1.4
低危

b9f121d55010c4d9f121682c6e4bd8aad7697afc073a99868081841778fd76ea

c596a7f8d08b6521d582b877da84ec36.exe

分析耗时

82s

最近分析

文件大小

156.5KB
静态报毒 动态报毒 QVM20 XPACK
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
McAfee 20210210 6.0.6.653
CrowdStrike 20210203 1.0
Alibaba 20190527 0.3.0.5
Baidu 20190318 1.0.0.2
Avast 20210210 21.1.5827.0
Kingsoft 20210210 2017.9.26.565
Tencent 20210210 1.0.0.1
行为判定
动态指标
File has been identified by 4 AntiVirus engines on VirusTotal as malicious (4 个事件)
F-Secure Trojan.TR/Crypt.XPACK.Gen
Ikarus Trojan.Crypt
Avira TR/Crypt.XPACK.Gen
Qihoo-360 Generic/HEUR/QVM20.1.B390.Malware.Gen
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2019-01-24 22:28:37

Imports

Library KERNEL32.dll:
0x408070 CreateFileA
0x408074 GetFileSize
0x408078 ReadFile
0x40807c GetTickCount
0x408080 GetModuleFileNameA
0x408084 GetCommandLineA
0x40808c GetTempPathA
0x408090 SetErrorMode
0x408094 GetCurrentProcess
0x408098 ExitProcess
0x40809c GetVersion
0x4080a4 lstrlenA
0x4080a8 CopyFileA
0x4080ac GetDiskFreeSpaceA
0x4080b0 GlobalAlloc
0x4080b4 GlobalUnlock
0x4080b8 GlobalLock
0x4080bc lstrcpynA
0x4080c0 CreateDirectoryA
0x4080c4 RemoveDirectoryA
0x4080c8 WriteFile
0x4080cc GetTempFileNameA
0x4080d0 GetLastError
0x4080d4 MoveFileA
0x4080d8 GetExitCodeProcess
0x4080dc CreateProcessA
0x4080e0 GetSystemDirectoryA
0x4080e4 GetProcAddress
0x4080e8 lstrcpyA
0x4080ec lstrcatA
0x4080f0 MoveFileExA
0x4080f4 LoadLibraryExA
0x4080f8 GetModuleHandleA
0x4080fc FreeLibrary
0x408100 Sleep
0x408104 CloseHandle
0x408108 SetFileTime
0x40810c SetFilePointer
0x408110 SetFileAttributesA
0x408114 GetFullPathNameA
0x408118 GetFileAttributesA
0x40811c FindNextFileA
0x408120 FindFirstFileA
0x408124 FindClose
0x408128 DeleteFileA
0x40812c CompareFileTime
0x408130 SearchPathA
0x408138 MultiByteToWideChar
0x408148 lstrcmpiA
0x40814c lstrcmpA
0x408150 MulDiv
0x408154 GetShortPathNameA
0x408158 WaitForSingleObject
0x40815c GlobalFree
0x408160 CreateThread
Library USER32.dll:
0x408184 EndDialog
0x408188 CheckDlgButton
0x40818c OpenClipboard
0x408190 CloseClipboard
0x408194 SetClipboardData
0x408198 EmptyClipboard
0x40819c IsWindowEnabled
0x4081a0 GetSystemMetrics
0x4081a4 GetSystemMenu
0x4081a8 CreatePopupMenu
0x4081ac EnableMenuItem
0x4081b0 AppendMenuA
0x4081b4 TrackPopupMenu
0x4081b8 GetWindowRect
0x4081bc SetCursor
0x4081c0 ScreenToClient
0x4081c4 GetSysColor
0x4081c8 GetWindowLongA
0x4081cc DialogBoxParamA
0x4081d0 LoadBitmapA
0x4081d4 LoadCursorA
0x4081dc DispatchMessageA
0x4081e0 PeekMessageA
0x4081e4 SetDlgItemTextA
0x4081e8 GetDlgItemTextA
0x4081ec CharPrevA
0x4081f0 MessageBoxIndirectA
0x4081f4 CharNextA
0x4081f8 ExitWindowsEx
0x4081fc SetWindowTextA
0x408200 SetTimer
0x408204 CreateDialogParamA
0x408208 DestroyWindow
0x40820c LoadImageA
0x408210 FindWindowExA
0x408214 InvalidateRect
0x408218 ReleaseDC
0x40821c IsWindowVisible
0x408220 SetWindowPos
0x408224 CreateWindowExA
0x408228 GetClassInfoA
0x40822c RegisterClassA
0x408230 CallWindowProcA
0x408234 SetClassLongA
0x408238 GetDC
0x40823c SetForegroundWindow
0x408240 EnableWindow
0x408244 GetDlgItem
0x408248 ShowWindow
0x40824c IsWindow
0x408250 PostQuitMessage
0x408254 SendMessageTimeoutA
0x408258 SendMessageA
0x40825c wsprintfA
0x408260 FillRect
0x408264 GetClientRect
0x408268 EndPaint
0x40826c BeginPaint
0x408270 DrawTextA
0x408274 DefWindowProcA
0x408278 GetMessagePos
0x40827c SetWindowLongA
Library GDI32.dll:
0x40804c CreateBrushIndirect
0x408050 DeleteObject
0x408054 SelectObject
0x408058 SetBkMode
0x40805c SetTextColor
0x408060 GetDeviceCaps
0x408064 SetBkColor
0x408068 CreateFontIndirectA
Library SHELL32.dll:
0x408168 ShellExecuteExA
0x40816c SHBrowseForFolderA
0x408174 SHGetFileInfoA
0x408178 SHFileOperationA
Library ADVAPI32.dll:
0x408004 RegCloseKey
0x408008 RegDeleteKeyA
0x40800c RegDeleteValueA
0x408010 RegEnumKeyA
0x408014 RegEnumValueA
0x408018 RegQueryValueExA
0x40801c RegSetValueExA
0x408020 OpenProcessToken
0x408024 RegOpenKeyExA
0x40802c SetFileSecurityA
0x408030 RegCreateKeyExA
Library COMCTL32.dll:
0x408038 ImageList_AddMasked
0x40803c
0x408040 ImageList_Create
0x408044 ImageList_Destroy
Library ole32.dll:
0x408284 OleInitialize
0x408288 OleUninitialize
0x40828c CoTaskMemFree
0x408290 CoCreateInstance

Hosts

No hosts contacted.

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 50534 114.114.114.114 53
192.168.56.101 51808 114.114.114.114 53
192.168.56.101 53657 114.114.114.114 53
192.168.56.101 58367 114.114.114.114 53
192.168.56.101 60123 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 123 20.189.79.72 time.windows.com 123
192.168.56.101 55368 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 57874 224.0.0.252 5355
192.168.56.101 62191 224.0.0.252 5355
192.168.56.101 63429 224.0.0.252 5355
192.168.56.101 65004 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900
192.168.56.101 53658 239.255.255.250 3702
192.168.56.101 53660 239.255.255.250 3702
192.168.56.101 58707 239.255.255.250 3702
192.168.56.101 60124 239.255.255.250 3702
192.168.56.101 62194 239.255.255.250 1900

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.