1.6
低危

3b0d74878fae800ca830d5c71f7d28da9e77360a95c432bf0125fcedaba0a9a9

c3a2ca3abd463d90b88017e2a0374191.exe

分析耗时

15s

最近分析

文件大小

67.4KB
静态报毒 动态报毒 NETFILTER
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba 20190527 0.3.0.5
Baidu 20190318 1.0.0.2
Kingsoft 20191122 2013.8.14.323
McAfee 20191121 6.0.6.653
Tencent 20191122 1.0.0.1
Avast 20191122 18.4.3895.0
CrowdStrike 20190702 1.0
行为判定
网络通信
Communicates with host for which no DNS query was performed (3 个事件)
host 151.139.128.14
host 172.217.24.14
host 52.218.96.60
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2019-10-24 03:52:40

Imports

Library fwpkclnt.sys:
0x40d040 FwpmProviderAdd0
0x40d048 FwpmSubLayerAdd0
0x40d054 FwpmSubLayerEnum0
0x40d05c FwpmCalloutAdd0
0x40d060 FwpmFilterAdd0
0x40d064 FwpsFlowAbort0
0x40d098 FwpmBfeStateGet0
0x40d0b8 FwpmEngineClose0
0x40d0bc FwpmEngineOpen0
0x40d0c0 FwpmFreeMemory0
0x40d0e4 FwpsPendClassify0
Library NDIS.SYS:
0x40d014 NdisWaitEvent
0x40d018 NdisInitializeEvent
0x40d024 NdisGetDataBuffer
Library ntoskrnl.exe:
0x40d0f4 memset
0x40d10c KeInitializeEvent
0x40d110 KeSetEvent
0x40d11c ExFreePoolWithTag
0x40d138 MmUnmapLockedPages
0x40d140 MmFreePagesFromMdl
0x40d14c IoAllocateMdl
0x40d150 IofCompleteRequest
0x40d154 IoCreateDevice
0x40d15c IoDeleteDevice
0x40d164 IoFreeMdl
0x40d174 ZwClose
0x40d178 ZwOpenKey
0x40d17c ZwQueryValueKey
0x40d188 RtlLengthSid
0x40d18c RtlCreateAcl
0x40d19c ZwSetSecurityObject
0x40d1a0 memcmp
0x40d1a4 SeExports
0x40d1a8 RtlGetVersion
0x40d1ac KeQuerySystemTime
0x40d1b0 _allmul
0x40d1b4 _aulldiv
0x40d1b8 _aullrem
0x40d1bc RtlUnwind
0x40d1c0 memcpy
0x40d1c4 swprintf_s
0x40d1cc ExUuidCreate
Library HAL.dll:
0x40d004 KeGetCurrentIrql

Hosts

No hosts contacted.

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 50534 114.114.114.114 53
192.168.56.101 51808 114.114.114.114 53
192.168.56.101 53657 114.114.114.114 53
192.168.56.101 58367 114.114.114.114 53
192.168.56.101 60123 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 55368 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 62191 224.0.0.252 5355
192.168.56.101 63429 224.0.0.252 5355
192.168.56.101 65004 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900
192.168.56.101 58707 239.255.255.250 3702
192.168.56.101 60124 239.255.255.250 3702
192.168.56.101 63434 239.255.255.250 1900
192.168.56.101 53657 8.8.8.8 53

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.