13.0
0-day

1bf6f08f2432324bd7bf5cc0cca3ac23c559547f404c8f62be7a2d209f74aff4

dbabdb99ffe19f2ee957c4c566e06bfe.exe

分析耗时

130s

最近分析

文件大小

897.5KB
静态报毒 动态报毒 4GW@A0QWCBJI AI SCORE=82 AIDETECTVM ALI2000015 AUTO AUTOG CLASSIC CONFIDENCE DELF DELFINJECT DELPHILESS EMOY EMRP EVSLG FAREIT GENERICKD GENETIC HIGH CONFIDENCE HODXET HPLOKI KCLOUD KRYPTIK LOKIBOT MALWARE1 MALWARE@#3WQE70A6EY5W S + TROJ SCORE SMBD STATIC AI SUSGEN SUSPICIOUS PE TSCOPE TSPY UNSAFE VTSQ X2094 ZELPHIF 更多
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
McAfee Fareit-FVZ!DBABDB99FFE1 20201211 6.0.6.653
Alibaba Trojan:Win32/DelfInject.ali2000015 20190527 0.3.0.5
Baidu 20190318 1.0.0.2
Avast Win32:Malware-gen 20201210 21.1.5827.0
Kingsoft Win32.Troj.Undef.(kcloud) 20201211 2017.9.26.565
Tencent Win32.Trojan.Inject.Auto 20201211 1.0.0.1
CrowdStrike win/malicious_confidence_90% (W) 20190702 1.0
静态指标
The executable contains unknown PE section names indicative of a packer (could be a false positive) (3 个事件)
section CODE
section DATA
section BSS
The executable uses a known packer (1 个事件)
packer BobSoft Mini Delphi -> BoB / BobSoft
One or more processes crashed (13 个事件)
Time & API Arguments Status Return Repeated
1619963598.094
__exception__
stacktrace:
RtlFlsAlloc+0x421 EtwNotificationRegister-0x6ae ntdll+0x3ee84 @ 0x77d6ee84
RtlRunOnceComplete+0x3a4 LdrLoadDll-0xb1 ntdll+0x3c389 @ 0x77d6c389
LdrLoadDll+0x7b _strcmpi-0x304 ntdll+0x3c4b5 @ 0x77d6c4b5
New_ntdll_LdrLoadDll@16+0x7b New_ntdll_LdrUnloadDll@4-0xb7 @ 0x752cd4cf
LoadLibraryExW+0x178 LoadLibraryExA-0x2a kernelbase+0x11d2a @ 0x778f1d2a
shdyufmj+0xa23f8 @ 0x4a23f8
_CorValidateImage+0x83f _CorExeMain-0x2cc mscoree+0x4b0f @ 0x750f4b0f
_CorExeMain+0xf62 CreateConfigStream-0x209a mscoree+0x5d3d @ 0x750f5d3d
0x57005c

registers.esp: 1633872
registers.edi: 0
registers.eax: 0
registers.ebp: 1633912
registers.edx: 582600
registers.ebx: 0
registers.esi: 1634116
registers.ecx: 176
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0xfdb8148d
success 0 0
1619963605.5315
__exception__
stacktrace:
RtlFlsAlloc+0x421 EtwNotificationRegister-0x6ae ntdll+0x3ee84 @ 0x77d6ee84
RtlRunOnceComplete+0x3a4 LdrLoadDll-0xb1 ntdll+0x3c389 @ 0x77d6c389
LdrLoadDll+0x7b _strcmpi-0x304 ntdll+0x3c4b5 @ 0x77d6c4b5
New_ntdll_LdrLoadDll@16+0x7b New_ntdll_LdrUnloadDll@4-0xb7 @ 0x752cd4cf
LoadLibraryExW+0x178 LoadLibraryExA-0x2a kernelbase+0x11d2a @ 0x778f1d2a
shdyufmj+0xa23f8 @ 0x4a23f8
_CorValidateImage+0x83f _CorExeMain-0x2cc mscoree+0x4b0f @ 0x75154b0f
_CorExeMain+0xf62 CreateConfigStream-0x209a mscoree+0x5d3d @ 0x75155d3d
0x57005c

registers.esp: 1633872
registers.edi: 0
registers.eax: 0
registers.ebp: 1633912
registers.edx: 582600
registers.ebx: 0
registers.esi: 1634116
registers.ecx: 176
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0xfd92148d
success 0 0
1619963610.282
__exception__
stacktrace:
RtlFlsAlloc+0x421 EtwNotificationRegister-0x6ae ntdll+0x3ee84 @ 0x77d6ee84
RtlRunOnceComplete+0x3a4 LdrLoadDll-0xb1 ntdll+0x3c389 @ 0x77d6c389
LdrLoadDll+0x7b _strcmpi-0x304 ntdll+0x3c4b5 @ 0x77d6c4b5
New_ntdll_LdrLoadDll@16+0x7b New_ntdll_LdrUnloadDll@4-0xb7 @ 0x752cd4cf
LoadLibraryExW+0x178 LoadLibraryExA-0x2a kernelbase+0x11d2a @ 0x778f1d2a
shdyufmj+0xa23f8 @ 0x4a23f8
_CorValidateImage+0x83f _CorExeMain-0x2cc mscoree+0x4b0f @ 0x75104b0f
_CorExeMain+0xf62 CreateConfigStream-0x209a mscoree+0x5d3d @ 0x75105d3d
0x57005c

registers.esp: 1633872
registers.edi: 0
registers.eax: 0
registers.ebp: 1633912
registers.edx: 582600
registers.ebx: 0
registers.esi: 1634116
registers.ecx: 176
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0xff4e148d
success 0 0
1619963615.282125
__exception__
stacktrace:
RtlFlsAlloc+0x421 EtwNotificationRegister-0x6ae ntdll+0x3ee84 @ 0x77d6ee84
RtlRunOnceComplete+0x3a4 LdrLoadDll-0xb1 ntdll+0x3c389 @ 0x77d6c389
LdrLoadDll+0x7b _strcmpi-0x304 ntdll+0x3c4b5 @ 0x77d6c4b5
New_ntdll_LdrLoadDll@16+0x7b New_ntdll_LdrUnloadDll@4-0xb7 @ 0x752cd4cf
LoadLibraryExW+0x178 LoadLibraryExA-0x2a kernelbase+0x11d2a @ 0x778f1d2a
shdyufmj+0xa23f8 @ 0x4a23f8
_CorValidateImage+0x83f _CorExeMain-0x2cc mscoree+0x4b0f @ 0x75154b0f
_CorExeMain+0xf62 CreateConfigStream-0x209a mscoree+0x5d3d @ 0x75155d3d
0x57005c

registers.esp: 1633872
registers.edi: 0
registers.eax: 0
registers.ebp: 1633912
registers.edx: 582600
registers.ebx: 0
registers.esi: 1634116
registers.ecx: 176
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0xfdb0148d
success 0 0
1619963623.04775
__exception__
stacktrace:
RtlFlsAlloc+0x421 EtwNotificationRegister-0x6ae ntdll+0x3ee84 @ 0x77d6ee84
RtlRunOnceComplete+0x3a4 LdrLoadDll-0xb1 ntdll+0x3c389 @ 0x77d6c389
LdrLoadDll+0x7b _strcmpi-0x304 ntdll+0x3c4b5 @ 0x77d6c4b5
New_ntdll_LdrLoadDll@16+0x7b New_ntdll_LdrUnloadDll@4-0xb7 @ 0x752cd4cf
LoadLibraryExW+0x178 LoadLibraryExA-0x2a kernelbase+0x11d2a @ 0x778f1d2a
shdyufmj+0xa23f8 @ 0x4a23f8
_CorValidateImage+0x83f _CorExeMain-0x2cc mscoree+0x4b0f @ 0x751a4b0f
_CorExeMain+0xf62 CreateConfigStream-0x209a mscoree+0x5d3d @ 0x751a5d3d
0x57005c

registers.esp: 1633872
registers.edi: 0
registers.eax: 0
registers.ebp: 1633912
registers.edx: 582600
registers.ebx: 0
registers.esi: 1634116
registers.ecx: 176
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0xfddb148d
success 0 0
1619963635.001125
__exception__
stacktrace:
RtlFlsAlloc+0x421 EtwNotificationRegister-0x6ae ntdll+0x3ee84 @ 0x77d6ee84
RtlRunOnceComplete+0x3a4 LdrLoadDll-0xb1 ntdll+0x3c389 @ 0x77d6c389
LdrLoadDll+0x7b _strcmpi-0x304 ntdll+0x3c4b5 @ 0x77d6c4b5
New_ntdll_LdrLoadDll@16+0x7b New_ntdll_LdrUnloadDll@4-0xb7 @ 0x752cd4cf
LoadLibraryExW+0x178 LoadLibraryExA-0x2a kernelbase+0x11d2a @ 0x778f1d2a
shdyufmj+0xa23f8 @ 0x4a23f8
_CorValidateImage+0x83f _CorExeMain-0x2cc mscoree+0x4b0f @ 0x74ff4b0f
_CorExeMain+0xf62 CreateConfigStream-0x209a mscoree+0x5d3d @ 0x74ff5d3d
0x57005c

registers.esp: 1633872
registers.edi: 0
registers.eax: 0
registers.ebp: 1633912
registers.edx: 582600
registers.ebx: 0
registers.esi: 1634116
registers.ecx: 176
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0xff5e148d
success 0 0
1619963656.937625
__exception__
stacktrace:
RtlFlsAlloc+0x421 EtwNotificationRegister-0x6ae ntdll+0x3ee84 @ 0x77d6ee84
RtlRunOnceComplete+0x3a4 LdrLoadDll-0xb1 ntdll+0x3c389 @ 0x77d6c389
LdrLoadDll+0x7b _strcmpi-0x304 ntdll+0x3c4b5 @ 0x77d6c4b5
New_ntdll_LdrLoadDll@16+0x7b New_ntdll_LdrUnloadDll@4-0xb7 @ 0x752cd4cf
LoadLibraryExW+0x178 LoadLibraryExA-0x2a kernelbase+0x11d2a @ 0x778f1d2a
shdyufmj+0xa23f8 @ 0x4a23f8
_CorValidateImage+0x83f _CorExeMain-0x2cc mscoree+0x4b0f @ 0x74ff4b0f
_CorExeMain+0xf62 CreateConfigStream-0x209a mscoree+0x5d3d @ 0x74ff5d3d
0x57005c

registers.esp: 1633872
registers.edi: 0
registers.eax: 0
registers.ebp: 1633912
registers.edx: 582600
registers.ebx: 0
registers.esi: 1634116
registers.ecx: 176
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0xfd94148d
success 0 0
1619963664.688
__exception__
stacktrace:
RtlFlsAlloc+0x421 EtwNotificationRegister-0x6ae ntdll+0x3ee84 @ 0x77d6ee84
RtlRunOnceComplete+0x3a4 LdrLoadDll-0xb1 ntdll+0x3c389 @ 0x77d6c389
LdrLoadDll+0x7b _strcmpi-0x304 ntdll+0x3c4b5 @ 0x77d6c4b5
New_ntdll_LdrLoadDll@16+0x7b New_ntdll_LdrUnloadDll@4-0xb7 @ 0x752cd4cf
LoadLibraryExW+0x178 LoadLibraryExA-0x2a kernelbase+0x11d2a @ 0x778f1d2a
shdyufmj+0xa23f8 @ 0x4a23f8
_CorValidateImage+0x83f _CorExeMain-0x2cc mscoree+0x4b0f @ 0x74ff4b0f
_CorExeMain+0xf62 CreateConfigStream-0x209a mscoree+0x5d3d @ 0x74ff5d3d
0x57005c

registers.esp: 1633872
registers.edi: 0
registers.eax: 0
registers.ebp: 1633912
registers.edx: 582600
registers.ebx: 0
registers.esi: 1634116
registers.ecx: 176
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0xfd8a148d
success 0 0
1619963668.548125
__exception__
stacktrace:
RtlFlsAlloc+0x421 EtwNotificationRegister-0x6ae ntdll+0x3ee84 @ 0x77d6ee84
RtlRunOnceComplete+0x3a4 LdrLoadDll-0xb1 ntdll+0x3c389 @ 0x77d6c389
LdrLoadDll+0x7b _strcmpi-0x304 ntdll+0x3c4b5 @ 0x77d6c4b5
New_ntdll_LdrLoadDll@16+0x7b New_ntdll_LdrUnloadDll@4-0xb7 @ 0x752cd4cf
LoadLibraryExW+0x178 LoadLibraryExA-0x2a kernelbase+0x11d2a @ 0x778f1d2a
shdyufmj+0xa23f8 @ 0x4a23f8
_CorValidateImage+0x83f _CorExeMain-0x2cc mscoree+0x4b0f @ 0x74ff4b0f
_CorExeMain+0xf62 CreateConfigStream-0x209a mscoree+0x5d3d @ 0x74ff5d3d
0x57005c

registers.esp: 1633872
registers.edi: 0
registers.eax: 0
registers.ebp: 1633912
registers.edx: 582600
registers.ebx: 0
registers.esi: 1634116
registers.ecx: 176
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0xfdbb148d
success 0 0
1619963672.843502
__exception__
stacktrace:
RtlFlsAlloc+0x421 EtwNotificationRegister-0x6ae ntdll+0x3ee84 @ 0x77d6ee84
RtlRunOnceComplete+0x3a4 LdrLoadDll-0xb1 ntdll+0x3c389 @ 0x77d6c389
LdrLoadDll+0x7b _strcmpi-0x304 ntdll+0x3c4b5 @ 0x77d6c4b5
New_ntdll_LdrLoadDll@16+0x7b New_ntdll_LdrUnloadDll@4-0xb7 @ 0x752cd4cf
LoadLibraryExW+0x178 LoadLibraryExA-0x2a kernelbase+0x11d2a @ 0x778f1d2a
shdyufmj+0xa23f8 @ 0x4a23f8
_CorValidateImage+0x83f _CorExeMain-0x2cc mscoree+0x4b0f @ 0x74ff4b0f
_CorExeMain+0xf62 CreateConfigStream-0x209a mscoree+0x5d3d @ 0x74ff5d3d
0x57005c

registers.esp: 1633872
registers.edi: 0
registers.eax: 0
registers.ebp: 1633912
registers.edx: 582600
registers.ebx: 0
registers.esi: 1634116
registers.ecx: 176
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0xfdb6148d
success 0 0
1619963677.265375
__exception__
stacktrace:
RtlFlsAlloc+0x421 EtwNotificationRegister-0x6ae ntdll+0x3ee84 @ 0x77d6ee84
RtlRunOnceComplete+0x3a4 LdrLoadDll-0xb1 ntdll+0x3c389 @ 0x77d6c389
LdrLoadDll+0x7b _strcmpi-0x304 ntdll+0x3c4b5 @ 0x77d6c4b5
New_ntdll_LdrLoadDll@16+0x7b New_ntdll_LdrUnloadDll@4-0xb7 @ 0x752cd4cf
LoadLibraryExW+0x178 LoadLibraryExA-0x2a kernelbase+0x11d2a @ 0x778f1d2a
shdyufmj+0xa23f8 @ 0x4a23f8
_CorValidateImage+0x83f _CorExeMain-0x2cc mscoree+0x4b0f @ 0x74ff4b0f
_CorExeMain+0xf62 CreateConfigStream-0x209a mscoree+0x5d3d @ 0x74ff5d3d
0x57005c

registers.esp: 1633872
registers.edi: 0
registers.eax: 0
registers.ebp: 1633912
registers.edx: 582600
registers.ebx: 0
registers.esi: 1634116
registers.ecx: 176
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0xff3f148d
success 0 0
1619963682.062875
__exception__
stacktrace:
RtlFlsAlloc+0x421 EtwNotificationRegister-0x6ae ntdll+0x3ee84 @ 0x77d6ee84
RtlRunOnceComplete+0x3a4 LdrLoadDll-0xb1 ntdll+0x3c389 @ 0x77d6c389
LdrLoadDll+0x7b _strcmpi-0x304 ntdll+0x3c4b5 @ 0x77d6c4b5
New_ntdll_LdrLoadDll@16+0x7b New_ntdll_LdrUnloadDll@4-0xb7 @ 0x752cd4cf
LoadLibraryExW+0x178 LoadLibraryExA-0x2a kernelbase+0x11d2a @ 0x778f1d2a
shdyufmj+0xa23f8 @ 0x4a23f8
_CorValidateImage+0x83f _CorExeMain-0x2cc mscoree+0x4b0f @ 0x74ff4b0f
_CorExeMain+0xf62 CreateConfigStream-0x209a mscoree+0x5d3d @ 0x74ff5d3d
0x57005c

registers.esp: 1633872
registers.edi: 0
registers.eax: 0
registers.ebp: 1633912
registers.edx: 582600
registers.ebx: 0
registers.esi: 1634116
registers.ecx: 176
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0xff4d148d
success 0 0
1619963686.328375
__exception__
stacktrace:
RtlFlsAlloc+0x421 EtwNotificationRegister-0x6ae ntdll+0x3ee84 @ 0x77d6ee84
RtlRunOnceComplete+0x3a4 LdrLoadDll-0xb1 ntdll+0x3c389 @ 0x77d6c389
LdrLoadDll+0x7b _strcmpi-0x304 ntdll+0x3c4b5 @ 0x77d6c4b5
New_ntdll_LdrLoadDll@16+0x7b New_ntdll_LdrUnloadDll@4-0xb7 @ 0x752cd4cf
LoadLibraryExW+0x178 LoadLibraryExA-0x2a kernelbase+0x11d2a @ 0x778f1d2a
shdyufmj+0xa23f8 @ 0x4a23f8
_CorValidateImage+0x83f _CorExeMain-0x2cc mscoree+0x4b0f @ 0x74ff4b0f
_CorExeMain+0xf62 CreateConfigStream-0x209a mscoree+0x5d3d @ 0x74ff5d3d
0x57005c

registers.esp: 1633872
registers.edi: 0
registers.eax: 0
registers.ebp: 1633912
registers.edx: 582600
registers.ebx: 0
registers.esi: 1634116
registers.ecx: 176
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0xff38148d
success 0 0
行为判定
动态指标
One or more potentially interesting buffers were extracted, these generally contain injected code, configuration data, etc.
HTTP traffic contains suspicious features which may be indicative of malware related traffic (1 个事件)
suspicious_features POST method with no referer header suspicious_request POST https://update.googleapis.com/service/update2?cup2key=10:1003030015&cup2hreq=2018d622b4512f6c7ac269e9b432dde5b72963fca1303ea6ee38f0eba5ce5291
Performs some HTTP requests (5 个事件)
request HEAD http://redirector.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe
request HEAD http://r1---sn-j5o76n7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.105&mm=28&mn=sn-j5o76n7e&ms=nvh&mt=1619934493&mv=m&mvi=1&pl=23&shardbypass=yes
request HEAD http://r4---sn-j5o76n7l.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&mvi=4&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5oe7e&req_id=ee414b18acac6e35&cms_redirect=yes&ipbypass=yes&mip=59.50.85.28&mm=28&mn=sn-j5o76n7l&ms=nvh&mt=1619934734&mv=m
request GET http://r4---sn-j5o76n7l.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&mvi=4&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5oe7e&req_id=ee414b18acac6e35&cms_redirect=yes&ipbypass=yes&mip=59.50.85.28&mm=28&mn=sn-j5o76n7l&ms=nvh&mt=1619934734&mv=m
request POST https://update.googleapis.com/service/update2?cup2key=10:1003030015&cup2hreq=2018d622b4512f6c7ac269e9b432dde5b72963fca1303ea6ee38f0eba5ce5291
Sends data using the HTTP POST Method (1 个事件)
request POST https://update.googleapis.com/service/update2?cup2key=10:1003030015&cup2hreq=2018d622b4512f6c7ac269e9b432dde5b72963fca1303ea6ee38f0eba5ce5291
Allocates read-write-execute memory (usually to unpack itself) (50 out of 406 个事件)
Time & API Arguments Status Return Repeated
1619948414.022784
NtAllocateVirtualMemory
process_identifier: 368
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003e0000
success 0 0
1619948414.116784
NtProtectVirtualMemory
process_identifier: 368
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 36864
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x0045c000
success 0 0
1619948414.116784
NtAllocateVirtualMemory
process_identifier: 368
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x01df0000
success 0 0
1619963594.750502
NtAllocateVirtualMemory
process_identifier: 944
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x003e0000
success 0 0
1619963594.781502
NtProtectVirtualMemory
process_identifier: 944
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 36864
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x0045c000
success 0 0
1619963594.797502
NtAllocateVirtualMemory
process_identifier: 944
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x01f90000
success 0 0
1619963595.657
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x00400000
success 0 0
1619963595.704
NtAllocateVirtualMemory
process_identifier: 2316
region_size: 1441792
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 8192 (MEM_RESERVE)
base_address: 0x01ff0000
success 0 0
1619963595.704
NtAllocateVirtualMemory
process_identifier: 2316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x02110000
success 0 0
1619963595.704
NtAllocateVirtualMemory
process_identifier: 2316
region_size: 630784
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x01f40000
success 0 0
1619963595.704
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 602112
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x01f42000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x00602000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76351000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x00602000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76353000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x00602000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76354000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x00602000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76351000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x00602000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x77d4f000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x00602000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76353000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x00602000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76351000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x00602000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76351000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x00602000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76354000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x00602000
success 0 0
1619963597.985
NtProtectVirtualMemory
process_identifier: 2316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76351000
success 0 0
1619963596.048
NtAllocateVirtualMemory
process_identifier: 2260
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x01cf0000
success 0 0
1619963596.157
NtProtectVirtualMemory
process_identifier: 2260
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 36864
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x0045c000
success 0 0
1619963596.157
NtAllocateVirtualMemory
process_identifier: 2260
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x01fe0000
success 0 0
1619963603.641125
NtAllocateVirtualMemory
process_identifier: 3224
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x00360000
success 0 0
1619963603.969125
NtProtectVirtualMemory
process_identifier: 3224
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 36864
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x0045c000
success 0 0
1619963603.985125
NtAllocateVirtualMemory
process_identifier: 3224
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x02e50000
success 0 0
1619963605.3595
NtProtectVirtualMemory
process_identifier: 3300
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x00400000
success 0 0
1619963605.3905
NtAllocateVirtualMemory
process_identifier: 3300
region_size: 2162688
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 8192 (MEM_RESERVE)
base_address: 0x02120000
success 0 0
1619963605.3905
NtAllocateVirtualMemory
process_identifier: 3300
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x022f0000
success 0 0
1619963605.3905
NtAllocateVirtualMemory
process_identifier: 3300
region_size: 630784
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x01f30000
success 0 0
1619963605.4065
NtProtectVirtualMemory
process_identifier: 3300
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 602112
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x01f32000
success 0 0
1619963605.4845
NtProtectVirtualMemory
process_identifier: 3300
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x003a2000
success 0 0
1619963605.4845
NtProtectVirtualMemory
process_identifier: 3300
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76351000
success 0 0
1619963605.4845
NtProtectVirtualMemory
process_identifier: 3300
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x003a2000
success 0 0
1619963605.4845
NtProtectVirtualMemory
process_identifier: 3300
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76353000
success 0 0
1619963605.4845
NtProtectVirtualMemory
process_identifier: 3300
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x003a2000
success 0 0
1619963605.5005
NtProtectVirtualMemory
process_identifier: 3300
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76354000
success 0 0
1619963605.5005
NtProtectVirtualMemory
process_identifier: 3300
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x003a2000
success 0 0
1619963605.5005
NtProtectVirtualMemory
process_identifier: 3300
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
base_address: 0x76351000
success 0 0
Creates executable files on the filesystem (1 个事件)
file C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\web.vbs
Searches running processes potentially to identify processes for sandbox evasion, code injection or memory dumping (50 out of 69 个事件)
The binary likely contains encrypted or compressed data indicative of a packer (2 个事件)
entropy 7.557859168096437 section {'size_of_data': '0x00071c00', 'virtual_address': '0x00075000', 'entropy': 7.557859168096437, 'name': '.rsrc', 'virtual_size': '0x00071aa4'} description A section with a high entropy has been found
entropy 0.5075292805354155 description Overall entropy of this PE file is high
Expresses interest in specific running processes (1 个事件)
process shdyufmj.exe
Repeatedly searches for a not-found process, you may want to run a web browser during analysis (40 个事件)
Time & API Arguments Status Return Repeated
1619948414.132784
Process32NextW
process_name: dbabdb99ffe19f2ee957c4c566e06bfe.exe
snapshot_handle: 0x000000f8
process_identifier: 368
failed 0 0
1619963594.797502
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 472
failed 0 0
1619963596.298
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 3132
failed 0 0
1619963602.813
Process32NextW
process_name: GoogleUpdate.exe
snapshot_handle: 0x0000019c
process_identifier: 3200
failed 0 0
1619963604.016125
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 3280
failed 0 0
1619963605.984375
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 3468
failed 0 0
1619963607.750375
Process32NextW
process_name: shdyufmj.exe
snapshot_handle: 0x00000128
process_identifier: 3364
failed 0 0
1619963608.5935
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 3544
failed 0 0
1619963610.860125
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 3720
failed 0 0
1619963612.782125
Process32NextW
process_name: shdyufmj.exe
snapshot_handle: 0x00000124
process_identifier: 3628
failed 0 0
1619963613.937625
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 3792
failed 0 0
1619963616.843375
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 3964
failed 0 0
1619963620.500375
Process32NextW
process_name: shdyufmj.exe
snapshot_handle: 0x00000148
process_identifier: 3876
failed 0 0
1619963621.406875
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 4056
failed 0 0
1619963623.250502
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 1888
failed 0 0
1619963629.953502
Process32NextW
process_name: dllhost.exe
snapshot_handle: 0x00000184
process_identifier: 3320
failed 0 0
1619963630.89125
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 3044
failed 0 0
1619963635.21925
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 3700
failed 0 0
1619963652.59425
Process32NextW
process_name: shdyufmj.exe
snapshot_handle: 0x0000033c
process_identifier: 3528
failed 0 0
1619963653.078375
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 3836
failed 0 0
1619963657.14125
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 3972
failed 0 0
1619963662.62625
Process32NextW
process_name: is32bit.exe
snapshot_handle: 0x00000170
process_identifier: 3184
failed 0 0
1619963663.39075
Process32NextW
process_name: inject-x64.exe
snapshot_handle: 0x000000f8
process_identifier: 176
failed 0 0
1619963664.718875
Process32NextW
process_name: is32bit.exe
snapshot_handle: 0x000000f8
process_identifier: 3448
failed 0 0
1619963666.578875
Process32NextW
process_name: shdyufmj.exe
snapshot_handle: 0x0000012c
process_identifier: 3408
failed 0 0
1619963666.875875
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 2940
failed 0 0
1619963668.797625
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 1396
failed 0 0
1619963670.937625
Process32NextW
process_name: WerFault.exe
snapshot_handle: 0x00000128
process_identifier: 4032
failed 0 0
1619963671.312625
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 364
failed 0 0
1619963673.079
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 1324
failed 0 0
1619963675.063
Process32NextW
process_name: shdyufmj.exe
snapshot_handle: 0x00000124
process_identifier: 324
failed 0 0
1619963675.501125
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 3352
failed 0 0
1619963677.797875
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 3156
failed 0 0
1619963679.984875
Process32NextW
process_name: svchost.exe
snapshot_handle: 0x00000130
process_identifier: 3768
failed 0 0
1619963680.31325
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 2212
failed 0 0
1619963682.64125
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 3012
failed 0 0
1619963683.54825
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x00000114
process_identifier: 3012
failed 0 0
1619963684.95375
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 3172
failed 0 0
1619963686.734375
Process32NextW
process_name: inject-x86.exe
snapshot_handle: 0x000000f8
process_identifier: 1032
failed 0 0
1619963688.937375
Process32NextW
process_name: shdyufmj.exe
snapshot_handle: 0x0000012c
process_identifier: 2200
failed 0 0
网络通信
Communicates with host for which no DNS query was performed (1 个事件)
host 172.217.24.14
Creates an Alternate Data Stream (ADS) (1 个事件)
file C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe:ZoneIdentifier
Allocates execute permission to another process indicative of possible code injection (1 个事件)
Time & API Arguments Status Return Repeated
1619948414.288784
NtAllocateVirtualMemory
process_identifier: 2456
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0x00000100
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x000f0000
success 0 0
Installs itself for autorun at Windows startup (1 个事件)
file C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\web.vbs
Deletes executed files from disk (1 个事件)
file C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe
Creates a thread using NtQueueApcThread in a remote process potentially indicative of process injection (2 个事件)
Process injection Process 368 created a thread in remote process 2456
Time & API Arguments Status Return Repeated
1619948414.288784
NtQueueApcThread
thread_handle: 0x00000108
process_identifier: 2456
function_address: 0x000f05c0
parameter: 0x00100000
success 0 0
Potential code injection by writing to the memory of another process (2 个事件)
Time & API Arguments Status Return Repeated
1619948414.288784
WriteProcessMemory
process_identifier: 2456
buffer: Q¹0d‹‹@ ‹@ ‹‹‹@‰$‹$YÃVWR¾§ÆgNè„Yƒøv· ¿Zwf;Ït ¿Ntf;ÏuƒÂƒè…Àt‹ÎÁá‹þÁïϾ:Ï3ñBHué_‹Æ^ÃU‹ìQQ‹MSVW…Ét;¸MZf9u1‹A<Át*8PEu"‹@xƒeüÁ‹x‹X$‹p ‹@ùÙñ‰Eø…Àu 3À_^[ÉËM‹Eü‹†ÑèOÿÿÿ;E t ÿEü‹Eü;Eøràë׋Eü·C‹‡EëÊU‹ìQSW3ÿWWjWjh@ÿuÿV‹Øƒûÿu3Àë&WWWS‰}üÿV0W‹}EüPWÿu SÿV SÿV3À9}ü”À_[ÉÅÉtè•…Àt3Éf‰ÃU‹ììV‹ð…äüÿÿP3ÀPPjPÿVl…À…Žj\Xf‰Eü3Àj.f‰EþXjvf‰EðXf‰EòjbXf‰EôjsXf‰Eö3Àf‰EøUü…äüÿÿèÖ‹U è΍UðèÆÿu…ìþÿÿÿuPÿVxƒÄ …äüÿÿPÿV…ìþÿÿPèÂ@P…ìþÿÿP…äüÿÿPèîþÿÿƒÄ^ÉÃU‹ìì,j:XjZf‰EÜXjof‰EÞXjnf‰EàXjef‰EâXjIf‰EäXjdf‰EæXjef‰EèXjnf‰EêXjtf‰EìXjif‰EîXjff‰EðXjif‰EòXf‰EôjeXf‰EöjrXf‰Eø3Àf‰Eú…Ôýÿÿ謍UÜè÷EÿPÆEÿèPEÿP…ÔýÿÿPè?þÿÿƒÄÉÃU‹ìQƒeüV‹ðEüPÿuèþYY…Àtƒ}ütÿuüPÿu è þÿÿƒÄ …Àt3À@ë3À^ÉÃU‹ììSV‹ð‹Ï…øýÿÿè'‹Èè(þÿÿ3ÛS…øýÿÿPÿVWÿV8] uWÿu‹Æè~ÿÿÿYY‹Øë €} u5SWÿuÿWÿV(3ۃøÿ‹Ï•Ãèªþÿÿƒûu9]u WÿV(ƒÈPWÿV,3À@ë3À^[ÉÃU‹ìƒìSVWèsüÿÿ‹ø…ÿ„"h"¿ŠWèÌüÿÿ‹ØYY…Û„ jh0h„jÿӋð…ö„ñh¼Û«½W‰~`‰^@è•üÿÿhÒ¼‰W‰F$è‡üÿÿh|QgjW‰F(èyüÿÿhëI”W‰F,èküÿÿh•å©—W‰F0è]üÿÿh¥°(W‰F4èOüÿÿh)·W‰F8èAüÿÿh[uŠðW‰FDè3üÿÿƒÄ@‹Øhd†óuW‰^ è üÿÿh¢¦aëW‰F èüÿÿhÕOd"W‰Fèüÿÿhy.ÔW‰Fèöûÿÿh±÷W‰FèèûÿÿheóW÷W‰FèÚûÿÿh¯4P“W‰FèÌûÿÿh{=#W‰F<è¾ûÿÿƒÄ@hOû~ W‰Fè­ûÿÿhà=!6W‰FHèŸûÿÿhh‰#W‰è’ûÿÿ‰FLhÍeWè„ûÿÿhÓ1ÆVW‰FPèvûÿÿh7œ½W‰FTèhûÿÿh£-ãW‰FXèZûÿÿ‰F\ƒÄ8EðPÇEðshelÇEôl32ÿӋø…ÿt"hÀåz°W‰~dè,ûÿÿhêêºW‰FlèûÿÿƒÄ‰FpEøPÇEøuserfÇEü32ÆEþÿV ‹ø…ÿtAhqV°0W‰~hèìúÿÿhkV°0W‰FxèÞúÿÿh&cj—W‰FtèÐúÿÿh<cj—W‰F|èÂúÿÿƒÄ ‰†€‹Æë3À_^[ÉÃU‹ìƒì\V‹uW3ÿ;÷„îSè¤ýÿÿ‹Ø;ßu WÿDéՍ†‰EüPëj2ÿSPÿuüWWÿSL…ÀuïjdÿSPF‰Eø‰E9>tYÿ¶¶ŽQP¾ ‹Ãè¾üÿÿ‰}3ÿƒÄ 9>t1jDE¤WPèjEèWPèüƒÄEèPE¤PWWj WWWWÿuÿS$9¾(t†lP†,Pÿu‹Ãè½úÿÿƒÄ 9¾tëj2ÿSPÿuüWWÿSL…ÀuïjdÿSPÿuøÿSWÿSD[_3À^ÉÂU‹ìƒì SW3ÿWWjWjh€ÿu‰}øÿV‹Øƒûÿu3Àë>WSÿV‰Eô;Çt+jh0PWÿV@‰Eø;ÇtWMüQÿuô‰}üPSÿV‹Eü‹M ‰SÿV‹Eø_[É÷f‰f…ÒtV‹ð+ñƒÁ·f‰f…Òuñ^ÃU‹ìQQ‹E‰Eü‹EüE‰Eø‹Eü;Eøt‹EüŠM ˆ‹Eü@‰Eüëç‹EÉÃfƒ8V‹ðt ƒÆfƒ>u÷+ò· f‰ ƒÂf…Éuñ^ËD$Š@„Éuù+D$HÅÉu3ÀÃfƒ9‹Át ƒÀfƒ8u÷+ÁÑøÃ…Ét èÚÿÿÿ…ÀtDAþë fƒù\t ƒè·f…Éuï3ÀÃ
process_handle: 0x00000100
base_address: 0x000f0000
success 1 0
1619948414.288784
WriteProcessMemory
process_identifier: 2456
buffer: C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dbabdb99ffe19f2ee957c4c566e06bfe.exeC:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dbabdb99ffe19f2ee957c4c566e06bfe.exe" webset MQbk = creaTeoBJecT("wscrIPT.sheLl") MqBk.ruN """%ls""", 0, False
process_handle: 0x00000100
base_address: 0x00100000
success 1 0
Used NtSetContextThread to modify a thread in a remote process indicative of process injection (26 个事件)
Process injection Process 944 called NtSetContextThread to modify thread in remote process 2316
Process injection Process 3224 called NtSetContextThread to modify thread in remote process 3300
Process injection Process 3484 called NtSetContextThread to modify thread in remote process 3564
Process injection Process 3736 called NtSetContextThread to modify thread in remote process 3816
Process injection Process 4000 called NtSetContextThread to modify thread in remote process 4072
Process injection Process 3152 called NtSetContextThread to modify thread in remote process 3404
Process injection Process 3668 called NtSetContextThread to modify thread in remote process 3864
Process injection Process 1664 called NtSetContextThread to modify thread in remote process 3380
Process injection Process 3648 called NtSetContextThread to modify thread in remote process 2656
Process injection Process 3800 called NtSetContextThread to modify thread in remote process 392
Process injection Process 4076 called NtSetContextThread to modify thread in remote process 3576
Process injection Process 812 called NtSetContextThread to modify thread in remote process 2056
Process injection Process 3056 called NtSetContextThread to modify thread in remote process 4032
Time & API Arguments Status Return Repeated
1619963595.062502
NtSetContextThread
thread_handle: 0x00000108
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5503072
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 2316
success 0 0
1619963604.813125
NtSetContextThread
thread_handle: 0x00000108
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5503072
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 3300
success 0 0
1619963609.3905
NtSetContextThread
thread_handle: 0x00000108
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5503072
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 3564
success 0 0
1619963614.406625
NtSetContextThread
thread_handle: 0x00000108
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5503072
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 3816
success 0 0
1619963621.937875
NtSetContextThread
thread_handle: 0x00000108
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5503072
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 4072
success 0 0
1619963631.40725
NtSetContextThread
thread_handle: 0x00000108
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5503072
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 3404
success 0 0
1619963654.765375
NtSetContextThread
thread_handle: 0x00000108
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5503072
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 3864
success 0 0
1619963663.90675
NtSetContextThread
thread_handle: 0x00000108
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5503072
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 3380
success 0 0
1619963667.343875
NtSetContextThread
thread_handle: 0x00000108
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5503072
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 2656
success 0 0
1619963672.406625
NtSetContextThread
thread_handle: 0x00000108
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5503072
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 392
success 0 0
1619963676.641125
NtSetContextThread
thread_handle: 0x00000108
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5503072
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 3576
success 0 0
1619963681.48525
NtSetContextThread
thread_handle: 0x00000108
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5503072
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 2056
success 0 0
1619963685.89075
NtSetContextThread
thread_handle: 0x00000108
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5503072
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 4032
success 0 0
Resumed a suspended thread in a remote process potentially indicative of process injection (26 个事件)
Process injection Process 944 resumed a thread in remote process 2316
Process injection Process 3224 resumed a thread in remote process 3300
Process injection Process 3484 resumed a thread in remote process 3564
Process injection Process 3736 resumed a thread in remote process 3816
Process injection Process 4000 resumed a thread in remote process 4072
Process injection Process 3152 resumed a thread in remote process 3404
Process injection Process 3668 resumed a thread in remote process 3864
Process injection Process 1664 resumed a thread in remote process 3380
Process injection Process 3648 resumed a thread in remote process 2656
Process injection Process 3800 resumed a thread in remote process 392
Process injection Process 4076 resumed a thread in remote process 3576
Process injection Process 812 resumed a thread in remote process 2056
Process injection Process 3056 resumed a thread in remote process 4032
Time & API Arguments Status Return Repeated
1619963595.406502
NtResumeThread
thread_handle: 0x00000108
suspend_count: 1
process_identifier: 2316
success 0 0
1619963605.188125
NtResumeThread
thread_handle: 0x00000108
suspend_count: 1
process_identifier: 3300
success 0 0
1619963609.9685
NtResumeThread
thread_handle: 0x00000108
suspend_count: 1
process_identifier: 3564
success 0 0
1619963614.843625
NtResumeThread
thread_handle: 0x00000108
suspend_count: 1
process_identifier: 3816
success 0 0
1619963622.562875
NtResumeThread
thread_handle: 0x00000108
suspend_count: 1
process_identifier: 4072
success 0 0
1619963634.62625
NtResumeThread
thread_handle: 0x00000108
suspend_count: 1
process_identifier: 3404
success 0 0
1619963656.609375
NtResumeThread
thread_handle: 0x00000108
suspend_count: 1
process_identifier: 3864
success 0 0
1619963664.10975
NtResumeThread
thread_handle: 0x00000108
suspend_count: 1
process_identifier: 3380
success 0 0
1619963667.968875
NtResumeThread
thread_handle: 0x00000108
suspend_count: 1
process_identifier: 2656
success 0 0
1619963672.562625
NtResumeThread
thread_handle: 0x00000108
suspend_count: 1
process_identifier: 392
success 0 0
1619963676.829125
NtResumeThread
thread_handle: 0x00000108
suspend_count: 1
process_identifier: 3576
success 0 0
1619963681.79825
NtResumeThread
thread_handle: 0x00000108
suspend_count: 1
process_identifier: 2056
success 0 0
1619963686.10975
NtResumeThread
thread_handle: 0x00000108
suspend_count: 1
process_identifier: 4032
success 0 0
Generates some ICMP traffic
Executed a process and injected code into it, probably while unpacking (50 out of 109 个事件)
Time & API Arguments Status Return Repeated
1619948414.288784
CreateProcessInternalW
thread_identifier: 2340
thread_handle: 0x00000108
process_identifier: 2456
current_directory:
filepath: C:\Windows\System32\notepad.exe
track: 1
command_line:
filepath_r: C:\Windows\system32\notepad.exe
stack_pivoted: 0
creation_flags: 32 (NORMAL_PRIORITY_CLASS)
process_handle: 0x00000100
inherit_handles: 0
success 1 0
1619948414.288784
NtAllocateVirtualMemory
process_identifier: 2456
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0x00000100
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x000f0000
success 0 0
1619948414.288784
NtAllocateVirtualMemory
process_identifier: 2456
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 4 (PAGE_READWRITE)
process_handle: 0x00000100
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
base_address: 0x00100000
success 0 0
1619948414.288784
WriteProcessMemory
process_identifier: 2456
buffer: Q¹0d‹‹@ ‹@ ‹‹‹@‰$‹$YÃVWR¾§ÆgNè„Yƒøv· ¿Zwf;Ït ¿Ntf;ÏuƒÂƒè…Àt‹ÎÁá‹þÁïϾ:Ï3ñBHué_‹Æ^ÃU‹ìQQ‹MSVW…Ét;¸MZf9u1‹A<Át*8PEu"‹@xƒeüÁ‹x‹X$‹p ‹@ùÙñ‰Eø…Àu 3À_^[ÉËM‹Eü‹†ÑèOÿÿÿ;E t ÿEü‹Eü;Eøràë׋Eü·C‹‡EëÊU‹ìQSW3ÿWWjWjh@ÿuÿV‹Øƒûÿu3Àë&WWWS‰}üÿV0W‹}EüPWÿu SÿV SÿV3À9}ü”À_[ÉÅÉtè•…Àt3Éf‰ÃU‹ììV‹ð…äüÿÿP3ÀPPjPÿVl…À…Žj\Xf‰Eü3Àj.f‰EþXjvf‰EðXf‰EòjbXf‰EôjsXf‰Eö3Àf‰EøUü…äüÿÿèÖ‹U è΍UðèÆÿu…ìþÿÿÿuPÿVxƒÄ …äüÿÿPÿV…ìþÿÿPèÂ@P…ìþÿÿP…äüÿÿPèîþÿÿƒÄ^ÉÃU‹ìì,j:XjZf‰EÜXjof‰EÞXjnf‰EàXjef‰EâXjIf‰EäXjdf‰EæXjef‰EèXjnf‰EêXjtf‰EìXjif‰EîXjff‰EðXjif‰EòXf‰EôjeXf‰EöjrXf‰Eø3Àf‰Eú…Ôýÿÿ謍UÜè÷EÿPÆEÿèPEÿP…ÔýÿÿPè?þÿÿƒÄÉÃU‹ìQƒeüV‹ðEüPÿuèþYY…Àtƒ}ütÿuüPÿu è þÿÿƒÄ …Àt3À@ë3À^ÉÃU‹ììSV‹ð‹Ï…øýÿÿè'‹Èè(þÿÿ3ÛS…øýÿÿPÿVWÿV8] uWÿu‹Æè~ÿÿÿYY‹Øë €} u5SWÿuÿWÿV(3ۃøÿ‹Ï•Ãèªþÿÿƒûu9]u WÿV(ƒÈPWÿV,3À@ë3À^[ÉÃU‹ìƒìSVWèsüÿÿ‹ø…ÿ„"h"¿ŠWèÌüÿÿ‹ØYY…Û„ jh0h„jÿӋð…ö„ñh¼Û«½W‰~`‰^@è•üÿÿhÒ¼‰W‰F$è‡üÿÿh|QgjW‰F(èyüÿÿhëI”W‰F,èküÿÿh•å©—W‰F0è]üÿÿh¥°(W‰F4èOüÿÿh)·W‰F8èAüÿÿh[uŠðW‰FDè3üÿÿƒÄ@‹Øhd†óuW‰^ è üÿÿh¢¦aëW‰F èüÿÿhÕOd"W‰Fèüÿÿhy.ÔW‰Fèöûÿÿh±÷W‰FèèûÿÿheóW÷W‰FèÚûÿÿh¯4P“W‰FèÌûÿÿh{=#W‰F<è¾ûÿÿƒÄ@hOû~ W‰Fè­ûÿÿhà=!6W‰FHèŸûÿÿhh‰#W‰è’ûÿÿ‰FLhÍeWè„ûÿÿhÓ1ÆVW‰FPèvûÿÿh7œ½W‰FTèhûÿÿh£-ãW‰FXèZûÿÿ‰F\ƒÄ8EðPÇEðshelÇEôl32ÿӋø…ÿt"hÀåz°W‰~dè,ûÿÿhêêºW‰FlèûÿÿƒÄ‰FpEøPÇEøuserfÇEü32ÆEþÿV ‹ø…ÿtAhqV°0W‰~hèìúÿÿhkV°0W‰FxèÞúÿÿh&cj—W‰FtèÐúÿÿh<cj—W‰F|èÂúÿÿƒÄ ‰†€‹Æë3À_^[ÉÃU‹ìƒì\V‹uW3ÿ;÷„îSè¤ýÿÿ‹Ø;ßu WÿDéՍ†‰EüPëj2ÿSPÿuüWWÿSL…ÀuïjdÿSPF‰Eø‰E9>tYÿ¶¶ŽQP¾ ‹Ãè¾üÿÿ‰}3ÿƒÄ 9>t1jDE¤WPèjEèWPèüƒÄEèPE¤PWWj WWWWÿuÿS$9¾(t†lP†,Pÿu‹Ãè½úÿÿƒÄ 9¾tëj2ÿSPÿuüWWÿSL…ÀuïjdÿSPÿuøÿSWÿSD[_3À^ÉÂU‹ìƒì SW3ÿWWjWjh€ÿu‰}øÿV‹Øƒûÿu3Àë>WSÿV‰Eô;Çt+jh0PWÿV@‰Eø;ÇtWMüQÿuô‰}üPSÿV‹Eü‹M ‰SÿV‹Eø_[É÷f‰f…ÒtV‹ð+ñƒÁ·f‰f…Òuñ^ÃU‹ìQQ‹E‰Eü‹EüE‰Eø‹Eü;Eøt‹EüŠM ˆ‹Eü@‰Eüëç‹EÉÃfƒ8V‹ðt ƒÆfƒ>u÷+ò· f‰ ƒÂf…Éuñ^ËD$Š@„Éuù+D$HÅÉu3ÀÃfƒ9‹Át ƒÀfƒ8u÷+ÁÑøÃ…Ét èÚÿÿÿ…ÀtDAþë fƒù\t ƒè·f…Éuï3ÀÃ
process_handle: 0x00000100
base_address: 0x000f0000
success 1 0
1619948414.288784
WriteProcessMemory
process_identifier: 2456
buffer: C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dbabdb99ffe19f2ee957c4c566e06bfe.exeC:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\dbabdb99ffe19f2ee957c4c566e06bfe.exe" webset MQbk = creaTeoBJecT("wscrIPT.sheLl") MqBk.ruN """%ls""", 0, False
process_handle: 0x00000100
base_address: 0x00100000
success 1 0
1619963594.532
CreateProcessInternalW
thread_identifier: 1060
thread_handle: 0x000000d0
process_identifier: 944
current_directory:
filepath: C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe
track: 1
command_line:
filepath_r: C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe
stack_pivoted: 0
creation_flags: 32 (NORMAL_PRIORITY_CLASS)
process_handle: 0x000000cc
inherit_handles: 0
success 1 0
1619963595.000502
CreateProcessInternalW
thread_identifier: 340
thread_handle: 0x00000108
process_identifier: 2316
current_directory:
filepath:
track: 1
command_line: "C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe"
filepath_r:
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
process_handle: 0x00000100
inherit_handles: 0
success 1 0
1619963595.000502
NtUnmapViewOfSection
process_identifier: 2316
region_size: 4096
process_handle: 0x00000100
base_address: 0x00400000
success 0 0
1619963595.000502
NtMapViewOfSection
section_handle: 0x00000110
process_identifier: 2316
commit_size: 1314816
win32_protect: 64 (PAGE_EXECUTE_READWRITE)
buffer:
process_handle: 0x00000100
allocation_type: 0 ()
section_offset: 0
view_size: 1314816
base_address: 0x00400000
success 0 0
1619963595.062502
NtGetContextThread
thread_handle: 0x00000108
success 0 0
1619963595.062502
NtSetContextThread
thread_handle: 0x00000108
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5503072
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 2316
success 0 0
1619963595.406502
NtResumeThread
thread_handle: 0x00000108
suspend_count: 1
process_identifier: 2316
success 0 0
1619963595.609502
CreateProcessInternalW
thread_identifier: 2900
thread_handle: 0x0000010c
process_identifier: 2260
current_directory:
filepath:
track: 1
command_line: "C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe" 2 2316 6088984
filepath_r:
stack_pivoted: 0
creation_flags: 32 (NORMAL_PRIORITY_CLASS)
process_handle: 0x0000011c
inherit_handles: 0
success 1 0
1619963603.188
CreateProcessInternalW
thread_identifier: 3228
thread_handle: 0x000001a0
process_identifier: 3224
current_directory:
filepath: C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe
track: 1
command_line:
filepath_r: C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe
stack_pivoted: 0
creation_flags: 32 (NORMAL_PRIORITY_CLASS)
process_handle: 0x000001a4
inherit_handles: 0
success 1 0
1619963604.641125
CreateProcessInternalW
thread_identifier: 3304
thread_handle: 0x00000108
process_identifier: 3300
current_directory:
filepath:
track: 1
command_line: "C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe"
filepath_r:
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
process_handle: 0x00000100
inherit_handles: 0
success 1 0
1619963604.641125
NtUnmapViewOfSection
process_identifier: 3300
region_size: 4096
process_handle: 0x00000100
base_address: 0x00400000
success 0 0
1619963604.673125
NtMapViewOfSection
section_handle: 0x00000110
process_identifier: 3300
commit_size: 1314816
win32_protect: 64 (PAGE_EXECUTE_READWRITE)
buffer:
process_handle: 0x00000100
allocation_type: 0 ()
section_offset: 0
view_size: 1314816
base_address: 0x00400000
success 0 0
1619963604.813125
NtGetContextThread
thread_handle: 0x00000108
success 0 0
1619963604.813125
NtSetContextThread
thread_handle: 0x00000108
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5503072
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 3300
success 0 0
1619963605.188125
NtResumeThread
thread_handle: 0x00000108
suspend_count: 1
process_identifier: 3300
success 0 0
1619963605.266125
CreateProcessInternalW
thread_identifier: 3368
thread_handle: 0x0000010c
process_identifier: 3364
current_directory:
filepath:
track: 1
command_line: "C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe" 2 3300 6098765
filepath_r:
stack_pivoted: 0
creation_flags: 32 (NORMAL_PRIORITY_CLASS)
process_handle: 0x0000011c
inherit_handles: 0
success 1 0
1619963607.875375
CreateProcessInternalW
thread_identifier: 3488
thread_handle: 0x0000012c
process_identifier: 3484
current_directory:
filepath: C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe
track: 1
command_line:
filepath_r: C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe
stack_pivoted: 0
creation_flags: 32 (NORMAL_PRIORITY_CLASS)
process_handle: 0x00000130
inherit_handles: 0
success 1 0
1619963609.2655
CreateProcessInternalW
thread_identifier: 3568
thread_handle: 0x00000108
process_identifier: 3564
current_directory:
filepath:
track: 1
command_line: "C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe"
filepath_r:
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
process_handle: 0x00000100
inherit_handles: 0
success 1 0
1619963609.2655
NtUnmapViewOfSection
process_identifier: 3564
region_size: 4096
process_handle: 0x00000100
base_address: 0x00400000
success 0 0
1619963609.2975
NtMapViewOfSection
section_handle: 0x00000110
process_identifier: 3564
commit_size: 1314816
win32_protect: 64 (PAGE_EXECUTE_READWRITE)
buffer:
process_handle: 0x00000100
allocation_type: 0 ()
section_offset: 0
view_size: 1314816
base_address: 0x00400000
success 0 0
1619963609.3905
NtGetContextThread
thread_handle: 0x00000108
success 0 0
1619963609.3905
NtSetContextThread
thread_handle: 0x00000108
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5503072
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 3564
success 0 0
1619963609.9685
NtResumeThread
thread_handle: 0x00000108
suspend_count: 1
process_identifier: 3564
success 0 0
1619963610.1565
CreateProcessInternalW
thread_identifier: 3632
thread_handle: 0x0000010c
process_identifier: 3628
current_directory:
filepath:
track: 1
command_line: "C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe" 2 3564 6103546
filepath_r:
stack_pivoted: 0
creation_flags: 32 (NORMAL_PRIORITY_CLASS)
process_handle: 0x0000011c
inherit_handles: 0
success 1 0
1619963613.204125
CreateProcessInternalW
thread_identifier: 3740
thread_handle: 0x00000128
process_identifier: 3736
current_directory:
filepath: C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe
track: 1
command_line:
filepath_r: C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe
stack_pivoted: 0
creation_flags: 32 (NORMAL_PRIORITY_CLASS)
process_handle: 0x0000012c
inherit_handles: 0
success 1 0
1619963614.343625
CreateProcessInternalW
thread_identifier: 3820
thread_handle: 0x00000108
process_identifier: 3816
current_directory:
filepath:
track: 1
command_line: "C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe"
filepath_r:
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
process_handle: 0x00000100
inherit_handles: 0
success 1 0
1619963614.343625
NtUnmapViewOfSection
process_identifier: 3816
region_size: 4096
process_handle: 0x00000100
base_address: 0x00400000
success 0 0
1619963614.359625
NtMapViewOfSection
section_handle: 0x00000110
process_identifier: 3816
commit_size: 1314816
win32_protect: 64 (PAGE_EXECUTE_READWRITE)
buffer:
process_handle: 0x00000100
allocation_type: 0 ()
section_offset: 0
view_size: 1314816
base_address: 0x00400000
success 0 0
1619963614.406625
NtGetContextThread
thread_handle: 0x00000108
success 0 0
1619963614.406625
NtSetContextThread
thread_handle: 0x00000108
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5503072
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 3816
success 0 0
1619963614.843625
NtResumeThread
thread_handle: 0x00000108
suspend_count: 1
process_identifier: 3816
success 0 0
1619963615.797625
CreateProcessInternalW
thread_identifier: 3880
thread_handle: 0x0000010c
process_identifier: 3876
current_directory:
filepath:
track: 1
command_line: "C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe" 2 3816 6108421
filepath_r:
stack_pivoted: 0
creation_flags: 32 (NORMAL_PRIORITY_CLASS)
process_handle: 0x0000011c
inherit_handles: 0
success 1 0
1619963620.640375
CreateProcessInternalW
thread_identifier: 4004
thread_handle: 0x0000014c
process_identifier: 4000
current_directory:
filepath: C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe
track: 1
command_line:
filepath_r: C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe
stack_pivoted: 0
creation_flags: 32 (NORMAL_PRIORITY_CLASS)
process_handle: 0x00000150
inherit_handles: 0
success 1 0
1619963621.828875
CreateProcessInternalW
thread_identifier: 4076
thread_handle: 0x00000108
process_identifier: 4072
current_directory:
filepath:
track: 1
command_line: "C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe"
filepath_r:
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
process_handle: 0x00000100
inherit_handles: 0
success 1 0
1619963621.828875
NtUnmapViewOfSection
process_identifier: 4072
region_size: 4096
process_handle: 0x00000100
base_address: 0x00400000
success 0 0
1619963621.843875
NtMapViewOfSection
section_handle: 0x00000110
process_identifier: 4072
commit_size: 1314816
win32_protect: 64 (PAGE_EXECUTE_READWRITE)
buffer:
process_handle: 0x00000100
allocation_type: 0 ()
section_offset: 0
view_size: 1314816
base_address: 0x00400000
success 0 0
1619963621.937875
NtGetContextThread
thread_handle: 0x00000108
success 0 0
1619963621.937875
NtSetContextThread
thread_handle: 0x00000108
registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 5503072
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
process_identifier: 4072
success 0 0
1619963622.562875
NtResumeThread
thread_handle: 0x00000108
suspend_count: 1
process_identifier: 4072
success 0 0
1619963622.765875
CreateProcessInternalW
thread_identifier: 3084
thread_handle: 0x0000010c
process_identifier: 3080
current_directory:
filepath:
track: 1
command_line: "C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe" 2 4072 6116156
filepath_r:
stack_pivoted: 0
creation_flags: 32 (NORMAL_PRIORITY_CLASS)
process_handle: 0x0000011c
inherit_handles: 0
success 1 0
1619963630.390502
CreateProcessInternalW
thread_identifier: 1868
thread_handle: 0x00000188
process_identifier: 3152
current_directory:
filepath: C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe
track: 1
command_line:
filepath_r: C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe
stack_pivoted: 0
creation_flags: 32 (NORMAL_PRIORITY_CLASS)
process_handle: 0x0000018c
inherit_handles: 0
success 1 0
1619963631.26625
CreateProcessInternalW
thread_identifier: 3400
thread_handle: 0x00000108
process_identifier: 3404
current_directory:
filepath:
track: 1
command_line: "C:\Users\Administrator.Oskar-PC\AppData\Roaming\appdata\shdyufmj.exe"
filepath_r:
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
process_handle: 0x00000100
inherit_handles: 0
success 1 0
1619963631.26625
NtUnmapViewOfSection
process_identifier: 3404
region_size: 4096
process_handle: 0x00000100
base_address: 0x00400000
success 0 0
1619963631.28225
NtMapViewOfSection
section_handle: 0x00000110
process_identifier: 3404
commit_size: 1314816
win32_protect: 64 (PAGE_EXECUTE_READWRITE)
buffer:
process_handle: 0x00000100
allocation_type: 0 ()
section_offset: 0
view_size: 1314816
base_address: 0x00400000
success 0 0
1619963631.40725
NtGetContextThread
thread_handle: 0x00000108
success 0 0
File has been identified by 58 AntiVirus engines on VirusTotal as malicious (50 out of 58 个事件)
Bkav W32.AIDetectVM.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.43521097
FireEye Generic.mg.dbabdb99ffe19f2e
McAfee Fareit-FVZ!DBABDB99FFE1
Cylance Unsafe
Zillya Trojan.Injector.Win32.751075
Sangfor Malware
K7AntiVirus Trojan ( 0056cd011 )
Alibaba Trojan:Win32/DelfInject.ali2000015
K7GW Trojan ( 0056cd011 )
Cybereason malicious.938685
Arcabit Trojan.Generic.D2981449
Cyren W32/Injector.VTSQ-0325
Symantec Infostealer.Lokibot!43
APEX Malicious
Paloalto generic.ml
Kaspersky HEUR:Trojan.Win32.Kryptik.gen
BitDefender Trojan.GenericKD.43521097
NANO-Antivirus Trojan.Win32.Kryptik.hodxet
AegisLab Riskware.Win32.Malicious.1!c
Avast Win32:Malware-gen
Rising Trojan.Injector!1.C99D (CLASSIC)
Ad-Aware Trojan.GenericKD.43521097
Emsisoft Trojan.GenericKD.43521097 (B)
Comodo Malware@#3wqe70a6ey5w
F-Secure Trojan.TR/Injector.evslg
VIPRE Trojan.Win32.Generic!BT
TrendMicro TSPY_HPLOKI.SMBD
McAfee-GW-Edition BehavesLike.Win32.Fareit.cc
Sophos Mal/Generic-S + Troj/AutoG-IQ
SentinelOne Static AI - Suspicious PE
Jiangmin Trojan.Kryptik.ccl
Webroot W32.Trojan.TR.Injector.evslg
Avira TR/Injector.evslg
Antiy-AVL Trojan/Win32.Kryptik
Kingsoft Win32.Troj.Undef.(kcloud)
Microsoft PWS:Win32/Fareit.AQ!MTB
ZoneAlarm HEUR:Trojan.Win32.Kryptik.gen
GData Trojan.GenericKD.43521097
Cynet Malicious (score: 100)
AhnLab-V3 Suspicious/Win.Delphiless.X2094
BitDefenderTheta Gen:NN.ZelphiF.34670.4GW@a0QWCbji
ALYac Trojan.GenericKD.43521097
MAX malware (ai score=82)
VBA32 TScope.Trojan.Delf
Malwarebytes Trojan.MalPack.DLF
ESET-NOD32 a variant of Win32/Injector.EMRP
TrendMicro-HouseCall TSPY_HPLOKI.SMBD
Tencent Win32.Trojan.Inject.Auto
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

1992-06-20 06:22:17

Imports

Library kernel32.dll:
0x469164 VirtualFree
0x469168 VirtualAlloc
0x46916c LocalFree
0x469170 LocalAlloc
0x469174 GetVersion
0x469178 GetCurrentThreadId
0x469184 VirtualQuery
0x469188 WideCharToMultiByte
0x46918c MultiByteToWideChar
0x469190 lstrlenA
0x469194 lstrcpynA
0x469198 LoadLibraryExA
0x46919c GetThreadLocale
0x4691a0 GetStartupInfoA
0x4691a4 GetProcAddress
0x4691a8 GetModuleHandleA
0x4691ac GetModuleFileNameA
0x4691b0 GetLocaleInfoA
0x4691b4 GetCommandLineA
0x4691b8 FreeLibrary
0x4691bc FindFirstFileA
0x4691c0 FindClose
0x4691c4 ExitProcess
0x4691c8 WriteFile
0x4691d0 RtlUnwind
0x4691d4 RaiseException
0x4691d8 GetStdHandle
Library user32.dll:
0x4691e0 GetKeyboardType
0x4691e4 LoadStringA
0x4691e8 MessageBoxA
0x4691ec CharNextA
Library advapi32.dll:
0x4691f4 RegQueryValueExA
0x4691f8 RegOpenKeyExA
0x4691fc RegCloseKey
Library oleaut32.dll:
0x469204 SysFreeString
0x469208 SysReAllocStringLen
0x46920c SysAllocStringLen
Library kernel32.dll:
0x469214 TlsSetValue
0x469218 TlsGetValue
0x46921c LocalAlloc
0x469220 GetModuleHandleA
Library advapi32.dll:
0x469228 RegQueryValueExA
0x46922c RegOpenKeyExA
0x469230 RegCloseKey
Library kernel32.dll:
0x469238 lstrcpyA
0x46923c WriteFile
0x469240 WaitForSingleObject
0x469244 VirtualQuery
0x469248 VirtualProtect
0x46924c VirtualAlloc
0x469250 Sleep
0x469254 SizeofResource
0x469258 SetThreadLocale
0x46925c SetFilePointer
0x469260 SetEvent
0x469264 SetErrorMode
0x469268 SetEndOfFile
0x46926c ResetEvent
0x469270 ReadFile
0x469274 MultiByteToWideChar
0x469278 MulDiv
0x46927c LockResource
0x469280 LoadResource
0x469284 LoadLibraryA
0x469290 GlobalUnlock
0x469294 GlobalSize
0x469298 GlobalReAlloc
0x46929c GlobalHandle
0x4692a0 GlobalLock
0x4692a4 GlobalFree
0x4692a8 GlobalFindAtomA
0x4692ac GlobalDeleteAtom
0x4692b0 GlobalAlloc
0x4692b4 GlobalAddAtomA
0x4692b8 GetVersionExA
0x4692bc GetVersion
0x4692c0 GetUserDefaultLCID
0x4692c4 GetTickCount
0x4692c8 GetThreadLocale
0x4692cc GetSystemInfo
0x4692d0 GetStringTypeExA
0x4692d4 GetStdHandle
0x4692d8 GetProcAddress
0x4692dc GetModuleHandleA
0x4692e0 GetModuleFileNameA
0x4692e4 GetLocaleInfoA
0x4692e8 GetLocalTime
0x4692ec GetLastError
0x4692f0 GetFullPathNameA
0x4692f4 GetDiskFreeSpaceA
0x4692f8 GetDateFormatA
0x4692fc GetCurrentThreadId
0x469300 GetCurrentProcessId
0x469304 GetComputerNameA
0x469308 GetCPInfo
0x46930c GetACP
0x469310 FreeResource
0x469314 InterlockedExchange
0x469318 FreeLibrary
0x46931c FormatMessageA
0x469320 FindResourceA
0x469324 EnumCalendarInfoA
0x469330 CreateThread
0x469334 CreateFileA
0x469338 CreateEventA
0x46933c CompareStringA
0x469340 CloseHandle
Library version.dll:
0x469348 VerQueryValueA
0x469350 GetFileVersionInfoA
Library gdi32.dll:
0x469358 UnrealizeObject
0x46935c StretchBlt
0x469360 SetWindowOrgEx
0x469364 SetWinMetaFileBits
0x469368 SetViewportOrgEx
0x46936c SetTextColor
0x469370 SetStretchBltMode
0x469374 SetROP2
0x469378 SetPixel
0x46937c SetMapMode
0x469380 SetEnhMetaFileBits
0x469384 SetDIBColorTable
0x469388 SetBrushOrgEx
0x46938c SetBkMode
0x469390 SetBkColor
0x469394 SelectPalette
0x469398 SelectObject
0x46939c SaveDC
0x4693a0 RestoreDC
0x4693a4 RectVisible
0x4693a8 RealizePalette
0x4693ac PlayEnhMetaFile
0x4693b0 PatBlt
0x4693b4 MoveToEx
0x4693b8 MaskBlt
0x4693bc LineTo
0x4693c0 LPtoDP
0x4693c4 IntersectClipRect
0x4693c8 GetWindowOrgEx
0x4693cc GetWinMetaFileBits
0x4693d0 GetTextMetricsA
0x4693dc GetStockObject
0x4693e0 GetPixel
0x4693e4 GetPaletteEntries
0x4693e8 GetObjectA
0x4693f8 GetEnhMetaFileBits
0x4693fc GetDeviceCaps
0x469400 GetDIBits
0x469404 GetDIBColorTable
0x469408 GetDCOrgEx
0x469410 GetClipBox
0x469414 GetBrushOrgEx
0x469418 GetBitmapBits
0x46941c ExtTextOutA
0x469420 ExcludeClipRect
0x469424 DeleteObject
0x469428 DeleteEnhMetaFile
0x46942c DeleteDC
0x469430 CreateSolidBrush
0x469434 CreatePenIndirect
0x469438 CreatePalette
0x469440 CreateFontIndirectA
0x469444 CreateEnhMetaFileA
0x469448 CreateDIBitmap
0x46944c CreateDIBSection
0x469450 CreateCompatibleDC
0x469458 CreateBrushIndirect
0x46945c CreateBitmap
0x469460 CopyEnhMetaFileA
0x469464 CloseEnhMetaFile
0x469468 BitBlt
Library user32.dll:
0x469470 CreateWindowExA
0x469474 WindowFromPoint
0x469478 WinHelpA
0x46947c WaitMessage
0x469480 UpdateWindow
0x469484 UnregisterClassA
0x469488 UnhookWindowsHookEx
0x46948c TranslateMessage
0x469494 TrackPopupMenu
0x46949c ShowWindow
0x4694a0 ShowScrollBar
0x4694a4 ShowOwnedPopups
0x4694a8 ShowCursor
0x4694ac SetWindowsHookExA
0x4694b0 SetWindowPos
0x4694b4 SetWindowPlacement
0x4694b8 SetWindowLongA
0x4694bc SetTimer
0x4694c0 SetScrollRange
0x4694c4 SetScrollPos
0x4694c8 SetScrollInfo
0x4694cc SetRect
0x4694d0 SetPropA
0x4694d4 SetParent
0x4694d8 SetMenuItemInfoA
0x4694dc SetMenu
0x4694e0 SetForegroundWindow
0x4694e4 SetFocus
0x4694e8 SetCursor
0x4694ec SetClassLongA
0x4694f0 SetCapture
0x4694f4 SetActiveWindow
0x4694f8 SendMessageA
0x4694fc ScrollWindow
0x469500 ScreenToClient
0x469504 RemovePropA
0x469508 RemoveMenu
0x46950c ReleaseDC
0x469510 ReleaseCapture
0x46951c RegisterClassA
0x469520 RedrawWindow
0x469524 PtInRect
0x469528 PostQuitMessage
0x46952c PostMessageA
0x469530 PeekMessageA
0x469534 OffsetRect
0x469538 OemToCharA
0x46953c MessageBoxA
0x469540 MapWindowPoints
0x469544 MapVirtualKeyA
0x469548 LoadStringA
0x46954c LoadKeyboardLayoutA
0x469550 LoadIconA
0x469554 LoadCursorA
0x469558 LoadBitmapA
0x46955c KillTimer
0x469560 IsZoomed
0x469564 IsWindowVisible
0x469568 IsWindowEnabled
0x46956c IsWindow
0x469570 IsRectEmpty
0x469574 IsIconic
0x469578 IsDialogMessageA
0x46957c IsChild
0x469580 InvalidateRect
0x469584 IntersectRect
0x469588 InsertMenuItemA
0x46958c InsertMenuA
0x469590 InflateRect
0x469598 GetWindowTextA
0x46959c GetWindowRect
0x4695a0 GetWindowPlacement
0x4695a4 GetWindowLongA
0x4695a8 GetWindowDC
0x4695ac GetTopWindow
0x4695b0 GetSystemMetrics
0x4695b4 GetSystemMenu
0x4695b8 GetSysColorBrush
0x4695bc GetSysColor
0x4695c0 GetSubMenu
0x4695c4 GetScrollRange
0x4695c8 GetScrollPos
0x4695cc GetScrollInfo
0x4695d0 GetPropA
0x4695d4 GetParent
0x4695d8 GetWindow
0x4695dc GetMessageTime
0x4695e0 GetMenuStringA
0x4695e4 GetMenuState
0x4695e8 GetMenuItemInfoA
0x4695ec GetMenuItemID
0x4695f0 GetMenuItemCount
0x4695f4 GetMenu
0x4695f8 GetLastActivePopup
0x4695fc GetKeyboardState
0x469604 GetKeyboardLayout
0x469608 GetKeyState
0x46960c GetKeyNameTextA
0x469610 GetIconInfo
0x469614 GetForegroundWindow
0x469618 GetFocus
0x46961c GetDlgItem
0x469620 GetDesktopWindow
0x469624 GetDCEx
0x469628 GetDC
0x46962c GetCursorPos
0x469630 GetCursor
0x469634 GetClipboardData
0x469638 GetClientRect
0x46963c GetClassNameA
0x469640 GetClassInfoA
0x469644 GetCapture
0x469648 GetActiveWindow
0x46964c FrameRect
0x469650 FindWindowA
0x469654 FillRect
0x469658 EqualRect
0x46965c EnumWindows
0x469660 EnumThreadWindows
0x469664 EndPaint
0x469668 EnableWindow
0x46966c EnableScrollBar
0x469670 EnableMenuItem
0x469674 DrawTextA
0x469678 DrawMenuBar
0x46967c DrawIconEx
0x469680 DrawIcon
0x469684 DrawFrameControl
0x469688 DrawEdge
0x46968c DispatchMessageA
0x469690 DestroyWindow
0x469694 DestroyMenu
0x469698 DestroyIcon
0x46969c DestroyCursor
0x4696a0 DeleteMenu
0x4696a4 DefWindowProcA
0x4696a8 DefMDIChildProcA
0x4696ac DefFrameProcA
0x4696b0 CreatePopupMenu
0x4696b4 CreateMenu
0x4696b8 CreateIcon
0x4696bc ClientToScreen
0x4696c0 CheckMenuItem
0x4696c4 CallWindowProcA
0x4696c8 CallNextHookEx
0x4696cc BeginPaint
0x4696d0 CharNextA
0x4696d4 CharLowerBuffA
0x4696d8 CharLowerA
0x4696dc CharToOemA
0x4696e0 AdjustWindowRectEx
Library kernel32.dll:
0x4696ec Sleep
Library oleaut32.dll:
0x4696f4 SafeArrayPtrOfIndex
0x4696f8 SafeArrayGetUBound
0x4696fc SafeArrayGetLBound
0x469700 SafeArrayCreate
0x469704 VariantChangeType
0x469708 VariantCopy
0x46970c VariantClear
0x469710 VariantInit
Library ole32.dll:
0x46971c IsAccelerator
0x469720 OleDraw
0x469728 CoTaskMemFree
0x46972c ProgIDFromCLSID
0x469730 StringFromCLSID
0x469734 CoCreateInstance
0x469738 CoGetClassObject
0x46973c CoUninitialize
0x469740 CoInitialize
0x469744 IsEqualGUID
Library oleaut32.dll:
0x46974c GetErrorInfo
0x469750 GetActiveObject
0x469754 SysFreeString
Library comctl32.dll:
0x469764 ImageList_Write
0x469768 ImageList_Read
0x469778 ImageList_DragMove
0x46977c ImageList_DragLeave
0x469780 ImageList_DragEnter
0x469784 ImageList_EndDrag
0x469788 ImageList_BeginDrag
0x46978c ImageList_Remove
0x469790 ImageList_DrawEx
0x469794 ImageList_Draw
0x4697a4 ImageList_Add
0x4697ac ImageList_Destroy
0x4697b0 ImageList_Create
Library comdlg32.dll:
0x4697b8 GetOpenFileNameA

Hosts

No hosts contacted.

TCP

Source Source Port Destination Destination Port
192.168.56.101 49221 113.108.239.130 r1---sn-j5o76n7e.gvt1.com 80
192.168.56.101 49220 203.208.41.33 redirector.gvt1.com 80
192.168.56.101 49219 203.208.41.66 update.googleapis.com 443
192.168.56.101 49222 58.63.233.69 r4---sn-j5o76n7l.gvt1.com 80

UDP

Source Source Port Destination Destination Port
192.168.56.101 49235 114.114.114.114 53
192.168.56.101 50534 114.114.114.114 53
192.168.56.101 53237 114.114.114.114 53
192.168.56.101 53657 114.114.114.114 53
192.168.56.101 56539 114.114.114.114 53
192.168.56.101 57756 114.114.114.114 53
192.168.56.101 62318 114.114.114.114 53
192.168.56.101 65004 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 51808 224.0.0.252 5355
192.168.56.101 55368 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 57874 224.0.0.252 5355
192.168.56.101 60123 224.0.0.252 5355
192.168.56.101 62191 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900
192.168.56.101 50535 239.255.255.250 3702
192.168.56.101 56540 239.255.255.250 3702
192.168.56.101 56807 239.255.255.250 1900

HTTP & HTTPS Requests

URI Data
http://redirector.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe
HEAD /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Host: redirector.gvt1.com

http://r4---sn-j5o76n7l.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&mvi=4&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5oe7e&req_id=ee414b18acac6e35&cms_redirect=yes&ipbypass=yes&mip=59.50.85.28&mm=28&mn=sn-j5o76n7l&ms=nvh&mt=1619934734&mv=m
HEAD /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&mvi=4&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5oe7e&req_id=ee414b18acac6e35&cms_redirect=yes&ipbypass=yes&mip=59.50.85.28&mm=28&mn=sn-j5o76n7l&ms=nvh&mt=1619934734&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Host: r4---sn-j5o76n7l.gvt1.com

http://r4---sn-j5o76n7l.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&mvi=4&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5oe7e&req_id=ee414b18acac6e35&cms_redirect=yes&ipbypass=yes&mip=59.50.85.28&mm=28&mn=sn-j5o76n7l&ms=nvh&mt=1619934734&mv=m
GET /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&mvi=4&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5oe7e&req_id=ee414b18acac6e35&cms_redirect=yes&ipbypass=yes&mip=59.50.85.28&mm=28&mn=sn-j5o76n7l&ms=nvh&mt=1619934734&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 13 Apr 2021 03:03:58 GMT
Range: bytes=7102-18336
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Host: r4---sn-j5o76n7l.gvt1.com

http://r1---sn-j5o76n7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.105&mm=28&mn=sn-j5o76n7e&ms=nvh&mt=1619934493&mv=m&mvi=1&pl=23&shardbypass=yes
HEAD /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.105&mm=28&mn=sn-j5o76n7e&ms=nvh&mt=1619934493&mv=m&mvi=1&pl=23&shardbypass=yes HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Host: r1---sn-j5o76n7e.gvt1.com

http://r4---sn-j5o76n7l.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&mvi=4&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5oe7e&req_id=ee414b18acac6e35&cms_redirect=yes&ipbypass=yes&mip=59.50.85.28&mm=28&mn=sn-j5o76n7l&ms=nvh&mt=1619934734&mv=m
GET /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&mvi=4&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5oe7e&req_id=ee414b18acac6e35&cms_redirect=yes&ipbypass=yes&mip=59.50.85.28&mm=28&mn=sn-j5o76n7l&ms=nvh&mt=1619934734&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 13 Apr 2021 03:03:58 GMT
Range: bytes=0-7101
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Host: r4---sn-j5o76n7l.gvt1.com

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.