4.8
中危

811ffe8f212e983b93f5f2d9e6e688a1e6ece170dbfcdcf254293127a3354bdb

a65c217e440d71ef0302c3eb71ca53ab.exe

分析耗时

73s

最近分析

文件大小

7.5MB
静态报毒 动态报毒 ARTEMIS DRUVZI GENERIC PUA JM MALWARE@#GWAT9BFNY6TX MTRA SCORE UNSAFE UNWADERS 更多
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
CrowdStrike 20190702 1.0
Baidu 20190318 1.0.0.2
Avast Win32:Malware-gen 20200623 18.4.3895.0
Alibaba 20190527 0.3.0.5
Kingsoft 20200623 2013.8.14.323
McAfee Artemis!A65C217E440D 20200623 6.0.6.653
Tencent 20200623 1.0.0.1
行为判定
动态指标
Creates an autorun.inf file (1 个事件)
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\inventar\Autorun.inf
Creates (office) documents on the filesystem (1 个事件)
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\tip\all128\ALL128-User-Guide.pdf
Creates executable files on the filesystem (50 out of 319 个事件)
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\aktuelledmtfdatetime.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\verz-suchen-loeschen.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\wmi-netzwerkeigenschaften.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\netzverb-zu-server.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\disk0-test.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\laufwerkliste.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\winnt-or-win9x.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\pckonfiguration-wintuc_fwmgr.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\dateinamespeichern.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\shell32dllversion.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\icq6-verlauflesen.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\ordnervergleich.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\dateienvergleich-1.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\verz-suchen-loeschen2.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\anmelden-an-win9x.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\patchlist.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\backup\datensich-2c.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\wmi-winver.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\cdauswerfen.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\dateierstellt.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\dez2hex.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\suchmaschine.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\ie-start.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\backup\datensich-3c.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\dateilisteholennachname.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\http-server-test.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\text-in-80-zeichen-je-zeile.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\inventar\REGOBJ.DLL
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\datei-in-datum-sichern.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\wschmelz-beispiele.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\stringanpositionindateitauschen.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\alleprozesseundtasks.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\druckerauswahl.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\lokalegruppen.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\inventar\inv-29CD.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\syntax-ipadr.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\mac-adr3.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\pcmitdhcp.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\mac-adr.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\lfdprozess-kill.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\ipnetz-loginscr.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\searchallmp3s.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\ramnutzung.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\inventar\Shelexec.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\searchmp3text.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\emailsenden_cmd.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\stundenschlag.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\deltree.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\skript-neustarten.vbs
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\1service_serviceentfernen.vbs
Drops an executable to the user AppData folder (27 个事件)
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\gepackt\WIM-BuR.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\backup\7zCon.sfx
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\Chiffr60.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\dir2htmlview.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\Chiff60S.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\backup\RAR.EXE
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\inventar\REGOBJ.DLL
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\backup\7z.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\Ramdisk.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\tip\ie5setup.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\backup\datensich-2c.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\wschmelz-beispiele.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\backup\default.sfx
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\inventar\inv-29CD.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\backup\datensich-36.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\backup\datensich-3c.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\copy_mp3_aus_m3u.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\zahlentheorie.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\inventar\Shelexec.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\desktopbild.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\backup\ROBOCOPY.EXE
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr-fu\cddurchsuchen\CDdurchsuchen.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\inventar\inventar29.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\inventar\SYSID.EXE
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\sudoku.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\allesschluss.exe
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dieseyer.de\scr\stundenschlag.exe
网络通信
Communicates with host for which no DNS query was performed (1 个事件)
host 172.217.24.14
File has been identified by 17 AntiVirus engines on VirusTotal as malicious (17 个事件)
Cylance Unsafe
Symantec Trojan.Gen.MBT
Avast Win32:Malware-gen
Kaspersky HEUR:Trojan.Script.Agent.gen
NANO-Antivirus Trojan.Script.Vbs-heuristic.druvzi
Comodo Malware@#gwat9bfny6tx
VIPRE Trojan.Win32.Generic!BT
McAfee-GW-Edition Artemis
Sophos Generic PUA JM (PUA)
Jiangmin Trojan.MSIL.mtra
Microsoft Program:Win32/Unwaders
AegisLab Worm.Script.Generic.o!c
ZoneAlarm HEUR:Trojan.Script.Agent.gen
McAfee Artemis!A65C217E440D
eGambit Unsafe.AI_Score_89%
AVG Win32:Malware-gen
Qihoo-360 Win32/Trojan.Script.af7
Connects to IP addresses that are no longer responding to requests (legitimate services will remain up-and-running usually) (2 个事件)
dead_host 172.217.24.14:443
dead_host 216.58.200.46:443
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2010-04-15 16:07:06

Imports

Library OLEAUT32.dll:
0x42016c SysAllocString
0x420170 SysFreeString
0x420174 VariantClear
Library ole32.dll:
0x420220 CoInitialize
0x420224 CoUninitialize
Library USER32.dll:
0x420190 MessageBoxW
0x420194 wsprintfA
0x420198 SetDlgItemTextA
0x42019c MapDialogRect
0x4201a0 ScreenToClient
0x4201a4 InvalidateRect
0x4201a8 SetTimer
0x4201ac DialogBoxParamW
0x4201b0 DialogBoxParamA
0x4201b4 SetWindowLongA
0x4201b8 GetWindowLongA
0x4201bc GetWindowRect
0x4201c0 ShowWindow
0x4201c4 MoveWindow
0x4201d0 SetCursor
0x4201d8 GetWindowTextA
0x4201dc SetWindowTextW
0x4201e0 SetWindowTextA
0x4201e4 SendMessageW
0x4201e8 LoadStringW
0x4201ec LoadStringA
0x4201f0 CharUpperW
0x4201f4 CharUpperA
0x4201f8 IsDlgButtonChecked
0x4201fc EndDialog
0x420200 GetDlgItem
0x420204 LoadIconA
0x420208 SendMessageA
0x42020c PostMessageA
0x420210 LoadCursorA
0x420214 KillTimer
0x420218 GetWindowTextW
Library SHELL32.dll:
0x42017c SHGetMalloc
0x420184 SHBrowseForFolderA
0x420188 SHGetFileInfoA
Library MSVCRT.dll:
0x4200fc __p__fmode
0x420100 __set_app_type
0x420104 _controlfp
0x420108 _adjust_fdiv
0x42010c __setusermatherr
0x420110 _initterm
0x420114 __getmainargs
0x420118 _acmdln
0x42011c exit
0x420120 _XcptFilter
0x420124 _exit
0x420128 _onexit
0x42012c __dllonexit
0x420134 _except_handler3
0x420138 _beginthreadex
0x42013c memset
0x420140 wcslen
0x420144 memcpy
0x420148 free
0x42014c malloc
0x420150 _CxxThrowException
0x420154 memmove
0x420158 _purecall
0x42015c memcmp
0x420160 __CxxFrameHandler
0x420164 __p__commode
Library KERNEL32.dll:
0x420000 GetStartupInfoA
0x420004 GetModuleHandleA
0x42000c ResetEvent
0x420010 SetEvent
0x420014 CreateEventA
0x420018 WaitForSingleObject
0x42001c VirtualFree
0x420020 VirtualAlloc
0x420024 GetCurrentProcess
0x420028 SetPriorityClass
0x42002c lstrcatA
0x420030 GetTickCount
0x420034 Sleep
0x420048 GetStdHandle
0x42004c GetModuleHandleW
0x420050 GetProcAddress
0x420058 SetEndOfFile
0x42005c WriteFile
0x420060 ReadFile
0x420064 SetFilePointer
0x420068 GetFileSize
0x42006c CreateFileA
0x420070 FindFirstFileW
0x420074 FindFirstFileA
0x420078 FindClose
0x420084 GetFullPathNameW
0x420088 GetFullPathNameA
0x42008c lstrlenA
0x420090 DeleteFileW
0x420094 DeleteFileA
0x420098 CreateDirectoryW
0x42009c CreateDirectoryA
0x4200a0 MoveFileW
0x4200a4 RemoveDirectoryW
0x4200a8 SetFileAttributesW
0x4200ac MoveFileA
0x4200b0 RemoveDirectoryA
0x4200b4 SetLastError
0x4200b8 CreateFileW
0x4200bc SetFileTime
0x4200c0 CloseHandle
0x4200c4 FormatMessageW
0x4200c8 FormatMessageA
0x4200cc LocalFree
0x4200d0 GetModuleFileNameW
0x4200d4 GetModuleFileNameA
0x4200d8 AreFileApisANSI
0x4200dc GetLastError
0x4200e0 WideCharToMultiByte
0x4200e4 MultiByteToWideChar
0x4200ec GetVersionExA
0x4200f0 GetCommandLineW
0x4200f4 SetFileAttributesA

Hosts

No hosts contacted.

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 50568 114.114.114.114 53
192.168.56.101 51963 114.114.114.114 53
192.168.56.101 60123 114.114.114.114 53
192.168.56.101 60215 114.114.114.114 53
192.168.56.101 62191 114.114.114.114 53
192.168.56.101 65004 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 123 20.189.79.72 time.windows.com 123
192.168.56.101 49235 224.0.0.252 5355
192.168.56.101 50002 224.0.0.252 5355
192.168.56.101 53657 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 57756 224.0.0.252 5355
192.168.56.101 57874 224.0.0.252 5355
192.168.56.101 58367 224.0.0.252 5355
192.168.56.101 60384 224.0.0.252 5355
192.168.56.101 62912 224.0.0.252 5355
192.168.56.101 63429 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.