20bf2ccc96997700cf5e2b1f6b6f63304008140f37948ab37c45b63e37f46b7d
20bf2ccc96997700cf5e2b1f6b6f63304008140f37948ab37c45b63e37f46b7d.exe
静态报毒
动态报毒
CVE
FAMILY
METATYPE
PLATFORM
TYPE
UNKNOWN
WIN32
TROJAN
WORM
DELF
DACN
0.12
FACILE
1.00
IMCLNet
0.79
MFGraph
0.00
| 引擎 |
描述 |
特征 |
威胁分数 |
可能家族 |
检测耗时 |
|
DACN
|
基于动态分析和胶囊网络的可视化恶意软件检测
|
API调用、DLL以及注册表的修改情况
|
0.12
|
Unknown
|
0.07s
|
|
FACILE
|
利用改进的层次胶囊网络对二进制恶意软件图像进行识别分类
|
二进制图像映射为的灰度图像
|
1.00
|
Unknown
|
0.03s
|
|
IMCLNet
|
轻量化深度卷积网络模型实现恶意软件家族检测
|
原始二进制映射而成的可视化图像
|
0.79
|
Unknown
|
0.21s
|
|
MFGraph
|
利用静态特征构建图网络以检测恶意软件
|
原始二进制PE文件的静态特征节点
|
0.00
|
Unknown
|
0.00s
|
| 查杀引擎 |
查杀结果 |
查杀时间 |
查杀版本 |
|
Alibaba
|
Worm:Win32/Delf.1cc5c5d6
|
20190527
|
0.3.0.5
|
|
Avast
|
Win32:TrojanX-gen [Trj]
|
20200916
|
18.4.3895.0
|
|
Baidu
|
Win32.Backdoor.Wabot.a
|
20190318
|
1.0.0.2
|
|
CrowdStrike
|
win/malicious_confidence_80% (W)
|
20190702
|
1.0
|
|
Kingsoft
|
None
|
20200916
|
2013.8.14.323
|
|
McAfee
|
None
|
20200915
|
6.0.6.653
|
|
Tencent
|
Malware.Win32.Gencirc.10b3531e
|
20200916
|
1.0.0.1
|
该二进制文件可能包含加密或压缩数据,表明使用了打包工具
(7 个事件)
| section |
{'name': '7519006', 'virtual_address': '0x00001000', 'virtual_size': '0x0000d000', 'size_of_data': '0x00007e00', 'entropy': 7.99353393817323} |
entropy |
7.99353393817323 |
description |
发现高熵的节 |
| section |
{'name': '8572755', 'virtual_address': '0x0000e000', 'virtual_size': '0x00001000', 'size_of_data': '0x00000400', 'entropy': 7.767636168582015} |
entropy |
7.767636168582015 |
description |
发现高熵的节 |
| section |
{'name': '6580166', 'virtual_address': '0x00011000', 'virtual_size': '0x00001000', 'size_of_data': '0x00000400', 'entropy': 7.830116036537715} |
entropy |
7.830116036537715 |
description |
发现高熵的节 |
| section |
{'name': '7044656', 'virtual_address': '0x00013000', 'virtual_size': '0x00001000', 'size_of_data': '0x00000200', 'entropy': 7.55488547604783} |
entropy |
7.55488547604783 |
description |
发现高熵的节 |
| section |
{'name': '5294235', 'virtual_address': '0x00014000', 'virtual_size': '0x00002000', 'size_of_data': '0x00001000', 'entropy': 7.952516725673953} |
entropy |
7.952516725673953 |
description |
发现高熵的节 |
| section |
{'name': '3707131', 'virtual_address': '0x00017000', 'virtual_size': '0x00003000', 'size_of_data': '0x00002600', 'entropy': 7.385206639806591} |
entropy |
7.385206639806591 |
description |
发现高熵的节 |
| entropy |
0.9595959595959596 |
description |
此PE文件的整体熵值较高 |
与未执行 DNS 查询的主机进行通信
(1 个事件)
文件已被 VirusTotal 上 55 个反病毒引擎识别为恶意
(50 out of 55 个事件)
| ALYac |
Trojan.Agent.DQQD |
| APEX |
Malicious |
| AVG |
Win32:TrojanX-gen [Trj] |
| Acronis |
suspicious |
| Ad-Aware |
Trojan.Agent.DQQD |
| AhnLab-V3 |
Malware/RL.Backdoor.R257255 |
| Alibaba |
Worm:Win32/Delf.1cc5c5d6 |
| Antiy-AVL |
Worm/Win32.AGeneric |
| Arcabit |
Trojan.Agent.DQQD |
| Avast |
Win32:TrojanX-gen [Trj] |
| Avira |
TR/Dropper.Gen |
| Baidu |
Win32.Backdoor.Wabot.a |
| BitDefender |
Trojan.Agent.DQQD |
| BitDefenderTheta |
AI:Packer.2BC80AAE16 |
| Bkav |
W32.AIDetectVM.malware5 |
| CAT-QuickHeal |
Worm.Generic |
| Comodo |
Malware@#2p2poaezm1hvk |
| CrowdStrike |
win/malicious_confidence_80% (W) |
| Cybereason |
malicious.e04d0f |
| Cylance |
Unsafe |
| Cynet |
Malicious (score: 100) |
| Cyren |
W32/SuspPack.R.gen!Eldorado |
| ESET-NOD32 |
a variant of Win32/Delf.NRF |
| Elastic |
malicious (high confidence) |
| F-Secure |
Trojan.TR/Dropper.Gen |
| FireEye |
Generic.mg.985747ce04d0f610 |
| Fortinet |
W32/Delf.NRF!tr |
| GData |
Trojan.Agent.DQQD |
| Ikarus |
Trojan.Patched |
| Invincea |
ML/PE-A + Troj/Delf-GBD |
| Jiangmin |
Worm.Generic.ahwj |
| K7AntiVirus |
Trojan ( 00129bd51 ) |
| K7GW |
Trojan ( 00129bd51 ) |
| Kaspersky |
HEUR:Worm.Win32.Generic |
| Lionic |
Virus.Win32.Elkern.kYNv |
| MAX |
malware (ai score=88) |
| Malwarebytes |
Backdoor.Wabot |
| MaxSecure |
Trojan.Malware.300983.susgen |
| MicroWorld-eScan |
Trojan.Agent.DQQD |
| Microsoft |
Worm:Win32/Sfone |
| NANO-Antivirus |
Trojan.Win32.Delf.hfbrwy |
| Paloalto |
generic.ml |
| Panda |
Trj/Genetic.gen |
| Qihoo-360 |
Generic/HEUR/QVM18.1.CB0D.Malware.Gen |
| Sangfor |
Malware |
| SentinelOne |
DFI - Suspicious PE |
| Sophos |
Troj/Delf-GBD |
| Symantec |
SMG.Heur!gen |
| Tencent |
Malware.Win32.Gencirc.10b3531e |
| VBA32 |
Trojan.MulDrop |
288x288
224x224
192x192
160x160
128x128
96x96
64x64
32x32
👋 欢迎使用 ChatHawk
我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!
🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
PE Compile Time
1992-06-20 06:22:17
PE Imphash
3c0e70bfa5f73f1f1cef484e2bcb5bf8
Sections
| Name |
Virtual Address |
Virtual Size |
Size of Raw Data |
Entropy |
| 7519006 |
0x00001000 |
0x0000d000 |
0x00007e00 |
7.99353393817323 |
| 8572755 |
0x0000e000 |
0x00001000 |
0x00000400 |
7.767636168582015 |
| 7151059 |
0x0000f000 |
0x00002000 |
0x00000000 |
0.0 |
| 6580166 |
0x00011000 |
0x00001000 |
0x00000400 |
7.830116036537715 |
| 3626684 |
0x00012000 |
0x00001000 |
0x00000000 |
0.0 |
| 7044656 |
0x00013000 |
0x00001000 |
0x00000200 |
7.55488547604783 |
| 5294235 |
0x00014000 |
0x00002000 |
0x00001000 |
7.952516725673953 |
| .rsrc |
0x00016000 |
0x00000698 |
0x00000800 |
4.882641711202083 |
| 3707131 |
0x00017000 |
0x00003000 |
0x00002600 |
7.385206639806591 |
Resources
| Name |
Offset |
Size |
Language |
Sub-language |
File type |
| RT_ICON |
0x0001654c |
0x00000128 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
None |
| RT_ICON |
0x0001654c |
0x00000128 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
None |
| RT_GROUP_ICON |
0x00016674 |
0x00000022 |
LANG_ENGLISH |
SUBLANG_ENGLISH_US |
None |
L!This program must be run under Win32
7519006
8572755
7151059
6580166
3626684
7044656
5294235
3707131
?Mn#fS
X$GZP~
9p9/ZD
|&d0n&
.#ArYn3JA(z
8O-@q}x.=
}YMF>kG"`ztY
@,15m^!_]02
k*tqyQ
rYNsUF
?]j&?[
Tv9p'7(P6#m
1PGJixRJ7bzp
OCh/\c
=#g?`y
r/Rvo_
{\Wgc%
%WhE7'BhW@Ao@Q
#@0t]-8
iI!F%9~mjw
Ogmo%Lc+I
^~<ZQRA(.zC6
T79?ho
kb9T,PW"
L5k{ezV;#lEtYzT@
}2IVe
m_WI!He
sXX"O}
kH$&G;
YSs?Q{
O7s<k<M^zw2oi
aE@4q[
?@.aJj7}a
{jPO1xEbu]SL"m
{di<P@
g?jsGJx\:Jz>
/&y1q8
SiWn*L-/V
DZdQ{t
Okl0z`B8
'%p$xI&]
B0Kfy{:
G.}Uv:
lJ]X?ro
bDN)GO2k
smq=i}
?UNGDH9
znh:kA
`QH!,:
"HT,:p$QQ
d$}.M=
R52O$w
Gs2P7h
S\'0HCM4'M|8xQYu,Y
Up3c'W0
=pm&-'
5)$xy7a
p]%5<GxvM=
>RSi&[
(Cjl/HW
*=G&[%f3
t>7BX|B<
g ^9!K
t3SZ&o0E"&
tn[2(({
H~cQG'
.1\*X#
(sb7bOP !
<au29R
_( '1*
3FS1S\2
r^6g}!0
4Yg}r
=55<mp*
eewX'b
J`;"_LY1
*Gr*ip
zkI*xFM_
fk0Ki 4hY
Dk"f&I
,DkqNgeN4%>!x!K
~R3-BE
&XCe|ofAFjc
,_-Tl
qQkr'YB
/>}f-t>a'u
F{fabRR.
(>!]^n
q[yFN''uJ2(p
<"z4,TK+1Q&P
s^omG>[V|A8K[
Y@bWZ0)%t-'|a;\:Y
l.Ei>Y
:JC:q\FJ
]!3_m*jS
]5D2AF[
>MY&H5#X
8I-K}ZO#;
~w9Z%O
kK{nh <ot
6+"<Q0mEMtzo
2jxW[S
CQIV;`,o&c+C=j
R)`pJe}L
%^X r}v1
F9HA9xcl
wgh"IB
HEroyBY
DHv&#'q
?5\:o$
:V}a.;
F[o`Ow42
pAaS*W&
DCqfzU
0|h()"Zm\?
=|iI`YNF
f^^@YD}_z
@Y,r,!riO
.v)}bar|[A7YS`
++~-+$YIkL
:VLAw$
p.X)~
bWQ0T>
*0'6x3A|=
5PBZ!q
ZT"/"5
\">}[&
VgF>Z1k5
R;]Yr""weT9 Q9
N' P*h
JmV{t,q
o/uEte
Sc=kRb
VGkHK2*V
L}dkz#
aQ6O&IR
(U`3lM!
b~sXgU
?vl?Oo
Y;mfpkL;S
235rlq^e
yt{S|f
6f.q?z`W<D(;9U:
p`v_IA
shg8a g0"<
qN]uCW+
J)_~!u?+_eAJ:
!]Qf&*2xc
/PV?k\d
`i9|QA
w:LixHL:=0
ckE-yo%
m8BNBcd/
aYHt+o
$;rEkDVl^GWQ7G&
x*2LdK
Epd+^rlO
E.k}.z^b
"}-x3dnegV
2t7b&EBm
Z!vf8sr5+
_-)ZO:'e7[
RmGT.g
39LEc8mhL
lX-_vS$o.@
[o{_qdH|=6
9\eLBR0
V&UBxTbB]
q`#rl#
i/c'k`>
)$Sh <T#
3<*Rs,
UIW=h#j%!
Q(<cT
=f*|!c
ty9BV7D
MXO*$-zZ
sA5d-:
V^D98S^4M/I%!
_'pb\T
&-4t]95R!
^a$`i2}6
\zRL}(
; 2e[=
bfnQ=fS
)M^a\(l
jZlw,7o
vr#;.0V
_1k<L6dC%~
`#h9_~k
G?v`gw
:,jJkP ~
VWwhd7)@
&pS$ $Z1C
,A=12`-^
TKeyQ/[
}I2NG9xO
F*2TOaWEAAMl"
92o5JM
2~u\_}
Ft{=x,2
b+,O{C
`NmTg<1k:~;D
/Z:Eob
|`:15U
r32*hnK
e.M'}WkUE
-E`}jz6Ds
+:K^xp!
]B-i~>8
5-quq=
@D |{HOZ
VfwC!'
H~szG9gCjV\s
wlgx&V_$x89K^k5
<9-}M@%
qa?~p9
GR'(cbjf
[y*@Q?Dl
|6AWU:s
j0i.BeY
Ou/DdqZb0
Z. mPT/@O
wQQV<{k'Tu
Z5m<WZ@H
iC)}aQ3 x\
KK~QHd
W Z7~'
(W%Axu
sS95b$oh;6_,L
oc!"hB
Aat5w
<F.lC(M^t
BxIN/<
=M+1Aen
I&wd\{6\j>d
%sUesvX?
}OYS!2%1)
j4+jgB<@
j>E9}c.
=s<2 :
lQj#Qb
K3)s_O
wf:)>D*h
Gf%;AC.
zs/WEw ,
K5`@F{Ms
Wkglx
`sj!j)Q
*K];%ts
-w5G{Ad
>To:}2Esbu_.l
BrC~7
O+3-~H1u4i
mhQ=He1
gv&1:w
91?y>E
'ql2{
yX` ,eaW8o!K] ,Q
mmUg\eMU
IairyMR'jfS
!Ia\0!Mtv
eTY>oe.A;\
0I|f$z$d
c(yw4{P
e0EqG4(
~PR:%b,(R
N9#|*xpI.
{:ea*XHt~
UBTj;%
VZZ]'-
H?8 )p
&a%y+8;E
5$f7Nz/\yN
OhZEc
|xgRc#
ewqDLu
)C%!a@
x 5K.;`lv"
b'(5Ogr)$2VJ
;;b,]NMr,r'<II;
j(Uoi[6
)IM\7/W*Q
e7vf=x
z~w@w=H
k7|O5*P
:9AALt`.}
_jc;=?
_>i1J
CF:6I1nMP:b
?>I.UP<c
]=_zC<
L"SMcj(
v-=p'N?
j XZK&
hN)U4q;@1Z^WF
.foTRVc
#>B{b4e$
.>]E8Pp
NE>O!Ut"
woeoBn
m:WZl|
&7z)U*
`otUdOQ
TqMB,s3N
w4UIF1p
iD i|_s3'M&r#
b|"|a+uS-}H Ms_\tP/
b{_KT&FW3Q
pWdP_{,\j
AFjg3id
eL*k0LF
O4zf=&SfoBR2
Izt"yHC
P4rm;/_
yUU$t(s-`
`X-X@a
A,h@P+45=pK
Q;F%H[%
.6+xb}
@Ip$i$
pIggn,z%(*;
($s6=w
/pt>Xj
S20UUz*Q}q@\g8W
~|[*i>JbwQG^!W
!uxBP6
k@&/P6p5D
KxL`S0iHfW
`G:v.)O#71
M#hX}xO
p7:<~X
H;-"Q}1
EBJv0}/
UgQB]6_$;
(6t#{\q
OL}wq0KEJLC
(xUI}v.)dz
PO-WXm|Q
++5,J2<
_r"wI}pDNJ9k8)k"N
;Q@V&7\(Dn6%.O!
cg~UDSv
/{Lr)+,Go
|xUXh
L,rDEW'>~TE3_[6
RkdE9Wu\@A
CVW_<E.B
/,^+T!c
6OFOxU(Kd7a
|A14KnzbCE>q
EJlr,5"x
.r?0{-W
}4T|9vWc
Ui ,RbV
s[)M8
\#c}]:
eNS)E:ge
-n_ sR%-9W:+
kDX{kP
#kCz[;
2$_*R)
/Vh3.aL5f
?%`4MPR
*z^>Sp
j>5x(i,0mg=]+n
d xm~ZF
b_L ."B?%
Cx&bgIMo
*+U7$vKX~
d'2@sdr6-lZD>v<|
Qjx(n#"[
"{?,>pT:b%
C}DA)@Y0m
.^`j@&
@{_.ePXB;n
s[V V"~R+
v(G&d!`+!mMn
+M4Z*Vj2)K
.P(2^B
[/^WyP(he(F*
[{|t{S$B
=rwBx\B
i%b-4\V3)jN
bA4Gh/dj0CQb
pY[?0AF
wRgwr$#M
D 0WO07
;kVg3=M
K5'R#sYC!>
)Z/\'PVw
>75[Fd
\RZ;?v`z;z}
/]>E+7L
3[~Tk16V
Z-cBx@
~$ qE2
+shTeh^5`R
&i8F70x&$F
u"%K8px
J0d>A|@ZV@h
F*{.|gd|;!P/.;4[u:b
G7tubV
b"^L4C
"V-0{cd
XA5(jM4V1B}
kM_oOfLfA"c||)v/MUS4Jd
]Fvs#zQS_0,
%(~o-(
z/0qOK$y3z
C:6$bX%sMFl
rg?bzA
=!YsS##
hvsH?N
.Kh8
e=#y<u
o*BJ}32"H
_CyWSKv
|iwD,t#|or
6/N:U9|
22~[rysmsz0
>d0s"h]_
wItzo6&
]C&JxCzvj
2X4X.?e^mx"
lMZ}v7kv_h%
oCpE.>z
cR_ r:dvgAULd
N0YKZ/q
%Wm;X!
j83.:X>o'}>NV
{YevSYbk
M-SjtW^\
f"eZXH@A-
1&42sX@dx_us
D}=s6ir
u3bIV[
B*Lc7j
F#gaOF
,\<sv1p/i
P^lc=T~j<;
'Dy4~^+N+Uir:#B
>kumX~
.A;S)M
1]F:=IqDo
@$?E>UA~
bB)p;P;M@P>E]:D
YXb\F^:
W)c@^B
w/o7]Tu
P!5}b'h3
}:m\"A
=WLPyU
`RcA;^
p~|[zW
-?/-FLZm^
Uv;?k ]&+
ok-asTytf8dn
>sh4w)mu,
-b^oA3a
f'H+Lx
5Eh9$J0 #@1vOTme
'Csgm1
+r=3@wr4
O\iOE/8Vh
@3FSs\xd;@i
bK.\]u
"-9S8k{
v7O+tN%,T]s7
ljcyda
^>CmF
6Z(`h@O1>27H\
>g+L}!CrW
0_0_mL&.
*df5b;h
j(hw*u
Z_?CqO
bD|/8~
++DgG({
8jVD+Y
[T_7g;
yEg8'&>I
[,M6?DdFV4<
O.piDu0)mMC2
e->)"C:#
{o.z3o
%J'aa?L
uMaWuCY1m
p%5f&z$
7..e"*573'Y&@
=waF+,4Ii
,(d0vXjBt~_
;Coqpb
/qBq%!
0c.*!T
W2:G90d
;:<3D>"M(
Mys%]?
#N1Jc6
s:]@v^X
V5s=,I
-z6qQiwP
*\8QX5l=>
3%95T;la
&I&7GeZ
!w3)!va
`"3r(\j|Oa;
30v g=dBE
\xc&d|
??0.37cI'RX
26s"*w
F.KB>i4'xUu~`o
O6eM4?X?{
/+q!jk)h={
HZ`nY3
kn{GyS
_^zhJP!
Y45DUS
)Km$FB5J;;o
ER'7UR/=Lg
1}5Y(N
TGPeqK];rc
AWQ}r^
.XIR{|(D=5^O
zbBm=?|oRw"U<jN:Dl'>?
mC29IA
SQ/uCl
m(.#qP.{mx
KaJ{&U
!#(&N;V
H\*WcD
}!37gK
DtLE$WI]
2fH\;?L\
Q]c_\"
C(4y`X
5*Aw($
Kc*T3JjE`Z
'?:kF'B<"X2
[0Amvd]`
Vu}>?$63
s-zm,'8
+)OG<8>|_s
9jMuyWmQ7N:
[UICrO|NOb
~/d.KHR}!Q.EY9
!v`s0K
X&.p<1(
%xf Q~u{
$}7'2Iw uckmucAPUzxz
-5j5OPD>w
uH~Pq)9x%g@
oZV"Vz_?
N?Ga/Z
5c0XAe
RbJ<=4E(
{ExWL\M:B?SZK"Oac
S~(qt*
-Qn)>0+?k
G4]9}{K
Yd=HKN~sB
<_B9iHMjv
"B36^XN6cJL
V~ZbEYl
$e<|gzUt^@
De4qK49
WC5=Ul)_A
+06r&f
KLayM7Ca\/[
:>|;)Z
<c|='nMQ#dR2qe
k+t#RS+O
gbs"hT
\V>e>V
SWh%x&o.MjQ
"*C}=
%MnWv'VTS(9d
(PI;R%
e{OSQ6_&
-'=`;JWZ
]@a'Zhb;b
Js9(>0<W
B7A|e>c?/;\2
$f[*Tw!sn
k2@46RC:O>&r
>SXIc\.F8
y|}Hd
yTKpI,1UF
h3Vxm8,Ma
U!,@_<X
--?)MT}[
W3_[@!_kWX?P5[
jMKCz
>K15Y(K
"08J@6z
Wl[RZm
Pj=n 0
zdJv@8\
[#bk^-RO9mA8L;
GJv6i^H
k,~B$Mq{%h!& %_
}z.V=>
qh!l<Rd
tj8-Y?aX!U
ra<+EF
$bA +~yl
~)kxsu;^
Wu :7=wI;B
k``fir
Flf!a>
`?T$Df'
Xl#\b[B`Flb^Yw
r/zX)J
Yf8Q1tRh3
'mRB^U
.nwo<=H
87LG?sI^
8k8o&E|
${Nv3}p#e6B;<B;Iq1(
"rWOB ?
pp/pbH
tkqA*CQ?
.~1y,?8"
O|9GIUpBPT
p%!/&x,fkH<t
1{X@BgR ^HSFwnS
^s>.9P.
<e.iK|a>It
E;_(6?
!^TGpFbyhid\.b
)#J"i:O
[O2wxZ6d<
c/_@"E
nlKt4xI)
6?Ch \Ao)`%
OcBE3m
)b mU*
K5R&]:.xH
`2FPj6,jd-H
g_iT@B@qZ+
g}`m~<`Y
:w,"j3-e8L;_0
vA[_{DFx
fdv9b#/k
f1N#C9=\1h
VWG?JN
*6QqS+
*DD7|$k8||K
2jj"C;lZ
^rOCio9w
XJ7D&9&W&
mw~!3\
qxkW)f*k
~+O:xH]9b 4:nsj2
(]>+g"(d
p:,Nfb
~|c[ s/2
,;6FL?c CN
/l#bCr
Q3jPH4F
zP@b=B
GP,b,2
P|Vk7$
OOOE}bM
[@lsd8(
lT4^z;86frUL.;O*ynM+
94k['o
p6M'bY8t
SGI!<-.)
hr(]~Hpm;^-.NMp"f0}`
w>w*GIM
X_d}|?DBz
0(J7Qg
rB=tG+
^<]6H!
_~'-VsFbQ
+1rA|g/n*T
=^XVqE8
pPo8DvZ)cI'D
X+nzszX 4I@Z
+kz)Z-r
;M{oNI
O!Lk\'
]T>J'^@;
B#*r=L
VQ!IxH'
Kodo7Me
I\G:*x<b
;60Hd;
*]/)7x
wT*El{vIC
[s4cs=II
[X'J9=,/
Q}lI:xMs=c*wXE.
&)-e^(+.IG,
+1 s)}_#
*,_u1Fb4%"
YwqnCM`T
X7:sn%.
o6ciyK
r6A,+p7
@Pq<+z
KYcm1C
-'CA`@Zc2o
+8Ikt&nkFTN|\$
:zBC;x
]Qf)g#+
zx Y!F
Q*eF48<<
$aoj"vU'e4'ITV
+Iq0,u}&^dK,M*q
GrL2yX(
{W~}2LY
~<>UOY%:I
z!0(b2o
.EQ\tps
~J9hxr\ifd
':hi_2KYAcJud8
1 VgSZT
+vLh+Z&q
B="vw%
C-aCQ:k
vsTxS^nL>
o$b.!GCP*]J
r2m*Rvj-
*YM>b#36G$d\K
[,8k[&C1RAs:v,$@
F*QQui
$nnaP!
xL39t`5p
n)._rm>!r3
HXupqZX!d
?<_,<-
06XxFJ6
qA(_W\
+}ze)kR(
Yzh8v"]"*k
&<le!FBi<:-7p1y
xuq*\X=:^
#n)W;:o[~d+/+Q
x5D)TS(c
@4_jDxn>+]
,;fSHDIeGjY0'b
(gF#!mT5
?.'5$.x
~>%3~+WOw4j
Q;olFK4
.;)zx[c
#?l1$jO
:}ZU2f?
Oi<HB(
??7dmn
E}f+]K
Vh>=~=p
sK):.-
wj!?|Q
`_dD{_iNvw~5DE
;b.sGcw
rw,]I~OU
PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX`
ET81NDUVHxC
s1A_h0Te
i}Lbmfmb 8
fq~^SELR~Uf~
KUQRj~
LS%}`qp'<
x.(7c!xe
1EzsM/wC
hP`-r?-a
<i3jU@[
I*B}*]
V\=tz1^fQ/hM%HK
R/PamX
HF2vqg
uw^\52OCL>
DUTC0y
y?*ezsXuZ)Z
{)'uO1[
rpQlxGC
K&$hHGL_HK+D+@_ ' *5"=>!*91
*Pi[P7
ZITc`q-H4N%M"0v-f[:I
Any6EHrc
)'|P-i(,atQ
{%r7r7!IS0
C6*7:|P
P/eXx
}m#p[|`5!i
vCY{VPtE[
^C|GGH6C+zdUZ
KifP.8
ZXiy1wub*b
e{x/77)0
t=U;p)
Wig5r.
:zcHiu
B6Qq!r
qeqk{Xa|hJi
A=O)Y#W8"#f8U#r$(2\
0Y;U{`d
i,fhC
,,k-U\)
hzx~5/
kQmuJ5x
cXA[k)
,|eZ#
|o^KqSP
wQ]4e&G@
9Z]lx
.vfO1c0Q
#kc>J9RY!mt+T
l9sr7mD
DZ7Mqrq
4|ByXMK2L
V{CT(?
DU PV?
hvtLT9
#)`*lOd)%5
qhKgteN5-M
sQ-5$lCT
N&1"9Hz
{^,3}{
R44*~:g^7
yJV_v1|
]ce"&eYL"[6
]j'v7h7
C<Eo^S{
k0Mbkn.
aR}T{TMk>/W/
E %V@J
B7lmcM
]MaW<>$
mJrPAJ/gN
,/^^#(
Vdc&5l
RKdA$q3e/_
6CLQP.oq
5A=j*'
\G,}OM
>E^{*%y#jv
h0b,v_2:i
8z]5NRv$sKfCqxB3
w/G'X-L^W1
]Ulu~"%6Q
KaE0$f
kb\2wRU<
imZ+o+
a,&TC!;E
L8]en+B
-T?Cg t+
]9i,'ay!y
9lsMWK
@HU}td
&Up[01
:9|}Ail]
RnNZ&>Wb
@wz{f_2D]mKU
`sJ2P"J4T
1J0@.m.
jy!fCcO''o%{YJL
DL>8v6i5
GfW!r%Z&dZym
UTUn)c
2h[1GD 8
Zc> ><y
0][}SXMhK
ok*H?Aq\>
0EL6ZVCH
:+QACi
\pz4Xho2yU7
4L#i>XX}D]nALx^
uuj+UxU$
n*0<QdB
he^:HMXs}*O
Ac"r5@Vb
2Br?0NUy!XS
C"1_sw
2L.oS<yICKm8
(Ful'\
u8RN9w
Ndo[w
<f\^G,
X&c\K"M
kernel32.dll
user32.dll
GetModuleHandleA
MessageBoxA
Kn[VS0/!
jy<zPn
3E &kL^tB$E6(&6W:n[
52CZ=oj
!sccXCX2
'2CJ')L_skx7G
CF1'P_bkggB
E4S;v
62CL;'ZP
^`v*v\
han9=iM(
wwwwww3388
D333338
/D333333
DD333333?
/DD33333?
DDH33?
/DDDDDD3?
DDDDDDH3?
/DDDDDD3
DDDDDD8
0& b}!
_-L\::/
I<TPB[
qi\|*IWQqrYL#
U<TG@m
!0AC`;[
Nj`qq1s}sx
*$</xS
+<H+$=
<shI%o-*
Y1vvhd
H4tO6I`
wK/i(AZu[
t:}nS.[7jv[
(~ 3XD>
:*GKkqm%n
P!xebh'
P$11qP
6r9{^!><:_
JVuHMg
7qBh]F8f
^oN.)K>
`GuUvd
]h>ldB-;[@
b3-3y-|"oqb
8E-C[a
pQ-:{`}L!
DY.9-_YJ
Y#hUAsh
$Kk7CK
h9oTM,
u}S&`A
2u!KHP
Lqxo+|
4j6zu: &ev
uL/P{@
<vYh[Z=k/
F$<!Uv\
u7]{G3Lwz0>T
Yz.qx^1A
8Du_60gFU
TzMGP'"
1l-.G_2
nP(V9a
qg /A<.
'K](,nK6mg_g
4PSf;m" -]k
S\"-2aC
TnpoC_
BU4wOu7$
K{4-kS|~D2
t;,ab:h]L?
g3$`[#)
)E{+v;*l^l3
DI1[;g
3m/iq%p
Du3#0o1
bz'W1L|B)6:
KMaIxU%_
QOKY_1[
oRi/G.
6RX;E.O
t^m[iy#
xZd<@CX-
?@j@ ay
hr!'q]lZ
@ZK z!
=Bj\+T+
2@=hPT
0W-=,?OX
9R^++i
l4=~&Q{k
wsXi*6~d
\tCj%Y
xNHu+`z
rReECWVYC+uN
>t3f+r+
py|GonwOw
]$#/c3
3&KWfe;x
[sOwsK*
)'S`:L
/`t}ti<dtdlM
uV'NRHn
XS&u.SD
!x]0Ud@
ND8-4Zzcd3[
w%oFIi
X7893Z
y~n)y{i#=
${S1|Vgf
/GDe_'
Mbz9_'qOB+
xf]B)f
!O&{CD(
uWFx*c/VcD~Hf`
fp.X`u
NB}8DM
cId=p2Krv7
oaD^&y
LM\KE
S-dVfV
@#c2HN6X
qbuep(
.RU,sK
PLwUOl
,,u:w#75
xKpOEjw9\&
10Cx]
r $-i-xq1
d5KU0'R
tvhG1~
C-XL_?j
[1LwyZV}
lols/`
4D!B7
J<%~SL.
%4d^sth'
BNx&|H
.4k^VVSO
D*S*Tt
Rk,GV04HV@8
U/|2TjVPD.`G~
g,n9wIg
35U)h
#=p8^R[B
=Y*iZ-kk5
3)F]|?
bZ0 XYn
MXV*LEx=
iDS{w*@
LI9*<Ut
fS"}O&
4&O7Zd
16}txKh
T~3..4hGZTp
+<q1 oF=
"ojwNca6
>M@z=_`bB@@M
wMm)mxR
2)@'~>T
X\!/ BK7
Ml}IY}
y4Wmru_
,Ep#zgxSK~pP9l+0%tgpW
'VsT,c
fzb;wiraL[
-e=l,8
$1kz2q
PTRJ.t_OV
bT%9m8_6#
{C.+t)y
*4Bouo
|]|neX
?H?@.O2
-w1Z_|v}r.dEu&h
rjjdW&28
E4qL:?".L
<Y-xp$][|
aXK[AE
=:}l(o2
pTf5XO?Z|
o gO5X^FqD5Q37F[t
/B#(u6i
s"+]mwH
iaz.\&E-
;%3DM/
A$:ObH
ur(CdWO
lYw"f|bV
">}c'(Z@ef
6'!.1H
m\G.!dw_UmamroU,by"nP
XSXR,m`}
iyqm??#HUg)
8$3(2.fY
sO'!q"
e42Iwi
nT8*c#}?mk
p"]MDSOJ}A{
Oqrv.:
i`Y~(V
<6p?)`
$48!S*Z
e|_FM\
e1v'Wd
;jMOTI:
C`5@G=uBO
O;kjS1gF
#w4=$r'~
pQ\tFPTd
tQ=z08
ZXj-;s
KL<^A(*
^'2vwk
[\%,jgI
3/09ZTO`
=BaT]b*
sBALQa
9"`i`kI
ms@90wY\<3>
{\;=I%Gz
]}Cj9
M A I N I C O N
TCP
No TCP connections recorded.
UDP
| Source |
Source Port |
Destination |
Destination Port |
| 192.168.56.101 |
53179 |
224.0.0.252 |
5355 |
| 192.168.56.101 |
49642 |
224.0.0.252 |
5355 |
| 192.168.56.101 |
137 |
192.168.56.255 |
137 |
| 192.168.56.101 |
61714 |
114.114.114.114 |
53 |
| 192.168.56.101 |
56933 |
114.114.114.114 |
53 |
| 192.168.56.101 |
138 |
192.168.56.255 |
138 |
HTTP & HTTPS Requests
No HTTP requests performed.
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts
Sorry! No dropped buffers.