1.8
低危

4d5eada80f9a8b7ab23e3ec05314018fe155a20a4b224f72546bc9ebe20d66d5

b9f88a2d595b180922a4c2614ebdbadd.exe

分析耗时

57s

最近分析

文件大小

554.6KB
静态报毒 动态报毒 100% AI SCORE=80 ALOF ATTRIBUTE BACKDOOR2 BHTA CLOUD CONFIDENCE CRYPREN CRYPT0L0CKER CRYPTOLOCKER CUTWAIL DFQKCCB DNQGJC FFRU FILECODER GAMARUE GENCIRC GENERICKD GENETIC HIGH CONFIDENCE HIGHCONFIDENCE HWZN IQ1@AIYVSDKI KVKX LGBTD6EVGR4 M6L9 MALICIOUS PE MALWARE@#3I1T54KJZG335 MODERATE MXRESICN ONXJS QVM10 R134831 RACK RANSOMWAREALTAS ROVNIX SCORE SMTH TEERAC TORRENTLOCKER UNSAFE XEMA ZBOT ZEUS ZEXAF 更多
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
McAfee Trojan-FFRU!B9F88A2D595B 20200627 6.0.6.653
Alibaba TrojanDownloader:Win32/Cutwail.144c3b03 20190527 0.3.0.5
Avast Win32:CryptoLocker-B [Trj] 20200627 18.4.3895.0
Baidu 20190318 1.0.0.2
Kingsoft 20200627 2013.8.14.323
Tencent Malware.Win32.Gencirc.10b9d337 20200627 1.0.0.1
CrowdStrike win/malicious_confidence_100% (W) 20190702 1.0
静态指标
行为判定
动态指标
网络通信
Communicates with host for which no DNS query was performed (1 个事件)
host 172.217.24.14
File has been identified by 66 AntiVirus engines on VirusTotal as malicious (50 out of 66 个事件)
Bkav W32.RansomwareALTAS.Trojan
DrWeb Trojan.Encoder.847
MicroWorld-eScan Trojan.GenericKD.33686538
FireEye Generic.mg.b9f88a2d595b1809
CAT-QuickHeal Worm.Gamarue.WR5
McAfee Trojan-FFRU!B9F88A2D595B
Cylance Unsafe
Zillya Trojan.Agent.Win32.508499
SUPERAntiSpyware Trojan.Agent/Gen-Rovnix
Sangfor Malware
K7AntiVirus Trojan ( 004b5c0b1 )
Alibaba TrojanDownloader:Win32/Cutwail.144c3b03
K7GW Trojan ( 004b5c0b1 )
Cybereason malicious.d595b1
Arcabit Trojan.Generic.D202040A
Invincea heuristic
BitDefenderTheta Gen:NN.ZexaF.34130.Iq1@aiYvsDki
Cyren W32/Backdoor.KVKX-2352
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Win32/Filecoder.TorrentLocker.A
TrendMicro-HouseCall Ransom.Win32.TORRENTLOCKER.SMTH
TotalDefense Win32/Cutwail.DFQKcCB
Avast Win32:CryptoLocker-B [Trj]
ClamAV Win.Malware.Bhta-7598462-0
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Trojan.GenericKD.33686538
NANO-Antivirus Trojan.Win32.Agent.dnqgjc
Paloalto generic.ml
AegisLab Trojan.Win32.Zbot.m6l9
Rising Trojan.Win32.Filecoder.v (CLOUD)
Ad-Aware Trojan.GenericKD.33686538
Emsisoft Trojan.GenericKD.33686538 (B)
Comodo Malware@#3i1t54kjzg335
F-Secure Trojan.TR/AD.Teerac.onxjs
VIPRE Trojan.Win32.Filecoder.dia (v)
TrendMicro Ransom.Win32.TORRENTLOCKER.SMTH
SentinelOne DFI - Malicious PE
Trapmine malicious.moderate.ml.score
Sophos Troj/Agent-ALOF
Ikarus Trojan-Ransom.Torrentlocker
F-Prot W32/Backdoor2.HWZN
Jiangmin Trojan/Rack.e
Webroot W32.Infostealer.Zeus
Avira TR/AD.Teerac.onxjs
Antiy-AVL Trojan/Win32.Agent
Microsoft TrojanDownloader:Win32/Cutwail
Endgame malicious (high confidence)
ZoneAlarm HEUR:Trojan.Win32.Generic
GData Trojan.GenericKD.33686538
Cynet Malicious (score: 100)
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2014-12-06 04:25:05

Imports

Library KERNEL32.dll:
0x41000c GetCurrencyFormatA
0x410010 GetConsoleCP
0x410014 GetLastError
0x410018 VirtualAlloc
0x41001c OutputDebugStringA
0x410024 GetVersion
0x410028 VirtualFree
0x41002c ReadFile
0x410030 FlushFileBuffers
0x410034 WriteConsoleW
0x410038 SetStdHandle
0x41003c LoadLibraryW
0x410040 GetTickCount
0x410044 GetCurrentProcessId
0x410048 GetCommandLineW
0x410050 HeapSetInformation
0x410054 GetStartupInfoW
0x410058 RaiseException
0x41005c DecodePointer
0x410068 IsDebuggerPresent
0x41006c EncodePointer
0x410070 TerminateProcess
0x410074 GetCurrentProcess
0x410078 HeapAlloc
0x41007c HeapFree
0x410090 GetCPInfo
0x41009c GetACP
0x4100a0 GetOEMCP
0x4100a4 IsValidCodePage
0x4100a8 TlsAlloc
0x4100ac TlsGetValue
0x4100b0 TlsSetValue
0x4100b4 TlsFree
0x4100b8 GetModuleHandleW
0x4100bc SetLastError
0x4100c0 GetCurrentThreadId
0x4100c4 GetProcAddress
0x4100c8 WideCharToMultiByte
0x4100cc LCMapStringW
0x4100d0 MultiByteToWideChar
0x4100d4 Sleep
0x4100d8 GetFileAttributesW
0x4100dc ExitProcess
0x4100e0 WriteFile
0x4100e4 GetStdHandle
0x4100e8 GetModuleFileNameW
0x4100f4 SetHandleCount
0x4100f8 GetFileType
0x4100fc HeapCreate
0x410108 SetFilePointer
0x41010c GetConsoleMode
0x410110 RtlUnwind
0x410114 CloseHandle
0x410118 GetStringTypeW
0x41011c HeapReAlloc
0x410120 HeapSize
0x410124 CreateFileW
Library USER32.dll:
0x41012c IsZoomed
0x410130 GetDesktopWindow
0x410134 GetCursorPos
0x410138 GetMessageTime
Library ADVAPI32.dll:
0x410000 RegOpenKeyExW

Hosts

No hosts contacted.

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 51808 114.114.114.114 53
192.168.56.101 53657 114.114.114.114 53
192.168.56.101 58367 114.114.114.114 53
192.168.56.101 60123 114.114.114.114 53
192.168.56.101 65004 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 123 20.189.79.72 time.windows.com 123
192.168.56.101 50534 224.0.0.252 5355
192.168.56.101 55368 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 62191 224.0.0.252 5355
192.168.56.101 63429 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900
192.168.56.101 51809 239.255.255.250 3702
192.168.56.101 58707 239.255.255.250 3702
192.168.56.101 60124 239.255.255.250 3702
192.168.56.101 62194 239.255.255.250 1900

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.