packer | UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser |
resource name | AIRPLAY_UIR |
suspicious_features | POST method with no referer header | suspicious_request | POST http://ap-serv.itools.hk/CheckVersion.php | ||||||
suspicious_features | POST method with no referer header | suspicious_request | POST http://ap-serv.itools.hk/Hi.php |
request | GET http://ap-serv.itools.hk/RuleEx.cfg |
request | POST http://ap-serv.itools.hk/CheckVersion.php |
request | POST http://ap-serv.itools.hk/Hi.php |
request | GET http://airplayer.itools.hk/new/index.php?lang=1&t=1620987619 |
request | GET http://airplayer.itools.hk/new/guide.htm |
request | GET http://airplayer.itools.hk/new/css_js_imgs_airplayer/global.css?v=2013073103 |
request | GET http://img.itools.hk/upload/js/jquery-1.7.1.min.js |
request | GET http://airplayer.itools.hk/new/css_js_imgs_airplayer/map.png |
request | GET http://airplayer.itools.hk/new/css_js_imgs_airplayer/map2.png |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/airplayer_02_01.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/airplayer_02_02.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/airplayer_02_03.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/airplayer_03.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/iphone8.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/airplayer_04_02.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/iphone6s.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/iphone6.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/iphone5.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/iphone_4s.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/ipad_air.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/ipad_mini2.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/ipad_mini.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer_tw/ipad2.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/ipad_3_4.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/touch_5.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/airplayer_04_1_ios7.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/airplayer_04_02_ios7.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/iPad%20Pro.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/airplayer_04_01.jpg |
request | GET http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/iphone7.jpg |
request | POST http://ap-serv.itools.hk/CheckVersion.php |
request | POST http://ap-serv.itools.hk/Hi.php |
name | AIRPLAY_UIR | language | LANG_CHINESE | offset | 0x012c3a8c | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00049456 | ||||||||||||||||||
name | AIRPLAY_UIR | language | LANG_CHINESE | offset | 0x012c3a8c | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00049456 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | offset | 0x013235fc | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | offset | 0x013235fc | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | offset | 0x013235fc | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | offset | 0x013235fc | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | offset | 0x013235fc | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000468 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | offset | 0x01315ce8 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x000000c0 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | offset | 0x01315ce8 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x000000c0 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | offset | 0x01315ce8 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x000000c0 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | offset | 0x01315ce8 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x000000c0 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | offset | 0x01315ce8 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x000000c0 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | offset | 0x01315ce8 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x000000c0 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | offset | 0x01315ce8 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x000000c0 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_CHINESE | offset | 0x01323a68 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x0000004c | ||||||||||||||||||
name | RT_VERSION | language | LANG_CHINESE | offset | 0x01323ab8 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x000002fc |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X6VHVO8H\jquery-1.7.1.min[1].js |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620985522.063205 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |
entropy | 7.932400093190161 | section | {'size_of_data': '0x00655800', 'virtual_address': '0x00cc5000', 'entropy': 7.932400093190161, 'name': 'UPX1', 'virtual_size': '0x00656000'} | description | A section with a high entropy has been found | |||||||||
entropy | 0.9942515520809382 | description | Overall entropy of this PE file is high |
section | UPX0 | description | Section name indicates UPX | ||||||
section | UPX1 | description | Section name indicates UPX |
host | 172.217.24.14 | |||
host | 203.208.40.66 | |||
host | 203.208.41.65 |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620985521.485205 NtQuerySystemInformation |
information_class:
76
(SystemFirmwareTableInformation)
|
failed | 3221225507 | 0 |
dead_host | 172.217.27.142:443 |
No hosts contacted.
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 49188 | 112.67.243.35 img.itools.cn | 80 |
192.168.56.101 | 49189 | 112.67.243.92 img.itools.cn | 80 |
192.168.56.101 | 49190 | 112.67.243.92 img.itools.cn | 80 |
192.168.56.101 | 49179 | 123.59.22.215 ap-serv.itools.hk | 80 |
192.168.56.101 | 49182 | 123.59.22.215 ap-serv.itools.hk | 80 |
192.168.56.101 | 49183 | 123.59.22.215 ap-serv.itools.hk | 80 |
192.168.56.101 | 49186 | 42.62.45.234 airplayer.itools.hk | 80 |
192.168.56.101 | 49187 | 42.62.45.234 airplayer.itools.hk | 80 |
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 49235 | 114.114.114.114 | 53 |
192.168.56.101 | 51808 | 114.114.114.114 | 53 |
192.168.56.101 | 53237 | 114.114.114.114 | 53 |
192.168.56.101 | 53657 | 114.114.114.114 | 53 |
192.168.56.101 | 57756 | 114.114.114.114 | 53 |
192.168.56.101 | 58367 | 114.114.114.114 | 53 |
192.168.56.101 | 60123 | 114.114.114.114 | 53 |
192.168.56.101 | 60384 | 114.114.114.114 | 53 |
192.168.56.101 | 62318 | 114.114.114.114 | 53 |
192.168.56.101 | 137 | 192.168.56.255 | 137 |
192.168.56.101 | 138 | 192.168.56.255 | 138 |
192.168.56.101 | 49713 | 224.0.0.252 | 5355 |
192.168.56.101 | 50534 | 224.0.0.252 | 5355 |
192.168.56.101 | 55368 | 224.0.0.252 | 5355 |
192.168.56.101 | 56804 | 224.0.0.252 | 5355 |
192.168.56.101 | 57874 | 224.0.0.252 | 5355 |
192.168.56.101 | 62191 | 224.0.0.252 | 5355 |
192.168.56.101 | 63429 | 224.0.0.252 | 5355 |
192.168.56.101 | 1900 | 239.255.255.250 | 1900 |
192.168.56.101 | 51809 | 239.255.255.250 | 3702 |
URI | Data |
---|---|
http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer_tw/ipad2.jpg | GET /airplayer.itools.hk/new/css_js_imgs_airplayer_tw/ipad2.jpg HTTP/1.1 Accept: */* Referer: http://airplayer.itools.hk/new/guide.htm Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: img.itools.cn Connection: Keep-Alive |
http://ap-serv.itools.hk/RuleEx.cfg | GET /RuleEx.cfg HTTP/1.1 Accept: */* Host: ap-serv.itools.hk User-Agent: CHttpAgent |
http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/iphone8.jpg | GET /airplayer.itools.hk/new/css_js_imgs_airplayer/iphone8.jpg HTTP/1.1 Accept: */* Referer: http://airplayer.itools.hk/new/guide.htm Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: img.itools.cn Connection: Keep-Alive |
http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/ipad_mini.jpg | GET /airplayer.itools.hk/new/css_js_imgs_airplayer/ipad_mini.jpg HTTP/1.1 Accept: */* Referer: http://airplayer.itools.hk/new/guide.htm Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: img.itools.cn Connection: Keep-Alive |
http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/iPad%20Pro.jpg | GET /airplayer.itools.hk/new/css_js_imgs_airplayer/iPad%20Pro.jpg HTTP/1.1 Accept: */* Referer: http://airplayer.itools.hk/new/guide.htm Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: img.itools.cn Connection: Keep-Alive |
http://img.itools.hk/upload/js/jquery-1.7.1.min.js | GET /upload/js/jquery-1.7.1.min.js HTTP/1.1 Accept: */* Referer: http://airplayer.itools.hk/new/guide.htm Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: img.itools.hk Connection: Keep-Alive |
http://airplayer.itools.hk/new/css_js_imgs_airplayer/map.png | GET /new/css_js_imgs_airplayer/map.png HTTP/1.1 Accept: */* Referer: http://airplayer.itools.hk/new/guide.htm Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: airplayer.itools.hk Connection: Keep-Alive |
http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/airplayer_03.jpg | GET /airplayer.itools.hk/new/css_js_imgs_airplayer/airplayer_03.jpg HTTP/1.1 Accept: */* Referer: http://airplayer.itools.hk/new/guide.htm Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: img.itools.cn Connection: Keep-Alive |
http://ap-serv.itools.hk/Hi.php | POST /Hi.php HTTP/1.1 Accept: */* Content-Length: 73 Host: ap-serv.itools.hk User-Agent: CHttpAgent |
http://img.itools.cn/airplayer.itools.hk/new/css_js_imgs_airplayer/airplayer_04_02_ios7.jpg | GET /airplayer.itools.hk/new/css_js_imgs_airplayer/airplayer_04_02_ios7.jpg HTTP/1.1 Accept: */* Referer: http://airplayer.itools.hk/new/guide.htm Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: img.itools.cn Connection: Keep-Alive |
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts