10.0
0-day

144903e623b5997d6856a3880393ebe02411b41c1aec3460168a59e2ec00aba5

9be4e1ec86dbe756cc6d1c593346fa8e.exe

分析耗时

97s

最近分析

文件大小

519.0KB
静态报毒 动态报毒 AI SCORE=84 ANDROM ATTRIBUTE CIVEI CONFIDENCE CRYPTINJECT ELDORADO FAREIT GDSDA GENERICKD GM0@AOWYA1I HIGH CONFIDENCE HIGHCONFIDENCE HSMYAM HXZW KRYPTIK MALICIOUS PE MSILKRYPT PACKEDNET PWSX R02DC0DHJ20 R348272 SCORE SUSGEN TSCOPE UNSAFE WOREFLINT ZEMSILF ZMUTZY 更多
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
McAfee Fareit-FYE!9BE4E1EC86DB 20200901 6.0.6.653
Alibaba Backdoor:MSIL/CryptInject.7c6d96ef 20190527 0.3.0.5
CrowdStrike win/malicious_confidence_80% (D) 20190702 1.0
Avast Win32:PWSX-gen [Trj] 20200901 18.4.3895.0
Baidu 20190318 1.0.0.2
Kingsoft 20200901 2013.8.14.323
Tencent Msil.Trojan.Agent.Hxzw 20200901 1.0.0.1
静态指标
Queries for the computername (3 个事件)
Time & API Arguments Status Return Repeated
1619812026.38575
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619812031.291125
GetComputerNameA
computer_name: OSKAR-PC
success 1 0
1619812031.291125
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
Checks if process is being debugged by a debugger (12 个事件)
Time & API Arguments Status Return Repeated
1619781071.690241
IsDebuggerPresent
failed 0 0
1619781124.706241
IsDebuggerPresent
failed 0 0
1619781125.206241
IsDebuggerPresent
failed 0 0
1619781125.721241
IsDebuggerPresent
failed 0 0
1619781126.206241
IsDebuggerPresent
failed 0 0
1619781126.721241
IsDebuggerPresent
failed 0 0
1619781127.206241
IsDebuggerPresent
failed 0 0
1619781127.721241
IsDebuggerPresent
failed 0 0
1619781128.206241
IsDebuggerPresent
failed 0 0
1619781128.737241
IsDebuggerPresent
failed 0 0
1619812030.197375
IsDebuggerPresent
failed 0 0
1619812030.478375
IsDebuggerPresent
failed 0 0
Command line console output was observed (1 个事件)
Time & API Arguments Status Return Repeated
1619812027.44775
WriteConsoleW
buffer: 成功: 成功创建计划任务 "Updates\BazqqSYZaWC"。
console_handle: 0x00000007
success 1 0
Checks amount of memory in system, this can be used to detect virtual machines that have a low amount of memory available (1 个事件)
Time & API Arguments Status Return Repeated
1619781072.487241
GlobalMemoryStatusEx
success 1 0
行为判定
动态指标
One or more potentially interesting buffers were extracted, these generally contain injected code, configuration data, etc.
Allocates read-write-execute memory (usually to unpack itself) (50 out of 102 个事件)
Time & API Arguments Status Return Repeated
1619781070.893241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 1310720
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 8192 (MEM_RESERVE)
base_address: 0x004b0000
success 0 0
1619781070.893241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x005b0000
success 0 0
1619781071.581241
NtProtectVirtualMemory
process_identifier: 2296
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x73f31000
success 0 0
1619781071.706241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003ba000
success 0 0
1619781071.706241
NtProtectVirtualMemory
process_identifier: 2296
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x73f32000
success 0 0
1619781071.706241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003b2000
success 0 0
1619781071.909241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003c2000
success 0 0
1619781072.112241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003c3000
success 0 0
1619781072.143241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003fb000
success 0 0
1619781072.143241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003f7000
success 0 0
1619781072.206241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003cc000
success 0 0
1619781072.362241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00590000
success 0 0
1619781072.456241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00591000
success 0 0
1619781072.518241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00592000
success 0 0
1619781073.112241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003c4000
success 0 0
1619781073.237241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003c5000
success 0 0
1619781073.237241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003c6000
success 0 0
1619781073.331241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003c7000
success 0 0
1619781073.440241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003da000
success 0 0
1619781073.440241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003d7000
success 0 0
1619781073.456241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003ea000
success 0 0
1619781073.534241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003bb000
success 0 0
1619781073.706241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00593000
success 0 0
1619781074.159241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00595000
success 0 0
1619781074.471241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003e2000
success 0 0
1619781074.565241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003f5000
success 0 0
1619781074.628241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003d6000
success 0 0
1619781074.659241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003c8000
success 0 0
1619781074.706241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00596000
success 0 0
1619781116.221241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x005b1000
success 0 0
1619781116.253241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00597000
success 0 0
1619781116.362241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003ec000
success 0 0
1619781116.393241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00598000
success 0 0
1619781116.409241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003c9000
success 0 0
1619781116.425241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00599000
success 0 0
1619781116.487241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003ca000
success 0 0
1619781116.518241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x04a10000
success 0 0
1619781116.518241
NtProtectVirtualMemory
process_identifier: 2296
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 360960
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x04b20400
failed 3221225550 0
1619781123.893241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x0059a000
success 0 0
1619781123.893241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x0059b000
success 0 0
1619781123.987241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x0059c000
success 0 0
1619781124.065241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x0059d000
success 0 0
1619781124.081241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x0059e000
success 0 0
1619781124.268241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x04a30000
success 0 0
1619781124.300241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x0059f000
success 0 0
1619781124.550241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x04da0000
success 0 0
1619781124.550241
NtAllocateVirtualMemory
process_identifier: 2296
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x04da1000
success 0 0
1619781124.550241
NtProtectVirtualMemory
process_identifier: 2296
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x04b20178
failed 3221225550 0
1619781124.550241
NtProtectVirtualMemory
process_identifier: 2296
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x04b201a0
failed 3221225550 0
1619781124.550241
NtProtectVirtualMemory
process_identifier: 2296
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x04b201c8
failed 3221225550 0
Creates a suspicious process (2 个事件)
cmdline schtasks.exe /Create /TN "Updates\BazqqSYZaWC" /XML "C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\tmp2522.tmp"
cmdline "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\BazqqSYZaWC" /XML "C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\tmp2522.tmp"
A process created a hidden window (1 个事件)
Time & API Arguments Status Return Repeated
1619781125.362241
ShellExecuteExW
parameters: /Create /TN "Updates\BazqqSYZaWC" /XML "C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\tmp2522.tmp"
filepath: schtasks.exe
filepath_r: schtasks.exe
show_type: 0
success 1 0
The binary likely contains encrypted or compressed data indicative of a packer (2 个事件)
entropy 7.928671113726509 section {'size_of_data': '0x00081200', 'virtual_address': '0x00002000', 'entropy': 7.928671113726509, 'name': '.text', 'virtual_size': '0x00081114'} description A section with a high entropy has been found
entropy 0.996142719382835 description Overall entropy of this PE file is high
Checks for the Locally Unique Identifier on the system for a suspicious privilege (1 个事件)
Time & API Arguments Status Return Repeated
1619781116.518241
LookupPrivilegeValueW
system_name:
privilege_name: SeDebugPrivilege
success 1 0
Uses Windows utilities for basic Windows functionality (2 个事件)
cmdline schtasks.exe /Create /TN "Updates\BazqqSYZaWC" /XML "C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\tmp2522.tmp"
cmdline "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\BazqqSYZaWC" /XML "C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\tmp2522.tmp"
网络通信
Communicates with host for which no DNS query was performed (1 个事件)
host 172.217.24.14
Allocates execute permission to another process indicative of possible code injection (1 个事件)
Time & API Arguments Status Return Repeated
1619781128.440241
NtAllocateVirtualMemory
process_identifier: 176
region_size: 417792
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0x000103ec
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x00400000
success 0 0
Deletes executed files from disk (1 个事件)
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\tmp2522.tmp
Potential code injection by writing to the memory of another process (4 个事件)
Time & API Arguments Status Return Repeated
1619781128.440241
WriteProcessMemory
process_identifier: 176
buffer: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PELÁ:_à  òþ @ `@…¨S 8@  H.textñ ò `.rsrc8 ô@@.reloc @ú@B
process_handle: 0x000103ec
base_address: 0x00400000
success 1 0
1619781128.456241
WriteProcessMemory
process_identifier: 176
buffer:  €P€8€€h€  ¬L#ê¬4VS_VERSION_INFO½ïþ?DVarFileInfo$Translation° StringFileInfoè000004b0,FileDescription 0FileVersion0.0.0.0l&InternalNametsETmJzIdYWIwRAnLoIEQwRWjrZMpRbtP.exe(LegalCopyright t&OriginalFilenametsETmJzIdYWIwRAnLoIEQwRWjrZMpRbtP.exe4ProductVersion0.0.0.08Assembly Version0.0.0.0<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <requestedExecutionLevel level="asInvoker" uiAccess="false"/> </requestedPrivileges> </security> </trustInfo> </assembly>
process_handle: 0x000103ec
base_address: 0x00462000
success 1 0
1619781128.456241
WriteProcessMemory
process_identifier: 176
buffer:  1
process_handle: 0x000103ec
base_address: 0x00464000
success 1 0
1619781128.456241
WriteProcessMemory
process_identifier: 176
buffer: @
process_handle: 0x000103ec
base_address: 0x7efde008
success 1 0
Code injection by writing an executable or DLL to the memory of another process (1 个事件)
Time & API Arguments Status Return Repeated
1619781128.440241
WriteProcessMemory
process_identifier: 176
buffer: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PELÁ:_à  òþ @ `@…¨S 8@  H.textñ ò `.rsrc8 ô@@.reloc @ú@B
process_handle: 0x000103ec
base_address: 0x00400000
success 1 0
Used NtSetContextThread to modify a thread in a remote process indicative of process injection (2 个事件)
Process injection Process 2296 called NtSetContextThread to modify thread in remote process 176
Time & API Arguments Status Return Repeated
1619781128.456241
NtSetContextThread
thread_handle: 0x000053f0
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 4591870
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 176
success 0 0
Resumed a suspended thread in a remote process potentially indicative of process injection (2 个事件)
Process injection Process 2296 resumed a thread in remote process 176
Time & API Arguments Status Return Repeated
1619781128.815241
NtResumeThread
thread_handle: 0x000053f0
suspend_count: 1
process_identifier: 176
success 0 0
Executed a process and injected code into it, probably while unpacking (20 个事件)
Time & API Arguments Status Return Repeated
1619781071.690241
NtResumeThread
thread_handle: 0x000000d0
suspend_count: 1
process_identifier: 2296
success 0 0
1619781071.753241
NtResumeThread
thread_handle: 0x00000158
suspend_count: 1
process_identifier: 2296
success 0 0
1619781124.690241
NtResumeThread
thread_handle: 0x0000cd84
suspend_count: 1
process_identifier: 2296
success 0 0
1619781124.706241
NtResumeThread
thread_handle: 0x0000f524
suspend_count: 1
process_identifier: 2296
success 0 0
1619781125.346241
CreateProcessInternalW
thread_identifier: 2944
thread_handle: 0x00001fc8
process_identifier: 2960
current_directory: C:\Users\Administrator.Oskar-PC\AppData\Local\Temp
filepath: C:\Windows\System32\schtasks.exe
track: 1
command_line: "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\BazqqSYZaWC" /XML "C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\tmp2522.tmp"
filepath_r: C:\Windows\System32\schtasks.exe
stack_pivoted: 0
creation_flags: 67634192 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
process_handle: 0x0000c6e8
inherit_handles: 0
success 1 0
1619781128.425241
CreateProcessInternalW
thread_identifier: 2144
thread_handle: 0x000053f0
process_identifier: 176
current_directory:
filepath: C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\9be4e1ec86dbe756cc6d1c593346fa8e.exe
track: 1
command_line: "{path}"
filepath_r: C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\9be4e1ec86dbe756cc6d1c593346fa8e.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
process_handle: 0x000103ec
inherit_handles: 0
success 1 0
1619781128.440241
NtGetContextThread
thread_handle: 0x000053f0
success 0 0
1619781128.440241
NtAllocateVirtualMemory
process_identifier: 176
region_size: 417792
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0x000103ec
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x00400000
success 0 0
1619781128.440241
WriteProcessMemory
process_identifier: 176
buffer: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PELÁ:_à  òþ @ `@…¨S 8@  H.textñ ò `.rsrc8 ô@@.reloc @ú@B
process_handle: 0x000103ec
base_address: 0x00400000
success 1 0
1619781128.440241
WriteProcessMemory
process_identifier: 176
buffer:
process_handle: 0x000103ec
base_address: 0x00402000
success 1 0
1619781128.456241
WriteProcessMemory
process_identifier: 176
buffer:  €P€8€€h€  ¬L#ê¬4VS_VERSION_INFO½ïþ?DVarFileInfo$Translation° StringFileInfoè000004b0,FileDescription 0FileVersion0.0.0.0l&InternalNametsETmJzIdYWIwRAnLoIEQwRWjrZMpRbtP.exe(LegalCopyright t&OriginalFilenametsETmJzIdYWIwRAnLoIEQwRWjrZMpRbtP.exe4ProductVersion0.0.0.08Assembly Version0.0.0.0<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <requestedExecutionLevel level="asInvoker" uiAccess="false"/> </requestedPrivileges> </security> </trustInfo> </assembly>
process_handle: 0x000103ec
base_address: 0x00462000
success 1 0
1619781128.456241
WriteProcessMemory
process_identifier: 176
buffer:  1
process_handle: 0x000103ec
base_address: 0x00464000
success 1 0
1619781128.456241
WriteProcessMemory
process_identifier: 176
buffer: @
process_handle: 0x000103ec
base_address: 0x7efde008
success 1 0
1619781128.456241
NtSetContextThread
thread_handle: 0x000053f0
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 4591870
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 176
success 0 0
1619781128.815241
NtResumeThread
thread_handle: 0x000053f0
suspend_count: 1
process_identifier: 176
success 0 0
1619781128.815241
NtResumeThread
thread_handle: 0x0000ea80
suspend_count: 1
process_identifier: 2296
success 0 0
1619812030.197375
NtResumeThread
thread_handle: 0x000000d0
suspend_count: 1
process_identifier: 176
success 0 0
1619812030.228375
NtResumeThread
thread_handle: 0x00000158
suspend_count: 1
process_identifier: 176
success 0 0
1619812030.760375
CreateProcessInternalW
thread_identifier: 3040
thread_handle: 0x000001ac
process_identifier: 1036
current_directory:
filepath: C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe
track: 1
command_line: dw20.exe -x -s 392
filepath_r: C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe
stack_pivoted: 0
creation_flags: 0 ()
process_handle: 0x000001a8
inherit_handles: 1
success 1 0
1619812031.306125
NtResumeThread
thread_handle: 0x000000bc
suspend_count: 1
process_identifier: 1036
success 0 0
File has been identified by 52 AntiVirus engines on VirusTotal as malicious (50 out of 52 个事件)
Elastic malicious (high confidence)
DrWeb Trojan.PackedNET.405
MicroWorld-eScan Trojan.GenericKD.43684417
FireEye Generic.mg.9be4e1ec86dbe756
CAT-QuickHeal Trojan.Multi
McAfee Fareit-FYE!9BE4E1EC86DB
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Malware
K7AntiVirus Trojan ( 0056cb4e1 )
Alibaba Backdoor:MSIL/CryptInject.7c6d96ef
K7GW Trojan ( 0056cb4e1 )
CrowdStrike win/malicious_confidence_80% (D)
Arcabit Trojan.Generic.D29A9241
Invincea heuristic
BitDefenderTheta Gen:NN.ZemsilF.34196.Gm0@aOwYA1i
Cyren W32/MSIL_Kryptik.BKZ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.XJJ
TrendMicro-HouseCall TROJ_GEN.R02DC0DHJ20
Kaspersky HEUR:Trojan.MSIL.Agent.gen
BitDefender Trojan.GenericKD.43684417
NANO-Antivirus Trojan.Win32.Androm.hsmyam
ViRobot Trojan.Win32.Z.Woreflint.531456
Avast Win32:PWSX-gen [Trj]
Ad-Aware Trojan.GenericKD.43684417
F-Secure Trojan.TR/Kryptik.civei
Zillya Trojan.Kryptik.Win32.2389856
TrendMicro TROJ_GEN.R02DC0DHJ20
Sophos Mal/Generic-S
Ikarus Trojan.MSIL.Crypt
Webroot W32.Malware.gen
Avira TR/Kryptik.civei
Microsoft Trojan:MSIL/CryptInject.AR!MTB
AegisLab Trojan.Multi.Generic.4!c
ZoneAlarm HEUR:Backdoor.MSIL.Androm.gen
GData Trojan.GenericKD.43684417
Cynet Malicious (score: 85)
AhnLab-V3 Trojan/Win32.MSILKrypt.R348272
VBA32 TScope.Trojan.MSIL
ALYac Trojan.GenericKD.43684417
MAX malware (ai score=84)
Malwarebytes Trojan.MalPack.PNG.Generic
APEX Malicious
Tencent Msil.Trojan.Agent.Hxzw
SentinelOne DFI - Malicious PE
Fortinet MSIL/Zmutzy.CDD!tr
MaxSecure Trojan.Malware.300983.susgen
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.eff207
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2020-08-18 11:03:50

Imports

Library mscoree.dll:
0x402000 _CorExeMain

Hosts

No hosts contacted.

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53237 114.114.114.114 53
192.168.56.101 57756 114.114.114.114 53
192.168.56.101 58367 114.114.114.114 53
192.168.56.101 60384 114.114.114.114 53
192.168.56.101 62318 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 49235 224.0.0.252 5355
192.168.56.101 49713 224.0.0.252 5355
192.168.56.101 50534 224.0.0.252 5355
192.168.56.101 51963 224.0.0.252 5355
192.168.56.101 53657 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 57874 224.0.0.252 5355
192.168.56.101 62191 224.0.0.252 5355
192.168.56.101 63429 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900
192.168.56.101 49238 239.255.255.250 1900
192.168.56.101 58368 239.255.255.250 3702
192.168.56.101 58707 239.255.255.250 3702

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.