1.3
低危

203b70ba0c67204a1087e509cd7197700781133f9c50c76b63470faa8c7489f3

203b70ba0c67204a1087e509cd7197700781133f9c50c76b63470faa8c7489f3.exe

分析耗时

194s

最近分析

366天前

文件大小

43.0KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN DOWNLOADER UPATRE
鹰眼引擎
DACN 0.12
FACILE 1.00
IMCLNet 0.69
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba None 20190527 0.3.0.5
Avast Win32:Malware-gen 20200709 18.4.3895.0
Baidu Win32.Trojan.Kryptik.jq 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (D) 20190702 1.0
Kingsoft None 20200709 2013.8.14.323
McAfee GenericRXBC-FD!B504DFEB42BE 20200709 6.0.6.653
Tencent Malware.Win32.Gencirc.10b9ccb3 20200709 1.0.0.1
静态指标
行为判定
动态指标
在 PE 资源中识别到外语 (23 个事件)
name RT_CURSOR language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x00007e90 size 0x00000134
name RT_CURSOR language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x00007e90 size 0x00000134
name RT_CURSOR language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x00007e90 size 0x00000134
name RT_CURSOR language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x00007e90 size 0x00000134
name RT_BITMAP language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x00006cf8 size 0x000000e0
name RT_BITMAP language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x00006cf8 size 0x000000e0
name RT_BITMAP language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x00006cf8 size 0x000000e0
name RT_BITMAP language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x00006cf8 size 0x000000e0
name RT_BITMAP language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x00006cf8 size 0x000000e0
name RT_BITMAP language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x00006cf8 size 0x000000e0
name RT_BITMAP language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x00006cf8 size 0x000000e0
name RT_ICON language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x00007fe0 size 0x00004228
name RT_RCDATA language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x000079c8 size 0x000000d4
name RT_RCDATA language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x000079c8 size 0x000000d4
name RT_RCDATA language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x000079c8 size 0x000000d4
name RT_RCDATA language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x000079c8 size 0x000000d4
name RT_GROUP_CURSOR language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x00007fc8 size 0x00000014
name RT_GROUP_CURSOR language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x00007fc8 size 0x00000014
name RT_GROUP_CURSOR language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x00007fc8 size 0x00000014
name RT_GROUP_CURSOR language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x00007fc8 size 0x00000014
name RT_GROUP_ICON language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x0000c208 size 0x00000014
name RT_VERSION language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x0000c428 size 0x00000264
name RT_MANIFEST language LANG_ROMANIAN filetype None sublanguage SUBLANG_ROMANIAN offset 0x0000c220 size 0x00000206
该二进制文件可能包含加密或压缩数据,表明使用了打包工具 (1 个事件)
section {'name': '.data', 'virtual_address': '0x00003000', 'virtual_size': '0x000026e0', 'size_of_data': '0x00001600', 'entropy': 7.537076091616508} entropy 7.537076091616508 description 发现高熵的节
网络通信
与未执行 DNS 查询的主机进行通信 (2 个事件)
host 114.114.114.114
host 8.8.8.8
文件已被 VirusTotal 上 61 个反病毒引擎识别为恶意 (50 out of 61 个事件)
ALYac Trojan.Upatre.Gen.3
APEX Malicious
AVG Win32:Malware-gen
Acronis suspicious
Ad-Aware Trojan.Upatre.Gen.3
AhnLab-V3 Trojan/Win32.Upatre.R153994
Antiy-AVL Trojan/Win32.AGeneric
Arcabit Trojan.Upatre.Gen.3
Avast Win32:Malware-gen
Avira TR/AD.Yarwi.oikyx
Baidu Win32.Trojan.Kryptik.jq
BitDefender Trojan.Upatre.Gen.3
BitDefenderTheta Gen:NN.ZexaF.34132.cq1@aaaKtclG
Bkav W32.AIDetectVM.malware1
CAT-QuickHeal TrojanDwnLdr.Upatre.A3
ClamAV Win.Downloader.Upatre-5744092-0
Comodo TrojWare.Win32.TrojanDownloader.Waski.FSA@5su3z8
CrowdStrike win/malicious_confidence_100% (D)
Cybereason malicious.b42be7
Cylance Unsafe
Cynet Malicious (score: 100)
Cyren W32/Upatre.AX.gen!Eldorado
DrWeb Trojan.DownLoader14.7198
ESET-NOD32 a variant of Win32/Kryptik.DNCM
Emsisoft Trojan.Upatre.Gen.3 (B)
Endgame malicious (high confidence)
F-Prot W32/Upatre.AX.gen!Eldorado
F-Secure Trojan.TR/AD.Yarwi.oikyx
FireEye Generic.mg.b504dfeb42be7863
Fortinet W32/Kryptik.DNCM!tr
GData Win32.Trojan-Downloader.Upatre.BK
Ikarus Trojan.Upatre
Invincea heuristic
Jiangmin TrojanDownloader.Upatre.qlg
K7AntiVirus Trojan-Downloader ( 0055c6c71 )
K7GW Trojan-Downloader ( 0055c6c71 )
Kaspersky HEUR:Trojan.Win32.Generic
MAX malware (ai score=81)
Malwarebytes Trojan.Upatre
McAfee GenericRXBC-FD!B504DFEB42BE
MicroWorld-eScan Trojan.Upatre.Gen.3
Microsoft TrojanDownloader:Win32/Upatre.BN
NANO-Antivirus Trojan.Win32.Dwn.egvwmz
Panda Trj/Upatre.B
Qihoo-360 QVM06.1.Malware.Gen
Rising Trojan.Waski!1.A489 (CLASSIC)
SUPERAntiSpyware Trojan.Agent/Gen-Upatre
Sangfor Malware
SentinelOne DFI - Malicious PE
Sophos Troj/Dyreza-FY
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2013-05-18 08:22:46

PE Imphash

ceb4df4fc7a32291bf4220f8b82c5b56

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00000d84 0x00000e00 6.192751458830495
.rdata 0x00002000 0x0000092a 0x00000a00 4.5165088462219725
.data 0x00003000 0x000026e0 0x00001600 7.537076091616508
.rsrc 0x00006000 0x00006e60 0x00007000 5.428713269791334

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x00007e90 0x00000134 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_CURSOR 0x00007e90 0x00000134 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_CURSOR 0x00007e90 0x00000134 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_CURSOR 0x00007e90 0x00000134 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_BITMAP 0x00006cf8 0x000000e0 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_BITMAP 0x00006cf8 0x000000e0 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_BITMAP 0x00006cf8 0x000000e0 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_BITMAP 0x00006cf8 0x000000e0 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_BITMAP 0x00006cf8 0x000000e0 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_BITMAP 0x00006cf8 0x000000e0 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_BITMAP 0x00006cf8 0x000000e0 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_ICON 0x00007fe0 0x00004228 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_DIALOG 0x00006dd8 0x00000052 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x0000c7b8 0x000000f0 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x0000c7b8 0x000000f0 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x0000c7b8 0x000000f0 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x0000c7b8 0x000000f0 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x0000c7b8 0x000000f0 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x0000c7b8 0x000000f0 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x0000c7b8 0x000000f0 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x0000c7b8 0x000000f0 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_RCDATA 0x000079c8 0x000000d4 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_RCDATA 0x000079c8 0x000000d4 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_RCDATA 0x000079c8 0x000000d4 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_RCDATA 0x000079c8 0x000000d4 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_GROUP_CURSOR 0x00007fc8 0x00000014 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_GROUP_CURSOR 0x00007fc8 0x00000014 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_GROUP_CURSOR 0x00007fc8 0x00000014 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_GROUP_CURSOR 0x00007fc8 0x00000014 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_GROUP_ICON 0x0000c208 0x00000014 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_VERSION 0x0000c428 0x00000264 LANG_ROMANIAN SUBLANG_ROMANIAN None
RT_MANIFEST 0x0000c220 0x00000206 LANG_ROMANIAN SUBLANG_ROMANIAN None

Imports

Library USER32.dll:
0x402040 LoadAcceleratorsA
0x402044 LoadIconA
0x402048 RegisterClassExA
0x40204c GetMessageA
0x402050 LoadStringA
0x402054 TranslateMessage
0x402058 DispatchMessageA
0x40205c BeginPaint
0x402060 EndPaint
0x402068 LoadCursorA
0x40206c ShowWindow
0x402070 CreateWindowExA
0x402074 DefWindowProcA
0x402078 SendMessageA
0x40207c DestroyWindow
0x402080 PostQuitMessage
0x402084 SetFocus
0x402088 UpdateWindow
Library KERNEL32.dll:
0x402008 HeapAlloc
0x40200c GetStartupInfoA
0x402010 GetModuleHandleA
0x402014 ExitProcess
0x402018 GetCommandLineA
0x40201c GetProcessHeap
0x402020 CreateDirectoryA
0x402024 GetCommandLineW
0x402028 lstrlenA
0x40202c LoadLibraryA
0x402030 WriteProcessMemory
Library GDI32.dll:
0x402000 TextOutA
Library SHELL32.dll:
0x402038 CommandLineToArgvW
Library WTSAPI32.dll:
0x402094 WTSLogoffSession
0x40209c WTSWaitSystemEvent

L!This program cannot be run in DOS mode.
[[[AG[A
[AB[Z[AF[A
[Af[Rich[
`.rdata
@.data
\n3NTBB_BBN
PFULSVu
jhVjdhHV@
UjlREE
t@=d @
pdwuUDV
<"u>"u
HtiHtS
|3_^[]
PQ3_^[]
RXQ]]]
P(MQhxX
+j }WO<
P(MQhXX
P(MQh4X
]2^]Up
Au^H;E
URE3PM3
3EEt"N
URE3PME
4Q4RLP
Educate
Quxtim
UpdateWindow
ShowWindow
CreateWindowExA
DefWindowProcA
SendMessageA
DestroyWindow
SetFocus
PostQuitMessage
EndPaint
BeginPaint
DispatchMessageA
TranslateMessage
TranslateAcceleratorA
GetMessageA
RegisterClassExA
LoadIconA
LoadCursorA
LoadStringA
LoadAcceleratorsA
USER32.dll
WriteProcessMemory
CreateDirectoryA
LoadLibraryA
lstrlenA
GetCommandLineW
KERNEL32.dll
TextOutA
GDI32.dll
CommandLineToArgvW
SHELL32.dll
WTSQuerySessionInformationA
WTSLogoffSession
WTSEnumerateProcessesA
WTSWaitSystemEvent
WTSAPI32.dll
ExitProcess
GetModuleHandleA
GetStartupInfoA
GetCommandLineA
HeapAlloc
GetProcessHeap
vNd46Ej
is@gj=m,f
pId@0q}d#
t}l%1p|o
afV@!qah2
u0)VjV@.W]t%
pjd4)kGq
2~n/pFj|U`P$cd"-1<)
$`.tU6!!
m77@p!d@_7;1rfa|y%fjfb/
!/rT1b3qWc!1n_=f3rWj82vH*
qQ5;4vfc>o'f5=/qR
<:0v_2b3qWc!6nW<f3rWj67sH6 frTt=/rS7>h-
5h5nU7>.)
5a7xH*=h-
5h3nT<?h-
5h1xH*!2@I6!f@W6=/x_i>q.
773nT+=0n
5=/sW+=0n
5=/sW+=0n
5=/rQ7b3qWc<5sH* frTt98nT5 frTt80wS7<h-
5h9xH*!
wS6<6@I6!f@Q<!.)
5a6qH*8.)
5a8xH*>
v_0>5@I6!f@P796sfc>o'f592sfc>o'f=<3tfc>o'f*63uVi>q.
*=5pfc>o'f6=/rQi>q.
<;0nT+=0n
6;3qQ<b3qWc!8nQ2f3rWj91uH*
2nT68.)
5a7tH*<.)
5a6wH7:.)
5a6wH59.)
5a2wH5>
yS7>1@I6!f@W6=/qV
!9nT5f3rWj>
e\Hqd:zwT@!
P#(LJ$Q=P
HDP^i3
&]Hqik(<\$5U9
4R@0+%,
-o<\"f
YwT0E9-o<\"DA
@f$0-?#DVr
fL+u]#`
b60eg>rL+,gUT#b
NzlR3`
I}:zt5kp:zhwT4T
pRxNzht8
9Rb!_cU
y%n7#-S
xV3wQL
8++NJ4wTDU]S@
&\Hpni
w,I&$b6
ppl:Z6@fwQ
3Yt$NJP
Y5knW*e
Htd&8}
tV\HqLJ4
|'LJPLk&
`n:Z*e
mwTDX&
R:zTwTPI0dw
\iO&w%2
mi$(30b
1t+NH5
Q3Rp7]HJX5k
0E@f#7]+'
e5niwO
Riched32.dll
Clariot
Best Application
static
button
richedit
www30www
xwwwwwxwwwwrwwwwww
ffffff
aGGDDV
tttDP`
twGD``awwGtu
PawwwGE
PffffffWP
GtwwwP
33333333
wwwwpwwwww
UUUUUUUUUp
DDDDUU
DDDDUU
DDDDUU
UUUwwww
UUUUUUUUUU@
articons
ucicons
System
SysInit
KWindows
3Messages
SysUtils
SysConst
^Classes
Consts
QTypInfo
sActiveX
+Graphics
&Controls
Printers
WWinSpool
Commctrl
FlatSB
StdActns
Clipbrd
EActnList
vMenus
Contnrs
ImgList
dStdCtrls
MultiMon
Dialogs
ExtCtrls
3CommDlg
(ShlObj
*ShellAPI
RegStr
?WinInet
UrlMon
Buttons
nComCtrls
ComStrs
RichEdit
ToolWin
8Registry
IniFiles
akernel
aiclopd
ExtDlgs
XGrids
IconLibrary
subIcon
AdvancedIcon
IconTypes
Magrutil
Qapalconst
apalutil
pngimage
aresample
*Fast256
oFastRGB
FastBMP
"RTLConsts
pngzlib
pnglang
!GIFImage
GMMSystem
agrfile
FileMappingStream
ageometry
Nasmooth
{astream
unitPEFile
unitResourceDetails
Imagehlp
aIconTools
oacompres
unitResourceGraphics
unitExIcon
CursorLibrary
FileCtrl
aregistry
iconproject
agradutil
;aundo
afilesys
astrrus
macwinicon
jconsts
OpenJpeg
Jpeg2000Bitmap
borlanddcr
unitResFile
_aerrList
FComObj
qComConst
gagrstrings
<amenureop
Lsinter
/aimagebutton
edregkey
gridmenu
newimage
confirm
Childwin
#aExeImage
arxtypes
icobox
TntGraphics
TntClasses
TntTypInfo
TntSystem
TntWindows
TntSysUtils
TntFormatStrUtils
edfiletypes
[uselcolor16
uselcolor16Ex
uPatternBG
xpmimage
=palview
iabrowsedir
1psdimage
animatedcursor
WBMPIMAGE
Waniproject
bSZCodeBaseX
aGifFramer
Liconapputils
expSingle
iconresupdate
uimportil
unewimagesize
ucustomsize
uAskDups
ouFindInFolder
|impimg
addtxt
$TntStdCtrls
sTntForms
6TntMenus
TntControls
TntActnList
TntStdActns
`TntDialogs
xTntClipBrd
QTntExtCtrls
)CheckLst
rselgrad
1uselTrack
uNegative
auDropShadow
fuSelPaste
:ucanvassize
uOpacity
uLayerProps
uNewLayer
uRotate
/ureplacecolor
@uHueSaturation
linewidthmenu
uContrast
uSmoothSharp
aniimage
utesticon
fileass
aregfileext
nainternet
WinSock
edhotspot
OldCreateOrder
Height
TSaveDialog
Filter
8Icon Library (*.icl)|*.icl|Icon Collection (*.icc)|*.icc
Options
ofHideReadOnly
OnCanClose
sdLibCanClose
TColorDialog
Options
cdFullOpen
cdAnyColor
TOpenDialog
Filter
Palettes and images (*.pal;*.act;*.bmp)|*.act;*.pal;*.bmp|Microsoft palette (*.pal)|*.pal|Color tables (*.act)|*.act|Bitmaps (*.bmp)|*.bmp|Color table resource (*.rc)|*.rc|All files (*.*)|*.*
TSaveDialog
DefaultExt
Filter
MS Palette (*.pal)|*.pal|Bitmap (*.bmp)|*.bmp|Color table (*.act)|*.act|Color table resource (*.rc)|*.rc|Pascal TRGB const (*.pas)|*.pas
Options
ofOverwritePrompt
ofHideReadOnly
ofEnableSizing
OnTypeChange
sdPalTypeChange
TfmChildAbstract
fmChildAbstract
BorderIcons
BorderStyle
bsNone
ClientHeight
ClientWidth
clBtnFace
ParentFont
OldCreateOrder
Position
poDefault
PixelsPerInch
TextHeight
z$o&'
<Gr~,,
9KRX4:
jp}kr{rzovqtnonpprrwox|o{|oy
ouqsnoqtrwqvrwqvrxsxswrwsxrxuxqqqq
}}}{{{zzz{{z
|||tttpppooonoommm}}}
vvviiiiii|}{
$** +**
( **+** +**&
' **((!*
XY!&!)(*(()((')
!*)!+!* ) )",*
!- )") ) )!* )!* )".
$('#.#,",",#- *
*"54;+3
t}"/%.$2$4",",#-",",#,",#. *#.
!$* '#/$0#/#/$/!*
$#-$0#/#/$0#/$/#/#/$/ )$.
! #)"+$1%/#/%/#/#.
"&2#/#/%/#/$0#/#/$1"-$/
$&%,%2%1$0$/%1(&5
"!,%/%,
$0$/%/$/%1$/$/%0%3"/
%%'/'4&/$/$/%/"+'4
(amercea]..
",%-OWgqeifi68"+#2$.
fqepjrjpkoKR *$/$0$/$/%0$/$/%0%1&2
())0(4&0%/%/'0&0+7%/","+)6&0*6%2*7)3)6'2$/$1#.$0'8+8%/+:%0%1(4'4*6)4%/&1%/%/%1%/&/%/&1%/
(((0)6'2%.%.%/(4)4&.#+1@/?(6-9(1$-$-*71B/?-<,;'2#'$-'2,61A+6-8*6'3)3'0(1'0'0(1'0'1'0(2'4 $
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0"
processorArchitecture="X86"
name="Retrostyle"
type="win32"/>
<description>RETRO</description>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="asInvoker"
uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
macedonian.xml
kyrgyz.xml
kCyrillic.xml
uzbek.xml
zbekcha
kazakh.xml
afrikaans.xml
Afrikaans
tagalog.xml
Tagalog
luxembourgish.xml
tzebuergesch
malay.xml
Bahasa Melayu
serbia
nCyrillic.xml
serbian.xml
Srpski
belarusian.xml
spanish_ar.xml
ol argentina
basque.xml
Euskara
georgian.xml
croatian.xml
Hrvatski jezik
albanian.xml
Gjuha shqipe
indonesian.xml
Bahasa Indonesia
NETWORK
OPENFOLDER
PREVIEWGLYPH
SPINDOWN
SPINUP
UNKNOWNFILE
DLGTEMPLATE
DVCLAL
PACKAGEINFO
TFMABOUT
BUTTON
COLORPICK
COLORREPLACE
MAINICON
MS Sans Serif
VS_VERSION_INFO
StringFileInfo
040A04A6
CompanyName
RETRO-soft
FileDescription
FileVersion
2.3.0.104
InternalName
LegalCopyright
LegalTrademarks
OriginalFilename
ProductName
RETROTool
ProductVersion
VarFileInfo
Translation
Invalid UTF7
August
September
October
November
December
Win32 Error. Code: %d.
A Win32 API function failed
January
February
Invalid pixel coordinates
Unsupported PixelFormat
Invalid image dimensions
Image has no DIB
Invalid stream Justefytion
Color not in color table
Color table is empty
Image is empty
Invalid reduction method
Nircular decoder table entry
Envalid Image trailerAEnternal error: Extension Instance does not match Extension Label,Ansupported Application Extension block size
Anknown GIF block type
*Emage width too small for contained frames
You not assign w to t
count out of bounds
list index out of bounds
doesn't support streaming)Abject type not supported for Justefytion+Smage height too small for contained frames
invalid windows image
list capacity out of bounds
index data dictionary count
C:\DOCUME~1\Owner\LOCALS~1\Temp\9205867affd12eed25bed7ed96ffe60082f13fc07a7e8dee5457c98df7a405eb
C:\OJ1cP04O.exe
C:\Aiw4UUDz.exe
C:\23057f2c0d8acddc60eab0a51082b8f55cd13a2fef99b3a358b95d3766e39058
C:\e6b65d448077a2bcdee20b644d82bad1e4c2100a4a65635d4aa2d1c5ad70959f
C:\pYERAb9R.exe
C:\D4yAgTZE.exe
C:\EaWifoWg.exe
C:\_vHNNK0Z.exe
C:\LH_loQYS.exe
C:\d52274a46ec9f122f4c8e9fc5462e02fdb7de255d239b1889bcee29fc9ad4653
C:\20733dced8c4c08994d947b922df7220901a3ff7e2cc5cb6673bb64e56029166
C:\6UkEvNdM.exe
C:\sKeiwQGp.exe
C:\lyORstgQ.exe
C:\wvNEZomQ.exe
C:\zRvffObZ.exe
C:\eQkWg2FN.exe
C:\Cg1OZZI0.exe
C:\UucVZ2_a.exe
C:\46e4459d7808830442c5940e80f5bf877d2970afe611b3666a6ee2280049fa91
C:\f06a9195cddf8a2918fbf9208a46339fdfc7ee48f90e56bd0cd24201b967dbd0
C:\I6i2wjpj.exe
C:\mJohHnul.exe
C:\oWThr9mW.exe
C:\mMQudRjk.exe
C:\KNxyj9_s.exe
C:\cldYuI0s.exe
C:\AJJcA4M5.exe
C:\CLdtCwXe.exe
C:\nqUVPyAL.exe
C:\gZNDWVuv.exe
C:\6c059f1c136be6cdc3cc4a69b8b17a8105a0314fd40abcac1ab68621e2239bba
C:\rkgyuFZs.exe
C:\JJ3x0uCS.exe
C:\IIGUix16.exe
C:\4SFA1bw4.exe
C:\WY4cokxU.exe
C:\sKLtY6Xb.exe
C:\s1Y5LaQR.exe
C:\AyCvibLn.exe
C:\JqVkRhMK.exe
C:\nssZ3hge.exe
C:\kUPoyKBj.exe
C:\m2IGU6lV.exe
C:\TrbcBxrC.exe
C:\Users\Joe Cage\Desktop\836o6gbgFJ.exe
C:\4542a0a51d42f4cc898123901bf4aaa189eeec9392c9759ec511f657b439b899

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 61714 8.8.8.8 53
192.168.56.101 56933 8.8.8.8 53
192.168.56.101 138 192.168.56.255 138
192.168.56.101 58485 114.114.114.114 53
192.168.56.101 58485 8.8.8.8 53

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.