5.8
高危

8cb35d687ea884490a4eaf803518ebe29c2d230d4ca0462e9e20e3d98afe7917

b570ee452386d4c2143863826e61a1c9.exe

分析耗时

22s

最近分析

文件大小

819.0KB
静态报毒 动态报毒 AI SCORE=81 AIDETECTVM ALI2000015 AUTO BTOX8U CLASSIC CONFIDENCE DELF DELFINJECT DELPHILESS ELXR EMHC FAREIT GENERICKDZ GENETIC HIGH CONFIDENCE HKSAEC IGENT KRYPTIK MALWARE2 MALWARE@#2SLXC5A8X8SPE MARIA R + MAL R06EC0DIA20 SCORE SNBOH SUSGEN TSCOPE UNSAFE WACATAC X2066 XUHF ZELPHIF ZGW@A8JHZQAI 更多
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
McAfee Fareit-FTB!B570EE452386 20201211 6.0.6.653
Alibaba Trojan:Win32/DelfInject.ali2000015 20190527 0.3.0.5
CrowdStrike win/malicious_confidence_90% (W) 20190702 1.0
Baidu 20190318 1.0.0.2
Avast Win32:Trojan-gen 20201210 21.1.5827.0
Kingsoft 20201211 2017.9.26.565
Tencent Win32.Trojan.Inject.Auto 20201211 1.0.0.1
静态指标
The executable contains unknown PE section names indicative of a packer (could be a false positive) (3 个事件)
section CODE
section DATA
section BSS
The executable uses a known packer (1 个事件)
packer BobSoft Mini Delphi -> BoB / BobSoft
One or more processes crashed (1 个事件)
Time & API Arguments Status Return Repeated
1619870357.618001
__exception__
stacktrace:
CreateFileMappingW+0xe5 OpenFileMappingW-0x29 kernelbase+0xdc73 @ 0x778edc73
GetFileVersion+0xa7 ND_RI2-0x2eb mscoreei+0xe97b @ 0x7501e97b
GetFileVersion+0x1bb ND_RI2-0x1d7 mscoreei+0xea8f @ 0x7501ea8f
RegisterShimImplCallback+0x48e5 CLRCreateInstance-0x13e6 mscoreei+0xb25a @ 0x7501b25a
RegisterShimImplCallback+0x4b52 CLRCreateInstance-0x1179 mscoreei+0xb4c7 @ 0x7501b4c7
RegisterShimImplCallback+0x4300 CLRCreateInstance-0x19cb mscoreei+0xac75 @ 0x7501ac75
RegisterShimImplCallback+0x4561 CLRCreateInstance-0x176a mscoreei+0xaed6 @ 0x7501aed6
CreateConfigStream+0xc89 _CorExeMain-0x62 mscoreei+0x5511 @ 0x75015511
_CorExeMain+0x2b _CorExeMain2-0x141 mscoreei+0x559e @ 0x7501559e
CreateConfigStream+0x13f GetProcessExecutableHeap-0xad6 mscoree+0x7f16 @ 0x75177f16
_CorExeMain+0x8 CreateConfigStream-0x2ff4 mscoree+0x4de3 @ 0x75174de3
b570ee452386d4c2143863826e61a1c9+0x90a4d @ 0x490a4d
b570ee452386d4c2143863826e61a1c9+0x89254 @ 0x489254
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x763533ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77d69ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77d69ea5

registers.esp: 1634372
registers.edi: 2
registers.eax: 1
registers.ebp: 1634412
registers.edx: 228
registers.ebx: 983045
registers.esi: 1634532
registers.ecx: 228
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0xff5b14ad
success 0 0
行为判定
动态指标
One or more potentially interesting buffers were extracted, these generally contain injected code, configuration data, etc.
Allocates read-write-execute memory (usually to unpack itself) (30 个事件)
Time & API Arguments Status Return Repeated
1619861116.614279
NtAllocateVirtualMemory
process_identifier: 2440
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003e0000
success 0 0
1619861116.770279
NtProtectVirtualMemory
process_identifier: 2440
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 32768
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x0045e000
success 0 0
1619861116.770279
NtAllocateVirtualMemory
process_identifier: 2440
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x01f90000
success 0 0
1619870356.790001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x00400000
success 0 0
1619870356.836001
NtAllocateVirtualMemory
process_identifier: 3064
region_size: 2097152
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 8192 (MEM_RESERVE)
base_address: 0x02060000
success 0 0
1619870356.836001
NtAllocateVirtualMemory
process_identifier: 3064
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x02220000
success 0 0
1619870356.836001
NtAllocateVirtualMemory
process_identifier: 3064
region_size: 557056
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x00740000
success 0 0
1619870356.836001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 520192
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x00742000
success 0 0
1619870357.118001
NtAllocateVirtualMemory
process_identifier: 3064
region_size: 1114112
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 8192 (MEM_RESERVE)
base_address: 0x02060000
success 0 0
1619870357.118001
NtAllocateVirtualMemory
process_identifier: 3064
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x02130000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x02052000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76351000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x02052000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76353000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x02052000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76354000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x02052000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76351000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x02052000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x77d4f000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x02052000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76353000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x02052000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76351000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x02052000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76351000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x02052000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76354000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x02052000
success 0 0
1619870357.586001
NtProtectVirtualMemory
process_identifier: 3064
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76351000
success 0 0
The binary likely contains encrypted or compressed data indicative of a packer (2 个事件)
entropy 7.52851148770977 section {'size_of_data': '0x0005d200', 'virtual_address': '0x00075000', 'entropy': 7.52851148770977, 'name': '.rsrc', 'virtual_size': '0x0005d164'} description A section with a high entropy has been found
entropy 0.4553789731051345 description Overall entropy of this PE file is high
网络通信
Communicates with host for which no DNS query was performed (1 个事件)
host 172.217.24.14
Used NtSetContextThread to modify a thread in a remote process indicative of process injection (2 个事件)
Process injection Process 2440 called NtSetContextThread to modify thread in remote process 3064
Time & API Arguments Status Return Repeated
1619861117.614279
NtSetContextThread
thread_handle: 0x000000fc
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5354720
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 3064
success 0 0
Resumed a suspended thread in a remote process potentially indicative of process injection (2 个事件)
Process injection Process 2440 resumed a thread in remote process 3064
Time & API Arguments Status Return Repeated
1619861118.020279
NtResumeThread
thread_handle: 0x000000fc
suspend_count: 1
process_identifier: 3064
success 0 0
Executed a process and injected code into it, probably while unpacking (6 个事件)
Time & API Arguments Status Return Repeated
1619861117.255279
CreateProcessInternalW
thread_identifier: 1176
thread_handle: 0x000000fc
process_identifier: 3064
current_directory:
filepath:
track: 1
command_line: "C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\b570ee452386d4c2143863826e61a1c9.exe"
filepath_r:
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
process_handle: 0x00000100
inherit_handles: 0
success 1 0
1619861117.255279
NtUnmapViewOfSection
process_identifier: 3064
region_size: 4096
process_handle: 0x00000100
base_address: 0x00400000
success 0 0
1619861117.427279
NtMapViewOfSection
section_handle: 0x00000108
process_identifier: 3064
commit_size: 1167360
win32_protect: 64 (PAGE_EXECUTE_READWRITE)
buffer:
process_handle: 0x00000100
allocation_type: 0 ()
section_offset: 0
view_size: 1167360
base_address: 0x00400000
success 0 0
1619861117.614279
NtGetContextThread
thread_handle: 0x000000fc
success 0 0
1619861117.614279
NtSetContextThread
thread_handle: 0x000000fc
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5354720
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 3064
success 0 0
1619861118.020279
NtResumeThread
thread_handle: 0x000000fc
suspend_count: 1
process_identifier: 3064
success 0 0
File has been identified by 61 AntiVirus engines on VirusTotal as malicious (50 out of 61 个事件)
Bkav W32.AIDetectVM.malware2
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKDZ.67460
FireEye Generic.mg.b570ee452386d4c2
McAfee Fareit-FTB!B570EE452386
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Malware
K7AntiVirus Trojan ( 0056739d1 )
Alibaba Trojan:Win32/DelfInject.ali2000015
K7GW Trojan ( 0056739d1 )
CrowdStrike win/malicious_confidence_90% (W)
Arcabit Trojan.Generic.D10784
Cyren W32/Injector.XUHF-9172
Symantec Trojan.Gen.2
APEX Malicious
Avast Win32:Trojan-gen
ClamAV Win.Dropper.Generickdz-7944944-0
Kaspersky HEUR:Trojan.Win32.Kryptik.gen
BitDefender Trojan.GenericKDZ.67460
NANO-Antivirus Trojan.Win32.Maria.hksaec
Paloalto generic.ml
AegisLab Trojan.Win32.Kryptik.4!c
Rising Trojan.Kryptik!1.C71C (CLASSIC)
Ad-Aware Trojan.GenericKDZ.67460
Sophos Mal/Generic-R + Mal/Fareit-AA
Comodo Malware@#2slxc5a8x8spe
F-Secure Trojan.TR/Injector.snboh
DrWeb Trojan.PWS.Maria.3
Zillya Dropper.Agent.Win32.428686
TrendMicro TROJ_GEN.R06EC0DIA20
McAfee-GW-Edition BehavesLike.Win32.Fareit.cc
Emsisoft Trojan.GenericKDZ.67460 (B)
Jiangmin Trojan.Kryptik.ayh
Avira TR/Injector.snboh
Antiy-AVL Trojan/Win32.Kryptik
Gridinsoft Trojan.Win32.Wacatac.ba!s1
Microsoft Trojan:Win32/DelfInject.B!MTB
ZoneAlarm HEUR:Trojan.Win32.Kryptik.gen
GData Trojan.GenericKDZ.67460
Cynet Malicious (score: 100)
AhnLab-V3 Suspicious/Win.Delphiless.X2066
Acronis suspicious
BitDefenderTheta Gen:NN.ZelphiF.34670.ZGW@a8jhzQai
ALYac Trojan.GenericKDZ.67460
MAX malware (ai score=81)
VBA32 TScope.Trojan.Delf
Malwarebytes Trojan.MalPack.DLF
Zoner Trojan.Win32.91359
ESET-NOD32 a variant of Win32/Injector.EMHC
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

1992-06-20 06:22:17

Imports

Library kernel32.dll:
0x46913c VirtualFree
0x469140 VirtualAlloc
0x469144 LocalFree
0x469148 LocalAlloc
0x46914c GetVersion
0x469150 GetCurrentThreadId
0x46915c VirtualQuery
0x469160 WideCharToMultiByte
0x469164 MultiByteToWideChar
0x469168 lstrlenA
0x46916c lstrcpynA
0x469170 LoadLibraryExA
0x469174 GetThreadLocale
0x469178 GetStartupInfoA
0x46917c GetProcAddress
0x469180 GetModuleHandleA
0x469184 GetModuleFileNameA
0x469188 GetLocaleInfoA
0x46918c GetCommandLineA
0x469190 FreeLibrary
0x469194 FindFirstFileA
0x469198 FindClose
0x46919c ExitProcess
0x4691a0 WriteFile
0x4691a8 RtlUnwind
0x4691ac RaiseException
0x4691b0 GetStdHandle
Library user32.dll:
0x4691b8 GetKeyboardType
0x4691bc LoadStringA
0x4691c0 MessageBoxA
0x4691c4 CharNextA
Library advapi32.dll:
0x4691cc RegQueryValueExA
0x4691d0 RegOpenKeyExA
0x4691d4 RegCloseKey
Library oleaut32.dll:
0x4691dc SysFreeString
0x4691e0 SysReAllocStringLen
0x4691e4 SysAllocStringLen
Library kernel32.dll:
0x4691ec TlsSetValue
0x4691f0 TlsGetValue
0x4691f4 LocalAlloc
0x4691f8 GetModuleHandleA
Library advapi32.dll:
0x469200 RegQueryValueExA
0x469204 RegOpenKeyExA
0x469208 RegCloseKey
Library kernel32.dll:
0x469210 lstrcpyA
0x469214 WriteFile
0x46921c WaitForSingleObject
0x469220 VirtualQuery
0x469224 VirtualAlloc
0x469228 Sleep
0x46922c SizeofResource
0x469230 SetThreadLocale
0x469234 SetFilePointer
0x469238 SetEvent
0x46923c SetErrorMode
0x469240 SetEndOfFile
0x469244 ResetEvent
0x469248 ReadFile
0x46924c MulDiv
0x469250 LockResource
0x469254 LoadResource
0x469258 LoadLibraryA
0x469264 GlobalUnlock
0x469268 GlobalReAlloc
0x46926c GlobalHandle
0x469270 GlobalLock
0x469274 GlobalFree
0x469278 GlobalFindAtomA
0x46927c GlobalDeleteAtom
0x469280 GlobalAlloc
0x469284 GlobalAddAtomA
0x469288 GetVersionExA
0x46928c GetVersion
0x469290 GetTickCount
0x469294 GetThreadLocale
0x46929c GetSystemTime
0x4692a0 GetSystemInfo
0x4692a4 GetStringTypeExA
0x4692a8 GetStdHandle
0x4692ac GetProcAddress
0x4692b0 GetModuleHandleA
0x4692b4 GetModuleFileNameA
0x4692b8 GetLocaleInfoA
0x4692bc GetLocalTime
0x4692c0 GetLastError
0x4692c4 GetFullPathNameA
0x4692c8 GetFileAttributesA
0x4692cc GetDiskFreeSpaceA
0x4692d0 GetDateFormatA
0x4692d4 GetCurrentThreadId
0x4692d8 GetCurrentProcessId
0x4692dc GetCPInfo
0x4692e0 GetACP
0x4692e4 FreeResource
0x4692e8 InterlockedExchange
0x4692ec FreeLibrary
0x4692f0 FormatMessageA
0x4692f4 FindResourceA
0x4692f8 FindFirstFileA
0x4692fc FindClose
0x469308 ExitThread
0x46930c EnumCalendarInfoA
0x469318 CreateThread
0x46931c CreateFileA
0x469320 CreateEventA
0x469324 CompareStringA
0x469328 CloseHandle
Library version.dll:
0x469330 VerQueryValueA
0x469338 GetFileVersionInfoA
Library gdi32.dll:
0x469340 UnrealizeObject
0x469344 StretchBlt
0x469348 SetWindowOrgEx
0x46934c SetWinMetaFileBits
0x469350 SetViewportOrgEx
0x469354 SetTextColor
0x469358 SetStretchBltMode
0x46935c SetROP2
0x469360 SetPixel
0x469364 SetEnhMetaFileBits
0x469368 SetDIBColorTable
0x46936c SetBrushOrgEx
0x469370 SetBkMode
0x469374 SetBkColor
0x469378 SelectPalette
0x46937c SelectObject
0x469380 SelectClipRgn
0x469384 SelectClipPath
0x469388 SaveDC
0x46938c RestoreDC
0x469390 Rectangle
0x469394 RectVisible
0x469398 RealizePalette
0x46939c Polyline
0x4693a0 PlayEnhMetaFile
0x4693a4 PatBlt
0x4693a8 MoveToEx
0x4693ac MaskBlt
0x4693b0 LineTo
0x4693b4 IntersectClipRect
0x4693b8 GetWindowOrgEx
0x4693bc GetWinMetaFileBits
0x4693c0 GetTextMetricsA
0x4693cc GetStockObject
0x4693d0 GetPixel
0x4693d4 GetPaletteEntries
0x4693d8 GetObjectA
0x4693e4 GetEnhMetaFileBits
0x4693e8 GetDeviceCaps
0x4693ec GetDIBits
0x4693f0 GetDIBColorTable
0x4693f4 GetDCOrgEx
0x4693fc GetClipBox
0x469400 GetBrushOrgEx
0x469404 GetBitmapBits
0x469408 ExtTextOutA
0x46940c ExcludeClipRect
0x469410 DeleteObject
0x469414 DeleteEnhMetaFile
0x469418 DeleteDC
0x46941c CreateSolidBrush
0x469420 CreateRectRgn
0x469424 CreatePenIndirect
0x469428 CreatePalette
0x469430 CreateFontIndirectA
0x469434 CreateDIBitmap
0x469438 CreateDIBSection
0x46943c CreateCompatibleDC
0x469444 CreateBrushIndirect
0x469448 CreateBitmap
0x46944c CopyEnhMetaFileA
0x469450 BitBlt
Library user32.dll:
0x469458 CreateWindowExA
0x46945c WindowFromPoint
0x469460 WinHelpA
0x469464 WaitMessage
0x469468 UpdateWindow
0x46946c UnregisterClassA
0x469470 UnhookWindowsHookEx
0x469474 TranslateMessage
0x46947c TrackPopupMenu
0x469484 ShowWindow
0x469488 ShowScrollBar
0x46948c ShowOwnedPopups
0x469490 ShowCursor
0x469494 SetWindowsHookExA
0x469498 SetWindowTextA
0x46949c SetWindowPos
0x4694a0 SetWindowPlacement
0x4694a4 SetWindowLongA
0x4694a8 SetTimer
0x4694ac SetScrollRange
0x4694b0 SetScrollPos
0x4694b4 SetScrollInfo
0x4694b8 SetRect
0x4694bc SetPropA
0x4694c0 SetParent
0x4694c4 SetMenuItemInfoA
0x4694c8 SetMenu
0x4694cc SetForegroundWindow
0x4694d0 SetFocus
0x4694d4 SetCursor
0x4694d8 SetClassLongA
0x4694dc SetCapture
0x4694e0 SetActiveWindow
0x4694e4 SendMessageA
0x4694e8 ScrollWindow
0x4694ec ScreenToClient
0x4694f0 RemovePropA
0x4694f4 RemoveMenu
0x4694f8 ReleaseDC
0x4694fc ReleaseCapture
0x469508 RegisterClassA
0x46950c RedrawWindow
0x469510 PtInRect
0x469514 PostQuitMessage
0x469518 PostMessageA
0x46951c PeekMessageA
0x469520 OffsetRect
0x469524 OemToCharA
0x469528 MessageBoxA
0x46952c MapWindowPoints
0x469530 MapVirtualKeyA
0x469534 LoadStringA
0x469538 LoadKeyboardLayoutA
0x46953c LoadIconA
0x469540 LoadCursorA
0x469544 LoadBitmapA
0x469548 KillTimer
0x46954c IsZoomed
0x469550 IsWindowVisible
0x469554 IsWindowEnabled
0x469558 IsWindow
0x46955c IsRectEmpty
0x469560 IsIconic
0x469564 IsDialogMessageA
0x469568 IsChild
0x46956c InvalidateRect
0x469570 IntersectRect
0x469574 InsertMenuItemA
0x469578 InsertMenuA
0x46957c InflateRect
0x469584 GetWindowTextA
0x469588 GetWindowRect
0x46958c GetWindowPlacement
0x469590 GetWindowLongA
0x469594 GetWindowDC
0x469598 GetTopWindow
0x46959c GetSystemMetrics
0x4695a0 GetSystemMenu
0x4695a4 GetSysColorBrush
0x4695a8 GetSysColor
0x4695ac GetSubMenu
0x4695b0 GetScrollRange
0x4695b4 GetScrollPos
0x4695b8 GetScrollInfo
0x4695bc GetPropA
0x4695c0 GetParent
0x4695c4 GetWindow
0x4695c8 GetMenuStringA
0x4695cc GetMenuState
0x4695d0 GetMenuItemInfoA
0x4695d4 GetMenuItemID
0x4695d8 GetMenuItemCount
0x4695dc GetMenu
0x4695e0 GetLastActivePopup
0x4695e4 GetKeyboardState
0x4695ec GetKeyboardLayout
0x4695f0 GetKeyState
0x4695f4 GetKeyNameTextA
0x4695f8 GetIconInfo
0x4695fc GetForegroundWindow
0x469600 GetFocus
0x469604 GetDlgItem
0x469608 GetDesktopWindow
0x46960c GetDCEx
0x469610 GetDC
0x469614 GetCursorPos
0x469618 GetCursor
0x46961c GetClipboardData
0x469620 GetClientRect
0x469624 GetClassNameA
0x469628 GetClassInfoA
0x46962c GetCapture
0x469630 GetActiveWindow
0x469634 FrameRect
0x469638 FindWindowA
0x46963c FillRect
0x469640 EqualRect
0x469644 EnumWindows
0x469648 EnumThreadWindows
0x46964c EndPaint
0x469650 EnableWindow
0x469654 EnableScrollBar
0x469658 EnableMenuItem
0x46965c DrawTextA
0x469660 DrawMenuBar
0x469664 DrawIconEx
0x469668 DrawIcon
0x46966c DrawFrameControl
0x469670 DrawFocusRect
0x469674 DrawEdge
0x469678 DispatchMessageA
0x46967c DestroyWindow
0x469680 DestroyMenu
0x469684 DestroyIcon
0x469688 DestroyCursor
0x46968c DeleteMenu
0x469690 DefWindowProcA
0x469694 DefMDIChildProcA
0x469698 DefFrameProcA
0x46969c CreatePopupMenu
0x4696a0 CreateMenu
0x4696a4 CreateIcon
0x4696a8 ClientToScreen
0x4696ac CheckMenuItem
0x4696b0 CallWindowProcA
0x4696b4 CallNextHookEx
0x4696b8 BeginPaint
0x4696bc CharNextA
0x4696c0 CharLowerBuffA
0x4696c4 CharLowerA
0x4696c8 CharToOemA
0x4696cc AdjustWindowRectEx
Library kernel32.dll:
0x4696d8 Sleep
Library oleaut32.dll:
0x4696e0 SafeArrayPtrOfIndex
0x4696e4 SafeArrayGetUBound
0x4696e8 SafeArrayGetLBound
0x4696ec SafeArrayCreate
0x4696f0 VariantChangeType
0x4696f4 VariantCopy
0x4696f8 VariantClear
0x4696fc VariantInit
Library comctl32.dll:
0x46970c ImageList_Write
0x469710 ImageList_Read
0x469720 ImageList_DragMove
0x469724 ImageList_DragLeave
0x469728 ImageList_DragEnter
0x46972c ImageList_EndDrag
0x469730 ImageList_BeginDrag
0x469734 ImageList_Remove
0x469738 ImageList_DrawEx
0x46973c ImageList_Replace
0x469740 ImageList_Draw
0x469750 ImageList_Add
0x469758 ImageList_Destroy
0x46975c ImageList_Create
0x469760 InitCommonControls
Library comdlg32.dll:
0x469768 GetOpenFileNameA

Hosts

No hosts contacted.

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 50534 114.114.114.114 53
192.168.56.101 51808 114.114.114.114 53
192.168.56.101 55368 114.114.114.114 53
192.168.56.101 56539 114.114.114.114 53
192.168.56.101 58367 114.114.114.114 53
192.168.56.101 63429 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 123 20.189.79.72 time.windows.com 123
192.168.56.101 51963 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 62191 224.0.0.252 5355
192.168.56.101 65004 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900
192.168.56.101 51809 239.255.255.250 3702
192.168.56.101 56540 239.255.255.250 3702
192.168.56.101 56807 239.255.255.250 1900
192.168.56.101 58707 239.255.255.250 3702

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.