entropy | 7.995040191083422 | section | {'size_of_data': '0x0004ac00', 'virtual_address': '0x00523000', 'entropy': 7.995040191083422, 'name': '/19', 'virtual_size': '0x0004aa9d'} | description | A section with a high entropy has been found | |||||||||
entropy | 7.941966013190239 | section | {'size_of_data': '0x00013600', 'virtual_address': '0x0056e000', 'entropy': 7.941966013190239, 'name': '/32', 'virtual_size': '0x000135a2'} | description | A section with a high entropy has been found | |||||||||
entropy | 7.955679977221876 | section | {'size_of_data': '0x00004600', 'virtual_address': '0x00582000', 'entropy': 7.955679977221876, 'name': '/46', 'virtual_size': '0x00004590'} | description | A section with a high entropy has been found | |||||||||
entropy | 7.9913323603436295 | section | {'size_of_data': '0x00009a00', 'virtual_address': '0x00587000', 'entropy': 7.9913323603436295, 'name': '/63', 'virtual_size': '0x0000998d'} | description | A section with a high entropy has been found | |||||||||
entropy | 7.997792626698757 | section | {'size_of_data': '0x0009ae00', 'virtual_address': '0x00592000', 'entropy': 7.997792626698757, 'name': '/99', 'virtual_size': '0x0009ad53'} | description | A section with a high entropy has been found | |||||||||
entropy | 7.995925986465307 | section | {'size_of_data': '0x00056600', 'virtual_address': '0x0062d000', 'entropy': 7.995925986465307, 'name': '/112', 'virtual_size': '0x000564c7'} | description | A section with a high entropy has been found | |||||||||
entropy | 7.8001373324716345 | section | {'size_of_data': '0x0001c200', 'virtual_address': '0x00684000', 'entropy': 7.8001373324716345, 'name': '/124', 'virtual_size': '0x0001c162'} | description | A section with a high entropy has been found | |||||||||
entropy | 0.21583762149799884 | description | Overall entropy of this PE file is high |
host | 172.217.24.14 | |||
host | 47.105.143.181 |
dead_host | 192.168.56.101:49173 |
dead_host | 47.105.143.181:80 |
No hosts contacted.
Name | Response | Post-Analysis Lookup |
---|---|---|
dns.msftncsi.com | A 131.107.255.255 | 131.107.255.255 |
dns.msftncsi.com | AAAA fd3e:4f5a:5b81::1 | 131.107.255.255 |
teredo.ipv6.microsoft.com |
No TCP connections recorded.
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 49235 | 114.114.114.114 | 53 |
192.168.56.101 | 50534 | 114.114.114.114 | 53 |
192.168.56.101 | 56539 | 114.114.114.114 | 53 |
192.168.56.101 | 65004 | 114.114.114.114 | 53 |
192.168.56.101 | 137 | 192.168.56.255 | 137 |
192.168.56.101 | 138 | 192.168.56.255 | 138 |
192.168.56.101 | 55368 | 224.0.0.252 | 5355 |
192.168.56.101 | 56804 | 224.0.0.252 | 5355 |
192.168.56.101 | 60123 | 224.0.0.252 | 5355 |
192.168.56.101 | 62191 | 224.0.0.252 | 5355 |
192.168.56.101 | 1900 | 239.255.255.250 | 1900 |
192.168.56.101 | 50535 | 239.255.255.250 | 3702 |
192.168.56.101 | 50537 | 239.255.255.250 | 3702 |
192.168.56.101 | 56540 | 239.255.255.250 | 3702 |
192.168.56.101 | 56807 | 239.255.255.250 | 1900 |
192.168.56.101 | 58707 | 239.255.255.250 | 3702 |
No HTTP requests performed.
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts