
File has been identified by 42 AntiVirus engines on VirusTotal as malicious (42 个事件)
MicroWorld-eScan Trojan.GenericKD.32115577
FireEye Generic.mg.8b4c02511fce1d8f
CAT-QuickHeal Trojan.Agent
McAfee Artemis!8B4C02511FCE
K7AntiVirus Trojan ( 7000000f1 )
Alibaba Trojan:Win32/JackServn.9c66a700
K7GW Trojan ( 7000000f1 )
Cybereason malicious.11fce1
Arcabit Trojan.Generic.D1EA0B79
Cyren W32/Trojan.NBEO-5402
Symantec ML.Attribute.HighConfidence
APEX Malicious
Paloalto generic.ml
BitDefender Trojan.GenericKD.32115577
ViRobot Trojan.Win32.Z.Krserv.2312704
Rising Trojan.Delf!8.67 (TFE:5:4TF6CL8nllC)
Ad-Aware Trojan.GenericKD.32115577
Emsisoft Trojan.GenericKD.32115577 (B)
Comodo TrojWare.Win32.Spy.Banker.Gen@1qlojk
F-Secure Trojan.TR/JackServn.xdutn
VIPRE Trojan.Win32.Generic!BT
McAfee-GW-Edition BehavesLike.Win32.Backdoor.vh
Sophos Mal/Generic-S
Ikarus Trojan.Win32.Jackservn
Jiangmin Trojan.KrServ.bg
Avira TR/JackServn.xdutn
MAX malware (ai score=100)
Microsoft Trojan:Win32/Occamy.C
AegisLab Trojan.Win32.Rwwi.4!c
AhnLab-V3 Trojan/Win32.Agent.C3312525
Acronis suspicious
VBA32 Trojan.KrServ
ALYac Trojan.GenericKD.32115577
ESET-NOD32 a variant of Win32/Delf.TXA
TrendMicro-HouseCall TROJ_GEN.R002C0PFQ19
Tencent Win32.Trojan.Generic.Ebhc
SentinelOne DFI - Suspicious PE
GData Trojan.GenericKD.32115577
AVG Win32:Trojan-gen
Panda Trj/Genetic.gen
CrowdStrike win/malicious_confidence_70% (W)
Qihoo-360 Win32/Trojan.64e
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2019-01-25 20:34:38

Imports

Library oleaut32.dll:
0x55aaf4 SysFreeString
0x55aaf8 SysReAllocStringLen
0x55aafc SysAllocStringLen
Library advapi32.dll:
0x55ab04 RegQueryValueExW
0x55ab08 RegOpenKeyExW
0x55ab0c RegCloseKey
Library user32.dll:
0x55ab14 MessageBoxA
0x55ab18 CharNextW
0x55ab1c LoadStringW
Library kernel32.dll:
0x55ab24 Sleep
0x55ab28 VirtualFree
0x55ab2c VirtualAlloc
0x55ab30 lstrlenW
0x55ab34 lstrcpynW
0x55ab38 VirtualQuery
0x55ab40 GetTickCount
0x55ab44 GetSystemInfo
0x55ab48 GetVersion
0x55ab4c CompareStringW
0x55ab50 IsDBCSLeadByteEx
0x55ab54 IsValidLocale
0x55ab58 SetThreadLocale
0x55ab64 GetLocaleInfoW
0x55ab68 WideCharToMultiByte
0x55ab6c MultiByteToWideChar
0x55ab70 GetConsoleOutputCP
0x55ab74 GetConsoleCP
0x55ab78 GetACP
0x55ab7c LoadLibraryExW
0x55ab80 GetStartupInfoW
0x55ab84 GetProcAddress
0x55ab88 GetModuleHandleW
0x55ab8c GetModuleFileNameW
0x55ab90 GetCommandLineW
0x55ab94 FreeLibrary
0x55ab98 GetLastError
0x55aba0 RtlUnwind
0x55aba4 RaiseException
0x55aba8 ExitProcess
0x55abac ExitThread
0x55abb0 SwitchToThread
0x55abb4 GetCurrentThreadId
0x55abb8 CreateThread
0x55abcc FindFirstFileW
0x55abd0 FindClose
0x55abd4 WriteFile
0x55abd8 SetFilePointer
0x55abdc SetEndOfFile
0x55abe0 ReadFile
0x55abe4 GetFileType
0x55abe8 GetFileSize
0x55abec CreateFileW
0x55abf0 GetStdHandle
0x55abf4 CloseHandle
Library kernel32.dll:
0x55abfc GetProcAddress
0x55ac00 RaiseException
0x55ac04 LoadLibraryA
0x55ac08 GetLastError
0x55ac0c TlsSetValue
0x55ac10 TlsGetValue
0x55ac14 LocalFree
0x55ac18 LocalAlloc
0x55ac1c GetModuleHandleW
0x55ac20 FreeLibrary
Library user32.dll:
0x55ac28 SetClassLongW
0x55ac2c GetClassLongW
0x55ac30 SetWindowLongW
0x55ac34 GetWindowLongW
0x55ac38 CreateWindowExW
0x55ac3c WindowFromPoint
0x55ac40 WaitMessage
0x55ac44 UpdateWindow
0x55ac48 UnregisterClassW
0x55ac4c UnhookWindowsHookEx
0x55ac50 TranslateMessage
0x55ac58 TrackPopupMenu
0x55ac60 ShowWindow
0x55ac64 ShowScrollBar
0x55ac68 ShowOwnedPopups
0x55ac6c ShowCaret
0x55ac70 SetWindowRgn
0x55ac74 SetWindowsHookExW
0x55ac78 SetWindowTextW
0x55ac7c SetWindowPos
0x55ac80 SetWindowPlacement
0x55ac84 SetTimer
0x55ac88 SetScrollRange
0x55ac8c SetScrollPos
0x55ac90 SetScrollInfo
0x55ac94 SetRect
0x55ac98 SetPropW
0x55ac9c SetParent
0x55aca0 SetMenuItemInfoW
0x55aca4 SetMenu
0x55aca8 SetForegroundWindow
0x55acac SetFocus
0x55acb0 SetCursorPos
0x55acb4 SetCursor
0x55acb8 SetClipboardData
0x55acbc SetCapture
0x55acc0 SetActiveWindow
0x55acc4 SendMessageA
0x55acc8 SendMessageW
0x55accc ScrollWindow
0x55acd0 ScreenToClient
0x55acd4 RemovePropW
0x55acd8 RemoveMenu
0x55acdc ReleaseDC
0x55ace0 ReleaseCapture
0x55acec RegisterClassW
0x55acf0 RedrawWindow
0x55acf4 PtInRect
0x55acf8 PostThreadMessageW
0x55acfc PostQuitMessage
0x55ad00 PostMessageW
0x55ad04 PeekMessageA
0x55ad08 PeekMessageW
0x55ad0c OpenClipboard
0x55ad10 OffsetRect
0x55ad1c MessageBoxW
0x55ad20 MessageBeep
0x55ad24 MapWindowPoints
0x55ad28 MapVirtualKeyW
0x55ad2c LoadStringW
0x55ad30 LoadKeyboardLayoutW
0x55ad34 LoadIconW
0x55ad38 LoadCursorW
0x55ad3c LoadBitmapW
0x55ad40 KillTimer
0x55ad44 IsZoomed
0x55ad48 IsWindowVisible
0x55ad4c IsWindowUnicode
0x55ad50 IsWindowEnabled
0x55ad54 IsWindow
0x55ad58 IsIconic
0x55ad5c IsDialogMessageA
0x55ad60 IsDialogMessageW
0x55ad64 IsChild
0x55ad68 InvalidateRect
0x55ad6c InsertMenuItemW
0x55ad70 InsertMenuW
0x55ad74 InflateRect
0x55ad78 HideCaret
0x55ad80 GetWindowTextW
0x55ad84 GetWindowRect
0x55ad88 GetWindowPlacement
0x55ad8c GetWindowDC
0x55ad90 GetTopWindow
0x55ad94 GetSystemMetrics
0x55ad98 GetSystemMenu
0x55ad9c GetSysColorBrush
0x55ada0 GetSysColor
0x55ada4 GetSubMenu
0x55ada8 GetScrollRange
0x55adac GetScrollPos
0x55adb0 GetScrollInfo
0x55adb4 GetPropW
0x55adb8 GetParent
0x55adbc GetWindow
0x55adc0 GetMessagePos
0x55adc4 GetMessageExtraInfo
0x55adc8 GetMessageW
0x55adcc GetMenuStringW
0x55add0 GetMenuState
0x55add4 GetMenuItemInfoW
0x55add8 GetMenuItemID
0x55addc GetMenuItemCount
0x55ade0 GetMenu
0x55ade4 GetLastActivePopup
0x55ade8 GetKeyboardState
0x55adf4 GetKeyboardLayout
0x55adf8 GetKeyState
0x55adfc GetKeyNameTextW
0x55ae00 GetIconInfo
0x55ae04 GetForegroundWindow
0x55ae08 GetFocus
0x55ae0c GetDlgCtrlID
0x55ae10 GetDesktopWindow
0x55ae14 GetDCEx
0x55ae18 GetDC
0x55ae1c GetCursorPos
0x55ae20 GetCursor
0x55ae24 GetClipboardData
0x55ae28 GetClientRect
0x55ae2c GetClassNameW
0x55ae30 GetClassInfoExW
0x55ae34 GetClassInfoW
0x55ae38 GetCapture
0x55ae3c GetActiveWindow
0x55ae40 FrameRect
0x55ae44 FindWindowExW
0x55ae48 FindWindowW
0x55ae4c FillRect
0x55ae50 EnumWindows
0x55ae54 EnumThreadWindows
0x55ae58 EnumChildWindows
0x55ae5c EndPaint
0x55ae60 EndMenu
0x55ae64 EnableWindow
0x55ae68 EnableScrollBar
0x55ae6c EnableMenuItem
0x55ae70 EmptyClipboard
0x55ae74 DrawTextExW
0x55ae78 DrawTextW
0x55ae7c DrawMenuBar
0x55ae80 DrawIconEx
0x55ae84 DrawIcon
0x55ae88 DrawFrameControl
0x55ae8c DrawFocusRect
0x55ae90 DrawEdge
0x55ae94 DispatchMessageA
0x55ae98 DispatchMessageW
0x55ae9c DestroyWindow
0x55aea0 DestroyMenu
0x55aea4 DestroyIcon
0x55aea8 DestroyCursor
0x55aeac DeleteMenu
0x55aeb0 DefWindowProcW
0x55aeb4 DefMDIChildProcW
0x55aeb8 DefFrameProcW
0x55aebc CreatePopupMenu
0x55aec0 CreateMenu
0x55aec4 CreateIcon
0x55aecc CopyImage
0x55aed0 CopyIcon
0x55aed4 CloseClipboard
0x55aed8 ClientToScreen
0x55aedc CheckMenuItem
0x55aee0 CharUpperBuffW
0x55aee4 CharUpperW
0x55aee8 CharNextW
0x55aeec CharLowerBuffW
0x55aef0 CharLowerW
0x55aef4 CallWindowProcW
0x55aef8 CallNextHookEx
0x55aefc BeginPaint
0x55af00 AdjustWindowRectEx
Library msimg32.dll:
0x55af0c GradientFill
0x55af10 AlphaBlend
Library gdi32.dll:
0x55af18 UnrealizeObject
0x55af1c StretchDIBits
0x55af20 StretchBlt
0x55af24 StartPage
0x55af28 StartDocW
0x55af2c SetWindowOrgEx
0x55af30 SetWinMetaFileBits
0x55af34 SetViewportOrgEx
0x55af38 SetTextColor
0x55af3c SetStretchBltMode
0x55af40 SetROP2
0x55af44 SetPixel
0x55af48 SetEnhMetaFileBits
0x55af4c SetDIBits
0x55af50 SetDIBColorTable
0x55af54 SetBrushOrgEx
0x55af58 SetBkMode
0x55af5c SetBkColor
0x55af60 SetAbortProc
0x55af64 SelectPalette
0x55af68 SelectObject
0x55af6c SaveDC
0x55af70 RoundRect
0x55af74 RestoreDC
0x55af78 Rectangle
0x55af7c RectVisible
0x55af80 RealizePalette
0x55af84 Polyline
0x55af88 Polygon
0x55af8c PolyBezierTo
0x55af90 PolyBezier
0x55af94 PlayEnhMetaFile
0x55af98 Pie
0x55af9c PatBlt
0x55afa0 MoveToEx
0x55afa4 MaskBlt
0x55afa8 LineTo
0x55afac IntersectClipRect
0x55afb0 GetWindowOrgEx
0x55afb4 GetWinMetaFileBits
0x55afb8 GetTextMetricsW
0x55afbc GetTextExtentPointW
0x55afc8 GetStockObject
0x55afcc GetRgnBox
0x55afd0 GetPixel
0x55afd4 GetPaletteEntries
0x55afd8 GetObjectW
0x55afe8 GetEnhMetaFileBits
0x55afec GetDeviceCaps
0x55aff0 GetDIBits
0x55aff4 GetDIBColorTable
0x55affc GetClipBox
0x55b000 GetBrushOrgEx
0x55b004 GetBitmapBits
0x55b008 GdiFlush
0x55b00c FrameRgn
0x55b010 ExtTextOutW
0x55b014 ExtFloodFill
0x55b018 ExcludeClipRect
0x55b01c EnumFontsW
0x55b020 EnumFontFamiliesExW
0x55b024 EndPage
0x55b028 EndDoc
0x55b02c Ellipse
0x55b030 DeleteObject
0x55b034 DeleteEnhMetaFile
0x55b038 DeleteDC
0x55b03c CreateSolidBrush
0x55b040 CreateRectRgn
0x55b044 CreatePenIndirect
0x55b048 CreatePalette
0x55b04c CreateICW
0x55b054 CreateFontIndirectW
0x55b058 CreateDIBitmap
0x55b05c CreateDIBSection
0x55b060 CreateDCW
0x55b064 CreateCompatibleDC
0x55b06c CreateBrushIndirect
0x55b070 CreateBitmap
0x55b074 CopyEnhMetaFileW
0x55b078 Chord
0x55b07c BitBlt
0x55b080 ArcTo
0x55b084 Arc
0x55b088 AngleArc
0x55b08c AbortDoc
Library version.dll:
0x55b094 VerQueryValueW
0x55b09c GetFileVersionInfoW
Library kernel32.dll:
0x55b0a4 WriteProcessMemory
0x55b0ac WriteFile
0x55b0b0 WideCharToMultiByte
0x55b0b4 WaitForSingleObject
0x55b0bc VirtualQueryEx
0x55b0c0 VirtualQuery
0x55b0c4 VirtualFreeEx
0x55b0c8 VirtualFree
0x55b0cc VirtualAllocEx
0x55b0d0 VirtualAlloc
0x55b0d8 TerminateProcess
0x55b0dc SwitchToThread
0x55b0e0 SuspendThread
0x55b0e4 Sleep
0x55b0e8 SizeofResource
0x55b0ec SetThreadPriority
0x55b0f0 SetThreadLocale
0x55b0f4 SetLastError
0x55b0f8 SetFilePointer
0x55b0fc SetEvent
0x55b100 SetErrorMode
0x55b104 SetEndOfFile
0x55b108 ResumeThread
0x55b10c ResetEvent
0x55b110 RemoveDirectoryW
0x55b114 ReadFile
0x55b118 RaiseException
0x55b11c IsDebuggerPresent
0x55b120 OutputDebugStringW
0x55b124 OpenProcess
0x55b128 MulDiv
0x55b12c LockResource
0x55b130 LocalFree
0x55b134 LoadResource
0x55b138 LoadLibraryW
0x55b140 IsValidLocale
0x55b148 GlobalUnlock
0x55b14c GlobalLock
0x55b150 GlobalFree
0x55b154 GlobalFindAtomW
0x55b158 GlobalDeleteAtom
0x55b15c GlobalAlloc
0x55b160 GlobalAddAtomW
0x55b164 GetVersionExW
0x55b168 GetVersion
0x55b16c GetTickCount
0x55b170 GetThreadPriority
0x55b174 GetThreadLocale
0x55b178 GetStdHandle
0x55b17c GetProcAddress
0x55b184 GetModuleHandleW
0x55b188 GetModuleFileNameW
0x55b18c GetLocaleInfoW
0x55b190 GetLocalTime
0x55b194 GetLastError
0x55b198 GetFullPathNameW
0x55b19c GetFileSize
0x55b1a0 GetFileAttributesW
0x55b1a4 GetExitCodeThread
0x55b1ac GetDiskFreeSpaceW
0x55b1b0 GetDateFormatW
0x55b1b4 GetCurrentThreadId
0x55b1b8 GetCurrentThread
0x55b1bc GetCurrentProcessId
0x55b1c0 GetCurrentProcess
0x55b1c4 GetComputerNameW
0x55b1c8 GetCPInfoExW
0x55b1cc GetCPInfo
0x55b1d0 GetACP
0x55b1d4 FreeResource
0x55b1dc InterlockedExchange
0x55b1e4 FreeLibrary
0x55b1e8 FormatMessageW
0x55b1ec FindResourceW
0x55b1f0 FindFirstFileW
0x55b1f4 FindClose
0x55b1f8 EnumSystemLocalesW
0x55b1fc EnumResourceNamesW
0x55b200 EnumCalendarInfoW
0x55b208 DeleteFileW
0x55b210 CreateThread
0x55b214 CreateRemoteThread
0x55b218 CreateFileW
0x55b21c CreateEventW
0x55b220 CopyFileW
0x55b224 CompareStringW
0x55b228 CloseHandle
Library advapi32.dll:
0x55b230 ReportEventW
0x55b238 RegUnLoadKeyW
0x55b23c RegSetValueExW
0x55b240 RegSaveKeyW
0x55b244 RegRestoreKeyW
0x55b248 RegReplaceKeyW
0x55b24c RegQueryValueExW
0x55b250 RegQueryInfoKeyW
0x55b254 RegOpenKeyExW
0x55b258 RegLoadKeyW
0x55b25c RegFlushKey
0x55b260 RegEnumValueW
0x55b264 RegEnumKeyExW
0x55b268 RegDeleteValueW
0x55b26c RegDeleteKeyW
0x55b270 RegCreateKeyExW
0x55b274 RegConnectRegistryW
0x55b278 RegCloseKey
0x55b27c OpenProcessToken
0x55b280 DuplicateTokenEx
Library advapi32.dll:
0x55b294 SetServiceStatus
0x55b29c OpenServiceW
0x55b2a0 OpenSCManagerW
0x55b2a4 DeleteService
0x55b2a8 CreateServiceW
0x55b2ac CloseServiceHandle
Library kernel32.dll:
0x55b2b4 Sleep
Library oleaut32.dll:
0x55b2bc GetErrorInfo
0x55b2c0 SysFreeString
Library ole32.dll:
0x55b2c8 OleUninitialize
0x55b2cc OleInitialize
0x55b2d0 CoTaskMemFree
0x55b2d4 CoTaskMemAlloc
0x55b2d8 CoCreateInstance
0x55b2dc CoUninitialize
0x55b2e0 CoInitialize
0x55b2e4 IsEqualGUID
Library oleaut32.dll:
0x55b2ec SafeArrayPtrOfIndex
0x55b2f0 SafeArrayGetUBound
0x55b2f4 SafeArrayGetLBound
0x55b2f8 SafeArrayCreate
0x55b2fc VariantChangeType
0x55b300 VariantCopy
0x55b304 VariantClear
0x55b308 VariantInit
Library comctl32.dll:
0x55b310 InitializeFlatSB
0x55b318 FlatSB_SetScrollPos
0x55b320 FlatSB_GetScrollPos
0x55b328 _TrackMouseEvent
0x55b338 ImageList_Write
0x55b33c ImageList_Read
0x55b348 ImageList_DragMove
0x55b34c ImageList_DragLeave
0x55b350 ImageList_DragEnter
0x55b354 ImageList_EndDrag
0x55b358 ImageList_BeginDrag
0x55b35c ImageList_Copy
0x55b364 ImageList_GetIcon
0x55b368 ImageList_Remove
0x55b36c ImageList_DrawEx
0x55b370 ImageList_Replace
0x55b374 ImageList_Draw
0x55b388 ImageList_Add
0x55b394 ImageList_Destroy
0x55b398 ImageList_Create
Library user32.dll:
0x55b3a0 EnumDisplayMonitors
0x55b3a4 GetMonitorInfoW
0x55b3a8 MonitorFromPoint
0x55b3ac MonitorFromRect
0x55b3b0 MonitorFromWindow
Library shell32.dll:
0x55b3b8 Shell_NotifyIconW
Library wininet.dll:

Hosts

No hosts contacted.

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 49713 114.114.114.114 53
192.168.56.101 50002 114.114.114.114 53
192.168.56.101 53237 114.114.114.114 53
192.168.56.101 58367 114.114.114.114 53
192.168.56.101 60384 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 123 20.189.79.72 time.windows.com 123
192.168.56.101 49235 224.0.0.252 5355
192.168.56.101 50534 224.0.0.252 5355
192.168.56.101 51963 224.0.0.252 5355
192.168.56.101 53657 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 57874 224.0.0.252 5355
192.168.56.101 62191 224.0.0.252 5355
192.168.56.101 62318 224.0.0.252 5355
192.168.56.101 63429 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900
192.168.56.101 50539 239.255.255.250 1900
192.168.56.101 53658 239.255.255.250 3702

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.