3.0
中危

a0b28daeb280d197d8128d2301906406c761f0aa9d5a9b7f21a7ed07302070ac

d5a9bd466cf5f212524fb8c22a46eefa.exe

分析耗时

110s

最近分析

文件大小

1.5MB
静态报毒 动态报毒 INSTALLCORE
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
McAfee 20210128 6.0.6.653
Alibaba 20190527 0.3.0.5
Avast 20210129 21.1.5827.0
Tencent 20210129 1.0.0.1
Baidu 20190318 1.0.0.2
Kingsoft 20210129 2017.9.26.565
CrowdStrike 20190702 1.0
行为判定
动态指标
Foreign language identified in PE resource (50 out of 178 个事件)
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00182e28 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00182e28 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00182e28 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00182e28 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00182e28 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00182e28 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00182e28 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00182e28 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name AFX_DIALOG_LAYOUT language LANG_CHINESE offset 0x00182e28 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00000002
name PNG language LANG_CHINESE offset 0x0017b2a8 filetype PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00007b68
name PNG language LANG_CHINESE offset 0x0017b2a8 filetype PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00007b68
name PNG language LANG_CHINESE offset 0x0017b2a8 filetype PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00007b68
name PNG language LANG_CHINESE offset 0x0017b2a8 filetype PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x00007b68
name RT_BITMAP language LANG_CHINESE offset 0x0014ba90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x0000480a
name RT_BITMAP language LANG_CHINESE offset 0x0014ba90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x0000480a
name RT_BITMAP language LANG_CHINESE offset 0x0014ba90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x0000480a
name RT_BITMAP language LANG_CHINESE offset 0x0014ba90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x0000480a
name RT_BITMAP language LANG_CHINESE offset 0x0014ba90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x0000480a
name RT_BITMAP language LANG_CHINESE offset 0x0014ba90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x0000480a
name RT_BITMAP language LANG_CHINESE offset 0x0014ba90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x0000480a
name RT_BITMAP language LANG_CHINESE offset 0x0014ba90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x0000480a
name RT_BITMAP language LANG_CHINESE offset 0x0014ba90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x0000480a
name RT_BITMAP language LANG_CHINESE offset 0x0014ba90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x0000480a
name RT_BITMAP language LANG_CHINESE offset 0x0014ba90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x0000480a
name RT_BITMAP language LANG_CHINESE offset 0x0014ba90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x0000480a
name RT_BITMAP language LANG_CHINESE offset 0x0014ba90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x0000480a
name RT_BITMAP language LANG_CHINESE offset 0x0014ba90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x0000480a
name RT_BITMAP language LANG_CHINESE offset 0x0014ba90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x0000480a
name RT_BITMAP language LANG_CHINESE offset 0x0014ba90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x0000480a
name RT_BITMAP language LANG_CHINESE offset 0x0014ba90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x0000480a
name RT_BITMAP language LANG_CHINESE offset 0x0014ba90 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x0000480a
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
name RT_ICON language LANG_CHINESE offset 0x000961a8 filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED size 0x000010a8
File has been identified by one AntiVirus engine on VirusTotal as malicious (1 个事件)
Microsoft PUA:Win32/InstallCore
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2019-03-20 12:37:20

Imports

Library Qt5Gui.dll:
Library mfc140u.dll:
0x429f60
0x429f64
0x429f68
0x429f6c
0x429f70
0x429f74
0x429f78
0x429f7c
0x429f80
0x429f84
0x429f88
0x429f8c
0x429f90
0x429f94
0x429f98
0x429f9c
0x429fa0
0x429fa4
0x429fa8
0x429fac
0x429fb0
0x429fb4
0x429fb8
0x429fbc
0x429fc0
0x429fc4
0x429fc8
0x429fcc
0x429fd0
0x429fd4
0x429fd8
0x429fdc
0x429fe0
0x429fe4
0x429fe8
0x429fec
0x429ff0
0x429ff4
0x429ff8
0x429ffc
0x42a000
0x42a004
0x42a008
0x42a00c
0x42a010
0x42a014
0x42a018
0x42a01c
0x42a020
0x42a024
0x42a028
0x42a02c
0x42a030
0x42a034
0x42a038
0x42a03c
0x42a040
0x42a044
0x42a048
0x42a04c
0x42a050
0x42a054
0x42a058
0x42a05c
0x42a060
0x42a064
0x42a068
0x42a06c
0x42a070
0x42a074
0x42a078
0x42a07c
0x42a080
0x42a084
0x42a088
0x42a08c
0x42a090
0x42a094
0x42a098
0x42a09c
0x42a0a0
0x42a0a4
0x42a0a8
0x42a0ac
0x42a0b0
0x42a0b4
0x42a0b8
0x42a0bc
0x42a0c0
0x42a0c4
0x42a0c8
0x42a0cc
0x42a0d0
0x42a0d4
0x42a0d8
0x42a0dc
0x42a0e0
0x42a0e4
0x42a0e8
0x42a0ec
0x42a0f0
0x42a0f4
0x42a0f8
0x42a0fc
0x42a100
0x42a104
0x42a108
0x42a10c
0x42a110
0x42a114
0x42a118
0x42a11c
0x42a120
0x42a124
0x42a128
0x42a12c
0x42a130
0x42a134
0x42a138
0x42a13c
0x42a140
0x42a144
0x42a148
0x42a14c
0x42a150
0x42a154
0x42a158
0x42a15c
0x42a160
0x42a164
0x42a168
0x42a16c
0x42a170
0x42a174
0x42a178
0x42a17c
0x42a180
0x42a184
0x42a188
0x42a18c
0x42a190
0x42a194
0x42a198
0x42a19c
0x42a1a0
0x42a1a4
0x42a1a8
0x42a1ac
0x42a1b0
0x42a1b4
0x42a1b8
0x42a1bc
0x42a1c0
0x42a1c4
0x42a1c8
0x42a1cc
0x42a1d0
0x42a1d4
0x42a1d8
0x42a1dc
0x42a1e0
0x42a1e4
0x42a1e8
0x42a1ec
0x42a1f0
0x42a1f4
0x42a1f8
0x42a1fc
0x42a200
0x42a204
0x42a208
0x42a20c
0x42a210
0x42a214
0x42a218
0x42a21c
0x42a220
0x42a224
0x42a228
0x42a22c
0x42a230
0x42a234
0x42a238
0x42a23c
0x42a240
0x42a244
0x42a248
0x42a24c
0x42a250
0x42a254
0x42a258
0x42a25c
0x42a260
0x42a264
0x42a268
0x42a26c
0x42a270
0x42a274
0x42a278
0x42a27c
0x42a280
0x42a284
0x42a288
0x42a28c
0x42a290
0x42a294
0x42a298
0x42a29c
0x42a2a0
0x42a2a4
0x42a2a8
0x42a2ac
0x42a2b0
0x42a2b4
0x42a2b8
0x42a2bc
0x42a2c0
0x42a2c4
0x42a2c8
0x42a2cc
0x42a2d0
0x42a2d4
0x42a2d8
0x42a2dc
0x42a2e0
0x42a2e4
0x42a2e8
0x42a2ec
0x42a2f0
0x42a2f4
0x42a2f8
0x42a2fc
0x42a300
0x42a304
0x42a308
0x42a30c
0x42a310
0x42a314
0x42a318
0x42a31c
0x42a320
0x42a324
0x42a328
0x42a32c
0x42a330
0x42a334
0x42a338
0x42a33c
0x42a340
0x42a344
0x42a348
0x42a34c
0x42a350
0x42a354
0x42a358
0x42a35c
0x42a360
0x42a364
0x42a368
0x42a36c
0x42a370
0x42a374
0x42a378
0x42a37c
0x42a380
0x42a384
0x42a388
0x42a38c
0x42a390
0x42a394
0x42a398
0x42a39c
0x42a3a0
0x42a3a4
0x42a3a8
0x42a3ac
0x42a3b0
0x42a3b4
0x42a3b8
0x42a3bc
0x42a3c0
0x42a3c4
0x42a3c8
0x42a3cc
0x42a3d0
0x42a3d4
0x42a3d8
0x42a3dc
0x42a3e0
0x42a3e4
0x42a3e8
0x42a3ec
0x42a3f0
0x42a3f4
0x42a3f8
0x42a3fc
0x42a400
0x42a404
0x42a408
0x42a40c
0x42a410
0x42a414
0x42a418
0x42a41c
0x42a420
0x42a424
0x42a428
0x42a42c
0x42a430
0x42a434
0x42a438
0x42a43c
0x42a440
0x42a444
0x42a448
0x42a44c
0x42a450
0x42a454
0x42a458
0x42a45c
0x42a460
0x42a464
0x42a468
0x42a46c
0x42a470
0x42a474
0x42a478
0x42a47c
0x42a480
0x42a484
0x42a488
0x42a48c
0x42a490
0x42a494
0x42a498
0x42a49c
0x42a4a0
0x42a4a4
0x42a4a8
0x42a4ac
Library KERNEL32.dll:
0x429c34 CreateThread
0x429c38 GetCurrentProcessId
0x429c3c GetTempPathW
0x429c48 GetLastError
0x429c60 GlobalUnlock
0x429c64 GlobalFree
0x429c68 GlobalLock
0x429c6c GlobalAlloc
0x429c70 SetEvent
0x429c74 CloseHandle
0x429c78 CreateEventW
0x429c7c GetDiskFreeSpaceExW
0x429c80 lstrcpyW
0x429c84 lstrlenW
0x429c88 GetFileTime
0x429c8c WaitForSingleObject
0x429c90 GetCurrentThreadId
0x429c94 GetModuleFileNameW
0x429c98 GetStartupInfoW
0x429c9c GetModuleHandleW
0x429ca0 GetProcAddress
0x429ca4 ResetEvent
0x429cb4 GetCurrentProcess
0x429cb8 TerminateProcess
0x429cc8 InitializeSListHead
0x429ccc IsDebuggerPresent
0x429cd0 OutputDebugStringW
0x429cd4 GetDriveTypeW
0x429cdc CreateFileW
0x429ce0 CreateDirectoryW
0x429ce4 ReadFile
0x429ce8 WriteFile
0x429cec SetFilePointer
0x429cf0 GetFileSizeEx
0x429cf4 SetEndOfFile
0x429cf8 DeleteFileW
0x429cfc RemoveDirectoryW
0x429d00 GetFileAttributesW
0x429d04 FindFirstFileW
0x429d08 FindNextFileW
0x429d0c FindClose
0x429d10 WideCharToMultiByte
0x429d14 MultiByteToWideChar
0x429d18 VerSetConditionMask
0x429d1c VerifyVersionInfoW
Library USER32.dll:
0x429df8 GetWindowRect
0x429dfc GetCursorPos
0x429e00 SetRectEmpty
0x429e04 PostMessageW
0x429e08 IsWindowVisible
0x429e0c DrawTextW
0x429e10 PtInRect
0x429e14 ScrollDC
0x429e18 GetClientRect
0x429e1c SetTimer
0x429e20 UpdateWindow
0x429e24 EnableWindow
0x429e28 PeekMessageW
0x429e2c SendMessageW
0x429e30 SetFocus
0x429e34 GetFocus
0x429e38 GetMenu
0x429e3c GetParent
0x429e40 UnhookWindowsHookEx
0x429e44 LoadIconW
0x429e48 DrawIcon
0x429e4c LoadMenuW
0x429e50 IsZoomed
0x429e54 IsIconic
0x429e58 RedrawWindow
0x429e5c ModifyMenuW
0x429e60 GetSubMenu
0x429e64 RemoveMenu
0x429e68 InsertMenuW
0x429e70 GetKeyState
0x429e78 GetSystemMetrics
0x429e7c LoadBitmapW
Library GDI32.dll:
0x429bfc BitBlt
0x429c00 GetTextColor
0x429c04 CreateFontIndirectW
0x429c08 GetTextCharsetInfo
0x429c10 GetObjectW
0x429c14 CreateFontW
0x429c18 GetBkColor
0x429c1c RealizePalette
0x429c20 GetDeviceCaps
0x429c24 CreateBitmap
0x429c2c CreateCompatibleDC
Library ADVAPI32.dll:
0x429000 RegSetValueExW
0x429004 RegQueryValueExW
0x429008 RegOpenKeyExW
0x42900c RegCloseKey
0x429010 RegCreateKeyExW
0x429014 RegDeleteValueW
Library SHELL32.dll:
0x429dd0 ShellExecuteW
0x429dd4 SHGetMalloc
0x429dd8 SHBrowseForFolderW
0x429de4 SHGetFileInfoW
0x429de8 DragQueryFileW
Library COMCTL32.dll:
0x429b84 ImageList_GetIcon
0x429b8c ImageList_AddMasked
Library SHLWAPI.dll:
0x429df0 SHDeleteKeyW
Library OLEAUT32.dll:
0x429d24 SysAllocString
0x429d28 VariantClear
Library BCGCBPRO2500u140.dll:
Library WS2_32.dll:
0x429eb0 WSACleanup
0x429eb4 WSAStartup
Library VCRUNTIME140.dll:
0x429e84 _CxxThrowException
0x429e88 memcpy
0x429e8c __std_terminate
0x429e90 _purecall
0x429e94 wcschr
0x429e98 memset
0x429e9c __CxxFrameHandler3
0x429ea8 wcsrchr
Library api-ms-win-crt-stdio-l1-1-0.dll:
0x429f30 _set_fmode
0x429f34 __p__commode
Library api-ms-win-crt-time-l1-1-0.dll:
0x429f4c _localtime64_s
0x429f50 wcsftime
0x429f54 _mktime64
0x429f58 _time64

Hosts

No hosts contacted.

TCP

Source Source Port Destination Destination Port
165.193.78.234 80 192.168.56.101 49186

UDP

Source Source Port Destination Destination Port
192.168.56.101 55368 114.114.114.114 53
192.168.56.101 56539 114.114.114.114 53
192.168.56.101 63429 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 123 20.189.79.72 time.windows.com 123
192.168.56.101 51963 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 58367 224.0.0.252 5355
192.168.56.101 62191 224.0.0.252 5355
192.168.56.101 65004 224.0.0.252 5355
192.168.56.101 53945 239.255.255.250 1900

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.