1.8
低危

9443c22ad481bec0fab0b36b449438ec3babbb9a12dbc1e494bbfe9afbacea7b

db03af99a86e88e4f9578717236fbe8e.exe

分析耗时

73s

最近分析

文件大小

1.4MB
静态报毒 动态报毒 433LKXCYEDIGJA5L0BNBG AI SCORE=99 BITCOIN MINER BITCOINMIN BITCOINMINER BTCMINE COINBITMINER COINMINER EYCIZU GENERIC@ML GENERICRXBK HIGH CONFIDENCE KLON MALXMR MINERS POTENTIALRISK RDML RISKTOOL SUSPICIOUS PE THAOBDAH TNEGA TOOL TSGENERIC UNSAFE XAXD 更多
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
McAfee GenericRXBK-VS!DB03AF99A86E 20191122 6.0.6.653
Alibaba RiskTool:Win32/Miners.4fe05f61 20190527 0.3.0.5
Avast Win32:BitCoinMiner-JU [Trj] 20191122 18.4.3895.0
Tencent 20191122 1.0.0.1
Baidu 20190318 1.0.0.2
Kingsoft 20191122 2013.8.14.323
CrowdStrike 20190702 1.0
静态指标
行为判定
动态指标
网络通信
Communicates with host for which no DNS query was performed (1 个事件)
host 172.217.24.14
File has been identified by 46 AntiVirus engines on VirusTotal as malicious (46 个事件)
DrWeb Tool.BtcMine.150
MicroWorld-eScan Application.BitCoinMiner.FJ
CAT-QuickHeal Risktool.Bitcoinmin.21102
McAfee GenericRXBK-VS!DB03AF99A86E
Cylance Unsafe
Zillya Backdoor.Klon.Win32.1093
K7AntiVirus Adware ( 0052c4711 )
Alibaba RiskTool:Win32/Miners.4fe05f61
K7GW Adware ( 0052c4711 )
Cybereason malicious.9a86e8
Arcabit Application.BitCoinMiner.FJ
Symantec Trojan.Coinbitminer
ESET-NOD32 a variant of Win32/CoinMiner.BA potentially unwanted
TotalDefense Win32/Tnega.XAXD!suspicious
Kaspersky not-a-virus:RiskTool.Win32.BitCoinMiner.lkl
BitDefender Application.BitCoinMiner.FJ
NANO-Antivirus Riskware.Win32.BitCoinMiner.eycizu
Avast Win32:BitCoinMiner-JU [Trj]
Ad-Aware Application.BitCoinMiner.FJ
Emsisoft Application.BitCoinMiner.FJ (B)
F-Secure PotentialRisk.PUA/CoinMiner.Gen
VIPRE Trojan.Win32.CoinMiner.ba (v)
TrendMicro Coinminer_MALXMR.THAOBDAH
McAfee-GW-Edition BehavesLike.Win32.PUP.th
FireEye Generic.mg.db03af99a86e88e4
Sophos Bitcoin Miner (PUA)
SentinelOne DFI - Suspicious PE
Jiangmin RiskTool.BitCoinMiner.ct
Webroot PUA.Gen
Avira PUA/CoinMiner.Gen
Antiy-AVL Trojan/Win32.TSGeneric
Microsoft PUA:Win32/CoinMiner
Endgame malicious (high confidence)
ViRobot Adware.Coinminer.1472526
ZoneAlarm not-a-virus:RiskTool.Win32.BitCoinMiner.lkl
GData Application.BitCoinMiner.FJ
Acronis suspicious
MAX malware (ai score=99)
TrendMicro-HouseCall Coinminer_MALXMR.THAOBDAH
Rising Trojan.Generic@ML.92 (RDML:/433LkXcYEDigja5l0bnbg)
Yandex Riskware.Agent!
Ikarus Trojan.Crypt
Fortinet Riskware/BitCoinMiner.BA!tr
AVG Win32:BitCoinMiner-JU [Trj]
Panda Trj/CI.A
Qihoo-360 Win32/Virus.RiskTool.91f
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2013-11-05 21:33:38

Imports

Library OpenCL.dll:
0x51f49c clBuildProgram
0x51f4a0 clCreateBuffer
0x51f4ac clCreateKernel
0x51f4bc clEnqueueReadBuffer
0x51f4c4 clFinish
0x51f4c8 clGetDeviceIDs
0x51f4cc clGetDeviceInfo
0x51f4d0 clGetPlatformIDs
0x51f4d4 clGetPlatformInfo
0x51f4dc clGetProgramInfo
0x51f4e4 clReleaseContext
0x51f4e8 clReleaseKernel
0x51f4ec clReleaseProgram
0x51f4f0 clSetKernelArg
Library ADVAPI32.DLL:
0x51f4fc FreeSid
Library libcurl-4.dll:
0x51f510 curl_easy_cleanup
0x51f514 curl_easy_getinfo
0x51f518 curl_easy_init
0x51f51c curl_easy_perform
0x51f520 curl_easy_reset
0x51f524 curl_easy_setopt
0x51f528 curl_global_cleanup
0x51f52c curl_global_init
0x51f530 curl_slist_append
0x51f534 curl_slist_free_all
Library KERNEL32.dll:
0x51f53c AllocConsole
0x51f540 AttachConsole
0x51f544 CancelIo
0x51f548 CloseHandle
0x51f550 CreateEventA
0x51f554 CreateFileA
0x51f558 CreateMutexA
0x51f55c CreateSemaphoreA
0x51f568 DeviceIoControl
0x51f56c DuplicateHandle
0x51f574 ExitProcess
0x51f578 FormatMessageA
0x51f57c FreeLibrary
0x51f580 GetCommModemStatus
0x51f584 GetConsoleMode
0x51f58c GetCurrentProcess
0x51f590 GetCurrentProcessId
0x51f594 GetCurrentThread
0x51f598 GetCurrentThreadId
0x51f59c GetFileType
0x51f5a0 GetLastError
0x51f5a4 GetModuleHandleA
0x51f5b0 GetOverlappedResult
0x51f5b4 GetProcAddress
0x51f5bc GetStdHandle
0x51f5c0 GetSystemDirectoryA
0x51f5c8 GetThreadContext
0x51f5cc GetThreadPriority
0x51f5d0 GetVersionExA
0x51f5d8 InterlockedExchange
0x51f5e0 IsDBCSLeadByteEx
0x51f5e8 LoadLibraryA
0x51f5ec MultiByteToWideChar
0x51f5f0 OpenProcess
0x51f5f4 PeekConsoleInputA
0x51f5f8 PurgeComm
0x51f604 ReadConsoleInputA
0x51f608 ReleaseMutex
0x51f60c ReleaseSemaphore
0x51f610 ResetEvent
0x51f614 ResumeThread
0x51f618 SetCommConfig
0x51f61c SetCommTimeouts
0x51f628 SetConsoleMode
0x51f630 SetEvent
0x51f634 SetLastError
0x51f63c SetThreadContext
0x51f640 SetThreadPriority
0x51f648 SetWaitableTimer
0x51f64c Sleep
0x51f650 SleepEx
0x51f654 SuspendThread
0x51f658 TerminateThread
0x51f65c TlsAlloc
0x51f660 TlsFree
0x51f664 TlsGetValue
0x51f668 TlsSetValue
0x51f66c VirtualProtect
0x51f670 VirtualQuery
0x51f678 WaitForSingleObject
0x51f67c WideCharToMultiByte
0x51f680 WriteConsoleOutputA
Library msvcrt.dll:
0x51f688 _access
0x51f68c _execv
0x51f690 _fdopen
0x51f694 _isatty
0x51f698 _read
0x51f69c _stat
0x51f6a0 _strdup
0x51f6a4 _write
Library msvcrt.dll:
0x51f6ac __getmainargs
0x51f6b0 __mb_cur_max
0x51f6b4 __p__environ
0x51f6b8 __p__fmode
0x51f6bc __set_app_type
0x51f6c0 _assert
0x51f6c4 _beginthreadex
0x51f6c8 _cexit
0x51f6cc _close
0x51f6d0 _endthreadex
0x51f6d4 _errno
0x51f6d8 _flsbuf
0x51f6dc _ftime
0x51f6e0 _get_osfhandle
0x51f6e4 _iob
0x51f6e8 _isctype
0x51f6ec _onexit
0x51f6f0 _open
0x51f6f4 _open_osfhandle
0x51f6f8 _pctype
0x51f6fc _setjmp
0x51f700 _setmode
0x51f704 _snprintf
0x51f708 _stricmp
0x51f70c _strnicmp
0x51f710 _vsnprintf
0x51f714 abort
0x51f718 atexit
0x51f71c atof
0x51f720 atoi
0x51f724 bsearch
0x51f728 calloc
0x51f72c exit
0x51f730 exp
0x51f734 fclose
0x51f738 fflush
0x51f73c fgetc
0x51f740 floor
0x51f744 fopen
0x51f748 fputc
0x51f74c fread
0x51f750 free
0x51f754 fseek
0x51f758 ftell
0x51f75c fwrite
0x51f760 getenv
0x51f764 localeconv
0x51f768 localtime
0x51f76c log
0x51f770 log10
0x51f774 longjmp
0x51f778 malloc
0x51f77c mbstowcs
0x51f780 memchr
0x51f784 memcmp
0x51f788 memcpy
0x51f78c memmove
0x51f790 memset
0x51f794 perror
0x51f798 qsort
0x51f79c raise
0x51f7a0 realloc
0x51f7a4 setlocale
0x51f7a8 setvbuf
0x51f7ac signal
0x51f7b0 sprintf
0x51f7b4 sscanf
0x51f7b8 strcat
0x51f7bc strchr
0x51f7c0 strcmp
0x51f7c4 strcpy
0x51f7c8 strcspn
0x51f7cc strerror
0x51f7d0 strlen
0x51f7d4 strncat
0x51f7d8 strncmp
0x51f7dc strncpy
0x51f7e0 strrchr
0x51f7e4 strstr
0x51f7e8 strtod
0x51f7ec strtok
0x51f7f0 strtol
0x51f7f4 time
0x51f7f8 tolower
0x51f7fc toupper
0x51f800 vfprintf
0x51f804 wcslen
0x51f808 wcstombs
Library WINMM.DLL:
0x51f810 timeBeginPeriod
0x51f814 timeEndPeriod
Library WS2_32.dll:
0x51f81c WSAGetLastError
0x51f820 __WSAFDIsSet
0x51f824 accept
0x51f828 bind
0x51f82c closesocket
0x51f830 connect
0x51f834 freeaddrinfo
0x51f838 getaddrinfo
0x51f83c getsockopt
0x51f840 htonl
0x51f844 htons
0x51f848 inet_addr
0x51f84c inet_ntoa
0x51f850 ioctlsocket
0x51f854 listen
0x51f858 ntohl
0x51f85c ntohs
0x51f860 recv
0x51f864 recvfrom
0x51f868 select
0x51f86c send
0x51f870 sendto
0x51f874 setsockopt
0x51f878 shutdown
0x51f87c socket

Hosts

No hosts contacted.

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 49235 114.114.114.114 53
192.168.56.101 50534 114.114.114.114 53
192.168.56.101 56539 114.114.114.114 53
192.168.56.101 58367 114.114.114.114 53
192.168.56.101 65004 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 123 20.189.79.72 time.windows.com 123
192.168.56.101 55368 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 60123 224.0.0.252 5355
192.168.56.101 62191 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900
192.168.56.101 56807 239.255.255.250 1900
192.168.56.101 58368 239.255.255.250 3702
192.168.56.101 58370 239.255.255.250 3702
192.168.56.101 58707 239.255.255.250 3702
192.168.56.101 62192 239.255.255.250 3702

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.