查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
---|---|---|---|
Alibaba | 20190527 | 0.3.0.5 | |
CrowdStrike | 20190702 | 1.0 | |
Baidu | 20190318 | 1.0.0.2 | |
Avast | Win32:Malware-gen | 20191231 | 18.4.3895.0 |
Tencent | 20191231 | 1.0.0.1 | |
Kingsoft | 20191231 | 2013.8.14.323 | |
McAfee | 20191231 | 6.0.6.653 |
section | .didata |
section | .aspack |
section | .adata |
packer | ASPack v2.12 -> Alexey Solodovnikov |
resource name | PNG |
request | GET http://cdn.ylzt.web.mlgame.wang/launcher/download/wd/launcher/data.zip?v=2496 |
name | PNG | language | LANG_CHINESE | offset | 0x001e40fc | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00007bd6 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | offset | 0x002249a0 | filetype | dBase IV DBT of `.DBF, block length 9216, next free block index 40, next free block 0, next used block 0 | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x000025a8 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_CHINESE | offset | 0x0022498c | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000014 | ||||||||||||||||||
name | RT_VERSION | language | LANG_CHINESE | offset | 0x00224648 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000344 | ||||||||||||||||||
name | RT_MANIFEST | language | LANG_CHINESE | offset | 0x002242e8 | filetype | XML 1.0 document, ASCII text, with CRLF line terminators | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x0000035d |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620985512.648784 Process32NextW |
process_name:
䅜灰慄慴䱜捯污呜浥屰戹愷㐰㤹敤扤换愲㙥愸愳搹慡㔴敢愲攮數
snapshot_handle: 0x00000160 process_identifier: 1919251285 |
failed | 0 | 0 |
Avast | Win32:Malware-gen |
F-Secure | Heuristic.HEUR/AGEN.1035796 |
Avira | HEUR/AGEN.1035796 |
Endgame | malicious (high confidence) |
AVG | Win32:Malware-gen |
entropy | 7.999547711354114 | section | {'size_of_data': '0x0008e200', 'virtual_address': '0x00001000', 'entropy': 7.999547711354114, 'name': '.text', 'virtual_size': '0x001ae000'} | description | A section with a high entropy has been found | |||||||||
entropy | 7.985874438088801 | section | {'size_of_data': '0x00008a00', 'virtual_address': '0x001af000', 'entropy': 7.985874438088801, 'name': '.data', 'virtual_size': '0x00027000'} | description | A section with a high entropy has been found | |||||||||
entropy | 7.92034731814359 | section | {'size_of_data': '0x00001200', 'virtual_address': '0x001d8000', 'entropy': 7.92034731814359, 'name': '.idata', 'virtual_size': '0x00004000'} | description | A section with a high entropy has been found | |||||||||
entropy | 7.741005761277137 | section | {'size_of_data': '0x00008a00', 'virtual_address': '0x001e3000', 'entropy': 7.741005761277137, 'name': '.rsrc', 'virtual_size': '0x0001f000'} | description | A section with a high entropy has been found | |||||||||
entropy | 7.992176533300218 | section | {'size_of_data': '0x00014400', 'virtual_address': '0x00202000', 'entropy': 7.992176533300218, 'name': '.reloc', 'virtual_size': '0x00021000'} | description | A section with a high entropy has been found | |||||||||
entropy | 0.9500657030223391 | description | Overall entropy of this PE file is high |
host | 172.217.24.14 |
Ordinal | Address | Name |
---|---|---|
19 | 0x4042c0 | @$xp$15Controls@TAlign |
20 | 0x404320 | @$xp$16Controls@TCursor |
21 | 0x404338 | @$xp$18Controls@TDragMode |
16 | 0x403760 | @$xp$26Shdocvw_tlb@TCppWebBrowser |
12 | 0x402f18 | @$xp$28Shdocvw_tlb@TCppShellWindows |
10 | 0x402e14 | @$xp$29Shdocvw_tlb@TCppShellUIHelper |
14 | 0x403070 | @$xp$32Shdocvw_tlb@TCppInternetExplorer |
6 | 0x402aa0 | @$xp$32Shdocvw_tlb@TShellShellNameSpace |
8 | 0x402c58 | @$xp$36Shdocvw_tlb@TShellFavoritesNameSpace |
22 | 0x40443c | @$xp$ynpqqrp14System@TObject$v |
No hosts contacted.
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 49175 | 222.186.170.171 cdn.ylzt.web.mlgame.wang | 80 |
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 49235 | 114.114.114.114 | 53 |
192.168.56.101 | 50534 | 114.114.114.114 | 53 |
192.168.56.101 | 51808 | 114.114.114.114 | 53 |
192.168.56.101 | 56539 | 114.114.114.114 | 53 |
192.168.56.101 | 58367 | 114.114.114.114 | 53 |
192.168.56.101 | 65004 | 114.114.114.114 | 53 |
192.168.56.101 | 137 | 192.168.56.255 | 137 |
192.168.56.101 | 138 | 192.168.56.255 | 138 |
192.168.56.101 | 123 | 20.189.79.72 time.windows.com | 123 |
192.168.56.101 | 55368 | 224.0.0.252 | 5355 |
192.168.56.101 | 56804 | 224.0.0.252 | 5355 |
192.168.56.101 | 60123 | 224.0.0.252 | 5355 |
192.168.56.101 | 62191 | 224.0.0.252 | 5355 |
192.168.56.101 | 1900 | 239.255.255.250 | 1900 |
192.168.56.101 | 56540 | 239.255.255.250 | 3702 |
192.168.56.101 | 56807 | 239.255.255.250 | 1900 |
192.168.56.101 | 58368 | 239.255.255.250 | 3702 |
192.168.56.101 | 58707 | 239.255.255.250 | 3702 |
URI | Data |
---|---|
http://cdn.ylzt.web.mlgame.wang/launcher/download/wd/launcher/data.zip?v=2496 | GET /launcher/download/wd/launcher/data.zip?v=2496 HTTP/1.1 Host: cdn.ylzt.web.mlgame.wang Accept: text/html, */* Accept-Encoding: identity User-Agent: Mozilla/3.0 (compatible; Indy Library) |
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts