1.1
低危

1a8e01a5b5599bc6e941f0c9581a1c20bea892ff58579f991984f4c08c48c515

1a8e01a5b5599bc6e941f0c9581a1c20bea892ff58579f991984f4c08c48c515.exe

分析耗时

194s

最近分析

380天前

文件大小

595.5KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN WORM MIRA
鹰眼引擎
DACN 0.12
FACILE 1.00
IMCLNet 0.77
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba Malware:Win32/Dorpal.ali1000029 20190527 0.3.0.5
Avast Win32:Malware-gen 20200830 18.4.3895.0
Baidu Win32.Worm.Mira.c 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (W) 20190702 1.0
Kingsoft None 20200830 2013.8.14.323
McAfee W32/Worm-GAT!E0A58B12052F 20200830 6.0.6.653
Tencent Worm.Win32.Mira.a 20200830 1.0.0.1
静态指标
行为判定
动态指标
该二进制文件可能包含加密或压缩数据,表明使用了打包工具 (1 个事件)
section {'name': '.rsrc', 'virtual_address': '0x00047000', 'virtual_size': '0x0001a000', 'size_of_data': '0x00006800', 'entropy': 6.883769772478795} entropy 6.883769772478795 description 发现高熵的节
网络通信
与未执行 DNS 查询的主机进行通信 (1 个事件)
host 114.114.114.114
文件已被 VirusTotal 上 61 个反病毒引擎识别为恶意 (50 out of 61 个事件)
ALYac Trojan.Agent.CCPK
APEX Malicious
AVG Win32:Malware-gen
Acronis suspicious
Ad-Aware Trojan.Agent.CCPK
AhnLab-V3 Trojan/Win32.Fakon.R138362
Alibaba Malware:Win32/Dorpal.ali1000029
Antiy-AVL Trojan/Win32.Agent.icgh
Arcabit Trojan.Agent.CCPK
Avast Win32:Malware-gen
Avira TR/Zusy.BQ
Baidu Win32.Worm.Mira.c
BitDefender Trojan.Agent.CCPK
BitDefenderTheta Gen:NN.ZexaF.34196.LyZ@a0Sdyzci
Bkav W32.FamVT.MiraVM.Worm
CAT-QuickHeal Trojan.Beaugrit.A6
ClamAV Win.Trojan.Agent-1388690
Comodo Worm.Win32.Mira.AA@59ticr
CrowdStrike win/malicious_confidence_100% (W)
Cylance Unsafe
Cynet Malicious (score: 100)
Cyren W32/Trojan.YVBK-2015
DrWeb Win32.HLLO.Siggen.5
ESET-NOD32 Win32/Mira.A
Elastic malicious (high confidence)
F-Secure Trojan.TR/Zusy.BQ
FireEye Generic.mg.e0a58b12052fd875
Fortinet W32/Mira.9C5!tr
GData Win32.Worm.Mira.D
Ikarus Trojan.Win32.Heur
Invincea heuristic
Jiangmin Trojan/Agent.iezf
K7AntiVirus Trojan ( 0056560b1 )
K7GW Trojan ( 004993691 )
Kaspersky Trojan.Win32.Agent.icgh
Lionic Trojan.Win32.Agent.lY1Q
MAX malware (ai score=88)
Malwarebytes Worm.Mira
MaxSecure Trojan.Agent.icgh
McAfee W32/Worm-GAT!E0A58B12052F
MicroWorld-eScan Trojan.Agent.CCPK
Microsoft Worm:Win32/Mira!rfn
NANO-Antivirus Trojan.Win32.Zusy.ethqlz
Paloalto generic.ml
Panda W32/Milam.A.worm
Qihoo-360 Worm.Win32.Mira.A
Rising Worm.Mira!1.A270 (CLASSIC)
Sangfor Malware
SentinelOne DFI - Malicious PE
Sophos W32/Mira-B
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2014-02-27 14:41:59

PE Imphash

dbf687d6aa2a6cafe4349f7b0821a792

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003be78 0x0003c000 6.080451775497244
.data 0x0003d000 0x00000260 0x00000400 0.705049269986258
.rdata 0x0003e000 0x000024a8 0x00002600 5.008530245268908
.bss 0x00041000 0x00004890 0x00000000 0.0
.idata 0x00046000 0x000008a4 0x00000a00 4.294939157790109
.rsrc 0x00047000 0x0001a000 0x00006800 6.883769772478795

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0004cfec 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_ICON 0x0004cfec 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_ICON 0x0004cfec 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_ICON 0x0004cfec 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_ICON 0x0004cfec 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_ICON 0x0004cfec 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_ICON 0x0004cfec 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_ICON 0x0004cfec 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_ICON 0x0004cfec 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_GROUP_ICON 0x0004d454 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_VERSION 0x0004d4d8 0x000002e0 LANG_ENGLISH SUBLANG_ENGLISH_US None

Imports

Library KERNEL32.dll:
0x4461b8 AddAtomA
0x4461bc CreateDirectoryA
0x4461c0 CreateProcessA
0x4461c4 CreateSemaphoreA
0x4461c8 DeleteFileA
0x4461cc ExitProcess
0x4461d0 FindAtomA
0x4461d4 GetAtomNameA
0x4461d8 GetCommandLineA
0x4461dc GetLastError
0x4461e0 GetModuleFileNameA
0x4461e4 GetModuleHandleA
0x4461e8 GetStartupInfoA
0x4461f4 ReleaseSemaphore
0x4461f8 SetFileAttributesA
0x4461fc SetLastError
0x446204 Sleep
0x446208 TlsAlloc
0x44620c TlsFree
0x446210 TlsGetValue
0x446214 TlsSetValue
0x446218 WaitForSingleObject
Library msvcrt.dll:
0x446224 _fdopen
0x446228 _read
0x44622c _strdup
0x446230 _write
Library msvcrt.dll:
0x44623c __getmainargs
0x446240 __mb_cur_max
0x446244 __p__environ
0x446248 __p__fmode
0x44624c __set_app_type
0x446250 _assert
0x446254 _cexit
0x446258 _ctype
0x44625c _errno
0x446260 _fstati64
0x446264 _iob
0x446268 _isctype
0x44626c _lseeki64
0x446270 _onexit
0x446274 _pctype
0x446278 _setmode
0x44627c _strnicmp
0x446280 _vsnprintf
0x446284 abort
0x446288 atexit
0x44628c fclose
0x446290 fflush
0x446294 fopen
0x446298 fprintf
0x44629c free
0x4462a0 localeconv
0x4462a4 malloc
0x4462a8 memchr
0x4462ac memcpy
0x4462b0 memmove
0x4462b4 memset
0x4462b8 rand
0x4462bc setlocale
0x4462c0 setvbuf
0x4462c4 signal
0x4462c8 srand
0x4462cc strcat
0x4462d0 strcmp
0x4462d4 strcoll
0x4462d8 strcpy
0x4462dc strftime
0x4462e0 strlen
0x4462e4 strtod
0x4462e8 strxfrm
0x4462ec time
Library SHELL32.DLL:
0x4462f8 SHGetFolderPathA
0x4462fc ShellExecuteA

L!This program cannot be run in DOS mode.
.rdata
.idata
E;Es9}
<t6p t<~@tO
x7EZ[^_]
UW1V1S
eEEE$@
++CCUNG
pP EtB(dB$
R \tp@$
hUhU`hu
llU6hU(Et
E!t#XtEXM~t
$]u}E$@
UpPl1|pl
;u ]]$}}
4$Yt8M
]1u}];] tIF
UWVS|U$E
E|[^_]
1|[^_]
UWVSL}
$DtbEN
UEXEE]u}E
++C B4CUNGB
t-S4C0
UEhEE]u}E
E]u}]E
UEhEE]u}E
tB1u2=C
UEXEE]u}E
80S4C0
t(S4C0
x9JtD|IS
]uEEEE
]uEEEE
]uEEEE
UUWVSLE
$UE@M@
$IMEQh$9t
$YMEQh$9t
$iMEQh$9t
]u}EEUE
Pht%$9t
UE]PhXdE
$]u}E$@
|u9EEP@
$]u}E$@
tuHxEE
$]u}E$@
tuHxEE
$]u}E$@
tuHxEE
$]u}E$@
tuHxEE
$]u}E$@
tuHxEE
$]u}E$@
tuHxEE
$]u}E$@
tuHxEE
$]u}E$@
tuHxEE
$]u}E$@
tuHxEE
UUWVS\E
EuSEUE9B
Et1@t@
UEXEE]
Et1@t@
UUWVS\E
EEUEn@
EuSEUE9B
UMWVSlE
UMWVSlE
UUWVS|E
@;Er]E[
@;ErEU]H
]xEEEt
$u}E$@
oUUWVSlUE
UUWVSlUE
9t1]u}]
[^_]UU
[^_]UXeE
$B4$Z]u]U
UEXEE]u}E
Eu!PRD
u9Et4+_
9}]t7q^
8"t-EE
$u}E$@
$u}E$@
$u}E$@
]uEEEE
]uEEEE
$u}E$@
$u}E$@
$u}E$@
]uEEEE
]uEEEE
$u}E$@
$u}E$@
$u}E$@
]uEEEE
]uEEEE
]uEEEE
]uEEEE
]uEEEE
]uEEEE
]uEEEE
]uEEEE
]uEEEE
]uEEEE
]uEEEE
e[^_]EAAAA
uEAAAAEAAAAE
EAAAAEAAAAE
EAAAAEAAAAE
EAAAAE
S C0C,
t(C,1D$
S0x]u]
t3[4u$&
t$B0x=B0uVB(
z(]u}]
H0x4P0uMX(]
[^_]o2
UWVS,PXD
]t"x0xFp0u X(EP J
UWVS,@
tLEtt$
tEp0x^X0uw@(UEEE
]tAH0xFP0u
X(EP J
X(EP J
H0us@(EUE
x0uaX(EP J
<$&]u}]
taH0xkP0uu@(
e[^_]PXD
H0yAPXD
EUM]Uu
M9MvuMEU]Eu}U]
EuaE9E
UEEEU]u}]
Mu,9vZ
1E]E}Uu]
W11V1S
tplhl$
D$'\ t&
ME1UfE
:|,1\$ \$0
t$$t$4|$(|$
\$ t$$|$(,
D$,L$(D$
T$$D$ L$
T$DfD$B
\$0fD$0
|T f|T`B
UWVS|$
t$@\$@L$B
;f9yD$
|[^_]fD$
\$ fD$
~t$`1L$@
tfxJ\$
[^_]uUt$
~ML$$t$$
~;D$$p
~PL$$q
[^_]Ov
1D[^_]
|$lOD$
~D[^_]
D[^_]fD$&
tH1|$(M
Ky\$\u=L$
|$\T$`
UWVSd\$xl$|
2L$:zQ
1d[^_]
1D$8L$
HyfD$8xfD$
UWVSLt$`l$d
:L$"ZQ
L[^_]1
HyT$ \$
LS[^_]
Iy%LbD
t,K9w4
0^t&K9w.
B9w[][]
;Ew,t&
Bt$H9v
9pr(t$
EZ;]]r
u39~rdF]
E9]EEr
9rrTB]
u)]u}]
9rrdB]
E@E9]EEr
9prw;M
DF;gUS
$]u}E$@
$]u}E$@
$]u}E$@
$]u}E$@
$]u}E$@
$]u}E$@
$]u}E$@
$]u}E$@
t>BtmEM
$rE]u}]
$UEP&A
]UUWVS
T$E|UD$
D$|UD$
eOEElD$
$SEJEEE
$@$EVE
rUMWVS
$EJEEE
$@$EFE
pUMWVS
$EJEEE
$@$EVE
rUMWVS
e|EElD$
$EJEEE
$@$ECE
nUMWVS,
enEElD$
11dE1X
'x $t&
cUMWVS,
e_EElD$
dE1X1\
$9\rpw
eUMWVS
$@$Eek
]EUu}]
UWVS<U
EMu`EED$
]UU EEE
$Uu}E$@
$:EUEEU
$8EU]u}]
UU EEE
$U]uE$@
$?7EU]u}]
]UU EEE
$Uu}E$@
$EU/EEU
$5EU]u}]
$;U(E$U
uM }u$}
UWVSLE
EUe[^_]
7UWVSLU
EUe[^_]
DUWVSLE
0P&M U
EUe[^_]
>UWVSLU
U N 1%D$
EUe[^_]
E$]U u]
E <$D$
@1vE D$
a0L$/4
@-6m D$
]U M$}>D$
W ]u}]
(]] uu
$WEEUs
AE]EUu}E
$YotuH
$]u}E$@
$;"UExE
$]u}E$@
$!UExE
$]u}E$@
UWVS<E
1t+u+t
$P$WUWVS<E
1t+u+t
<[^_]#
$P$WUW1VS
$P$US$M
E0EE,l
;E |qgfff
M(9Mt\EU
$P$UWVS|E
U ElUE
EET$$U
1t+u+t
|[^_]S<1u
Bu+E1E
UWVS,E,EE(l
C;]$s!U
CG;]$r
$X?E(UM
$<?E9Ur
U2Cu9rE
e[^_]E
<$MEMP
EET$$U
BdEBhEBlEBpE
1t6u6t
9u{tEC
,A<8w4
D$ E$T$$
D$ ,T$$U
|,U$HB
T$ 4E$
BHEBLEBPEBTE
E$T$(L$$D$
Bd8Bh<Bl@BpDBtHBxLB|P
B,EB0EB4EB8EB<EB@EBDE5
FJ8tJU
$%\$ ~
c%\$ (
$P$US$M
UWVS<E
$3;]$tb
tO%tv}
C;]$uE
%uC;]$tE
u!C;]$tM
R4UVS ]
^]kTU(
UMWVS|
MU E$@
e?E]l]
hxUxBl@
||8\A
\|@@B4E1<<
$E,|B
80tp@U
)UMWVS|
MU E$@
rxUxBl@
||8\A
\|@@B4E1<<
80tp@U
D$ E$T$
D$ E$T$
U M$$@
|htL$/p
x|e[^_]
$hp)dL$
UU EE$U
U8uE u
]U$M(}>D$
4$L$ D$
U t,t$
]u}]UWVS
$nXlD$
HlL$+@Ep1D$
@L$+<P0
T$+@Bl
kUWVS<
eE|lp<$yl
Od|dBl@
0L$'D,
0C,<$D$
EUEEUE
&{TPLB
ChtB4E
J$Z(@@<
X<$BuEX
$xUWVS<
eE|lp<$ll
Bd|dBl@
0L$'D,
0C,<$D$
EUEEUE
&nTPLB
ChtB4E
J$Z(@@<
X<$BuEX
$xUUWVS\E
$>\[^_]
UMWVSLE
$yL[^_]
U]Mu}EU
U]Mu}EU
$R]u}]
uEE}UM
UMWVSlE
t ]u$E
El[^_]
$bEl[^_]
]MEEUEIB
$E|[^_]
E|[^_]
EEUu}E
t&]u*E
EEU]}E
t&}u*E
$4E]u}]
$E]u}]
UU]EEu}E
E@t']u+E
$2E]u}]
EEU]}E
$nE]u}]E
EEUu}E$@
$D~E]u}]
UU]EEu}E$@
$B}E]u}]
$m|E]u}]
$]}E$@
EEUu}E
B@t2]u6t&
$yE]u}]
$yE]u}]
UMWVSlE
$wEl[^_]
$s.UWVS
UMWVS|E
$NrE|[^_]
rE|[^_]
}EEEEUE
@@t.}u2&
pE]u}]
$oE]u}]
$%nE\[^_]
$mE\[^_]
$rl]u}]
$$k]u}]
U}1EEU]uE
iE]u}]
$hE]u}]
UUWVS|E
$8gE|[^_]
$fE|[^_]
UUWVS|E
$heE|[^_]
$dE|[^_]
KUUWVS|E
$cE|[^_]
$"cE|[^_]
{UUWV1S|E
$aE|[^_]
$RaE|[^_]
UUWV1S|E
$_E|[^_]
$_E|[^_]
UUWV1S
UUWVS|E
$(\E|[^_]
$[E|[^_]
UUWV1S|E
$XZE|[^_]
$YE|[^_]
;UUWVS|E
$XE|[^_]
XE|[^_]
kUUWV1S
mUUWVS|E
$TE|[^_]
$BTE|[^_]
UUWV1S|E
$RE|[^_]
$rRE|[^_]
UUWVS|E
QE|[^_]
$PE|[^_]
UWVS|E
e1OEUE
$OE|[^_]
U]UEEu}E
$ME]u}]
ME]u}]E
EEUu}E$@
$NLE]u}]
$dKE]u}]
UU]EEu}E$@
$bJE]u}]
$IE]u}]
$]}E$@
$u}E$@
$8GE]u}]
$B]u}]
$kA]u}]
e5?EED$
}U|BtBu
#UUWVS|E
$<E|[^_]
6PxBtBu
]M|BtBu
eE4EED$
J|BtBu
e0E|D$
EpBtBu
eE-EED$
C|BtBu
]UUWVS
e"*E|E
3UUWVS
eu&EED$
<|BtBu
@))9rZt$
]]UXeE
]uEEEE}E
E]u}]E
$E+vUE
UU]EEu}E
UEWVSlE
El[^_]=
\dE|EiC
4$)1D$
9PrWp1|$
9BraR1_U\$
$K]u}]
9JrfzU
X?)9rY|$
9s3Bt$
)9snu~B
$u}E$@
UuL C
UjU(]E
u0F)9w
EJ?))9rRt$
8D]u}]
?J)9r[|$
?]9EUUrwU
X9s?))9rtt$
]u}]9st$
]]U(uU
<$E)(>U
UEEMEB
$I:EEE
$69E\E
A?));U
$u}E$@
$aUUWVS|E
$|[^_]
EE]u}E$@
$@]u}]
$u}E$@
9BUr~Uu
EHjU(}}
EE]u}E$@
$0]u}]
$u}E$@
9BUr~Uu
E8jU(}}
$]u}E$@
$]u}]E
$]u}E$@
$J]u}]E
}~UXeE
$cUXeE
U]uEEU
$@]u}]
$#UXeE
$cUXeE
$A]u}]
$~]u}]
$#UXeE
$cUXeE
U]uEEU
$>]u}]
$#UXeE
$bUheE
$sUXeE
$L]u}]
$c]u}]
$AUXeE
$(XUXeE
$(hUXeE
tD~@Q@
c_UWVS<E
7E|$/M
$UE19u
C@uaC@
C\u'C\
$#uOEE
$E]u}]
P0P@@J
@4A8A<u
$4UB@BI
;EE0AtM
$E.UMWVS
tlUEPXE
$e[^_]
$E,E3WqMEAX
$e[^_]
EpXX\
CdpueUpB\B
B4B8B<E
U]uEE}E
$E]u}]
${E]u}]
$EL*U(uu
EE]u}]
]9ttuF
U;:|CF
;9t19~!)tQC|$
P1SBF0
ChCdC@C
YLQ@9A
ALIPCT
$E>$BX
U9EXXPd
#t{]{T
$P$t:E
U]uEE}E
$:tfEU]@
$PE]CX
$E]u}]
E:IaUX}}
]u}]GT
_h1Wd)9]
G<~?O\U)
u6whO\U
F?E)\$
GhMW\)9EEr
GdeEGX
$\gGd\$
$AUUWVS\E
$\[^_]
UUWVS\E
$u\[^_]
]uEEEE
$R]u}]
]uEEEE
$1UXeE
]uEEEE
UUWVSlUE
e6EMxM
EUxBx8
UUWVS\UE
EUxBx8
hUMWVSlME
M6UMWVS\E
eR]UMC
EMUE]A
qUUWVS\E
EUxBx8
_UUWVS\E
EUxBx8
_UMWVS\E
EMUE]A
$4\[^_]
$RE]u}]
UUW1VS\E
$$UEMBt
$\[^_]
$OUUWV1S\UE
eDEMtM
$"UEMBt
$t\[^_]
UMWVS\E
$\[^_]
$yUMWVS\E
$YUXeE
EUtBt8
$1UXeE
EUtBt8
$RE]u}]
UUW1VS\E
$\[^_]
$WUUW1VS\E
eVEMpM
$UMWVS\E
$%\[^_]
UMWVS\E
EUpBp8
EUpBp8
$xUXeE
$"]u}]
$8p1D$
$"]u}]
$8o1D$
"EUE1}
*UqUheE
$.]u}]
$(UqUheE
]uEEEE
]uEEEE
$']u}]
]uEEEE
$g]u}]
]EEEEU
$]EUD$
$]YUheE
REUE1}
$:\EUD$
$m\YUS
[[]}OU
pl&$hd
$|e[^_]
$X)TL$
Nld)hL$
UUWVS\E
esEUE1}
t\[^_]
$K1UD$
$KZUUWVS\E
eXrEUE1}
$r\[^_]
$nJZUS
X[]}=U
UUWVS\E
epEUE1}
q\[^_]
HE1Ut$
$HZUUWVS\E
eHoEUE1}
$o\[^_]
1G1UD$
$^GZUS
X[]m:U
$'utJ$
p`1(@=
ie[^_]
$rld)hL$
$gktJ$
p`1(@=
$T_e[^_]
$hld)hL$
$69cU1
X[]}&U
Y[]-&U
$U]u}]
$`[UXeE
$ZUXeE
$ZT]u}]
$S]u}]
$SYUXeE
]uEEEE
$R]u}]
$XUXeE
]uEEEE
$:R]u}]
$WUXeE
]uEEEE
$Q]u}]
$O]u}]
$#UUXeE
$N]u}]
$sTUXeE
$ N]u}]
$SUXeE
$pM]u}]
]uEEEE
$L]u}]
$SRUXeE
]uEEEE
$K]u}]
$QUXeE
]uEEEE
$JK]u}]
$PUXeE
$J]u}]
$=PUXeE
$I]u}]
${OUXeE
$NUXeE
$WH]u}]
$MUXeE
$G]u}]
$;MUXeE
$F]u}]
UMWVS\E
$WC\[^_]
CtSt]u]
?XCtCu
CtSt]u]
$u}E$@
$&EUD$
E@xEtP
UWVSLE
$wllD$
$TCtCu
].UXeE
$~E1@t
$F=]u}]
u1EEEE}1
^H[^_]E
[H^_]E
-UWVS(E
C9u([^_]
4$ [^]
UUWVS|E
$2E|[^_]
$d2E|[^_]
UEXEE]u}E
$-1E]u}]
UEXEE]u}E
$m0E]u}]
UEXEE]u}E
$/E]u}]
$E]5t&
$EYUEXEE]u}E
$.E]u}]
UEXEE]u}E
$-.E]u}]
UEXEE]u}E
$m-E]u}]
UEXEE]u}E
$,E]u}]
$E]2t&
$EYUEXEE]u}E
$+E]u}]
UEXEE]u}E
$-+E]u}]
UEXEE]u}E
$m*E]u}]
UEXEE]u}E
$)E]u}]
$E]/t&
$EYUEXEE]u}E
$(E]u}]
UEXEE]u}E
$-(E]u}]
e}#EME
$MAX9EE~wE
k-MT$+Uyu
#Ee[^_]
8UBtBu
$e7 EME
.*MT$+Uyu
6UBtBu
$Ee[^_]=uE
$]uE$@
$E."EU
$]u}E$@
$E*!EU
$u}E$@
||EH;E
En}t uu$E
UM4$L$
UU]EEu}E
\Mira.h
Saaaalamm
basic_filebuf::xsgetn error reading the file
basic_filebuf::_M_convert_to_external conversion error
basic_filebuf::underflow codecvt::max_length() is not valid
basic_filebuf::underflow incomplete character in file
basic_filebuf::underflow error reading the file
basic_filebuf::underflow invalid byte sequence in file
basic_ios::clear
basic_string::at
basic_string::copy
basic_string::compare
basic_string::_S_create
basic_string::reserve
basic_string::erase
basic_string::assign
basic_string::append
basic_string::_M_replace_aux
basic_string::replace
basic_string::insert
basic_string::resize
basic_string::_S_construct NULL not valid
basic_string::basic_string
basic_string::substr
ios_base::_M_grow_words is not valid
ios_base::_M_grow_words allocation failed
locale::_S_normalize_category category not found
locale::_Impl::_M_replace_facet
basic_string::_M_replace_aux
%H:%M:%S
%m/%d/%y
basic_string::_M_replace_aux
basic_string::erase
pure virtual method called
LC_CTYPE
LC_NUMERIC
LC_TIME
LC_COLLATE
LC_MONETARY
LC_MESSAGES
locale::facet::_S_create_c_locale name not valid
-+xX0123456789abcdef0123456789ABCDEF
-+xX0123456789abcdefABCDEF
-0123456789
%m/%d/%y
August
September
October
November
December
%H:%M:%S
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
c:/mnt/samo/mingw/msys/mthr_stub.c
-LIBGCCW32-EH-2-SJLJ-GTHR-MINGW32
w32_sharedptr->size == sizeof(W32_EH_SHARED)
%s:%u: failed assertion `%s'
../../gcc/gcc/config/i386/w32-shared-ptr.c
GetAtomNameA (atom, s, sizeof(s)) != 0
R`%uM]=];Z
uuvHMe
Ix@ p+
N10__cxxabiv117__class_type_infoE
N10__cxxabiv120__si_class_type_infoE
N10__cxxabiv121__vmi_class_type_infoE
NSt6locale5facetE
NSt8ios_base7failureE
St10bad_typeid
St10ctype_base
St10money_base
St10moneypunctIcLb0EE
St10moneypunctIcLb1EE
St11__timepunctIcE
St11logic_error
St11range_error
St12codecvt_base
St12ctype_bynameIcE
St12domain_error
St12length_error
St12out_of_range
St13bad_exception
St13basic_filebufIcSt11char_traitsIcEE
St13basic_fstreamIcSt11char_traitsIcEE
St13messages_base
St13runtime_error
St14basic_ifstreamIcSt11char_traitsIcEE
St14basic_ofstreamIcSt11char_traitsIcEE
St14codecvt_bynameIcciE
St14collate_bynameIcE
St14overflow_error
St15basic_streambufIcSt11char_traitsIcEE
St15messages_bynameIcE
St15numpunct_bynameIcE
St15time_get_bynameIcSt19istreambuf_iteratorIcSt11char_traitsIcEEE
St15time_put_bynameIcSt19ostreambuf_iteratorIcSt11char_traitsIcEEE
St15underflow_error
St16__numpunct_cacheIcE
St16invalid_argument
St17__timepunct_cacheIcE
St17moneypunct_bynameIcLb0EE
St17moneypunct_bynameIcLb1EE
St18__moneypunct_cacheIcLb0EE
St18__moneypunct_cacheIcLb1EE
St21__ctype_abstract_baseIcE
St23__codecvt_abstract_baseIcciE
St5ctypeIcE
St7codecvtIcciE
St7collateIcE
St7num_getIcSt19istreambuf_iteratorIcSt11char_traitsIcEEE
St7num_putIcSt19ostreambuf_iteratorIcSt11char_traitsIcEEE
St8bad_cast
St8ios_base
St8messagesIcE
St8numpunctIcE
St8time_getIcSt19istreambuf_iteratorIcSt11char_traitsIcEEE
St8time_putIcSt19ostreambuf_iteratorIcSt11char_traitsIcEEE
St9bad_alloc
St9basic_iosIcSt11char_traitsIcEE
St9exception
St9money_getIcSt19istreambuf_iteratorIcSt11char_traitsIcEEE
St9money_putIcSt19ostreambuf_iteratorIcSt11char_traitsIcEEE
St9time_base
St9type_info
AddAtomA
CreateDirectoryA
CreateProcessA
CreateSemaphoreA
DeleteFileA
ExitProcess
FindAtomA
GetAtomNameA
GetCommandLineA
GetLastError
GetModuleFileNameA
GetModuleHandleA
GetStartupInfoA
InterlockedDecrement
InterlockedIncrement
ReleaseSemaphore
SetFileAttributesA
SetLastError
SetUnhandledExceptionFilter
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
WaitForSingleObject
_fdopen
_strdup
_write
__getmainargs
__mb_cur_max
__p__environ
__p__fmode
__set_app_type
_assert
_cexit
_ctype
_errno
_fstati64
_isctype
_lseeki64
_onexit
_pctype
_setmode
_strnicmp
_vsnprintf
atexit
fclose
fflush
fprintf
localeconv
malloc
memchr
memcpy
memmove
memset
setlocale
setvbuf
signal
strcat
strcmp
strcoll
strcpy
strftime
strlen
strtod
strxfrm
SHGetFolderPathA
ShellExecuteA
KERNEL32.dll
msvcrt.dll
msvcrt.dll
SHELL32.DLL
NaHaJa:
wyjvlZ
uZ'~'lh
N{dW+B
>x@:UL2
>vL2OD
L*V;W:
FW+BK:W+>~J:W+;"W
-:?~J:
9G&::8
9v(.H%
:v-&UK^,}
^x0:UK^.}
^x?<UK^
O6>v`P
#0S{QH
@}UL9G:
J<:JCR
J<:JCR,
ULpG:W
:x!:UL
^x :vdP:
s&\Bx`
J<:JCQ
^K:x:WF
hn*zUL
hn*zUL
9a['~/g
&Q>'~UL
:x:yU\
{_3g~Hy
PD`nJ:YQ
^hnJ:W;
J<:JCQ
s&v\6zW#IFN
PG:xp:
PG:x`:
hn*zUL
+F~|UL
L`:hK:
JFvP9L
pG:xp:
LW:hK:
JFv`8L
pG:Ws\
JFvp7L
kYyF}
2Lw8NvD
ULpG:W
ULpG:W
^xPg<wE9
ULpG:W
^xf<wE9
ULpG:W
F~NvP
ULpG:W
^xpb<wE9
ULpG:W
^xa<wE9
ULpG:W
^x0_<wE9
F~Nvp
ULpG:W
^x^<wE9
ULpG:W
^x\<wE9
F~Nv0
ULpG:W
^xPZ<wE9
hn*zUL
hn*zUL
xZJ:WL
:v$wO
hn*zUL
hn*zUL
hn*zUL
:v|qOI
:x3:UL
hn*zUL
:GuBy-
P>vhOI
Svvd9=
ULpG:W
J:x9UL
,n*zULh[J:W
=-6%bR
^x@<wv9
pG:K^l~UL
:UH>`K:W
~Fv.>j~F
J>v`.?
HK:N803Jh~kk1
83rh~F
:ODK:`Z
K:N~8V
Ph~w`K:
K:N803i~K:
K:Hi~17
^xT9UL
~`K:N8
3fg~kb1
h~K:NwK:
OK:3h~K:N893h~k1{
:GK:I^g~1
"h~>i~UL
:Ji~F
^xX9UL
T3i~FON
^x 9UL
>v`(>fi~
^pJ:x<9
^K:{w>j~y
|~>m~v<1>m~F7
K:3&g~F7
s&v9K:S
G:x O:
:{eFUL
:{eFUL
pG:K^l~UL
:UH>`K:W
Fv ">j~G
83jh~>h~
:WLK:K
@K:3nh~28
Ph~wtK:V
3i~kb1?
83i~K:N~
i~OK:VZ
pK:3j~F
K:3fg~k1
kPtK:N"
^g~K:NwK:oK:WK:iGK:WOK:`z
3h~K:N
:OK:`~
xK:Hvi~
K:W+Jr
^pJ:x9
N>v|xeQ
^xK:UL
^K:{n>j~y
ULpG:W
{>.g~v
^0K:xL:W
H}QdkPQdJ:SR
H}QdJ:S]
^x$w:y
l}Vv@90
+kkv7>G
+>xlv:UL
hn*zUL
\J:W,
9vt>UL
:}?oJ:
}?hoJ:
R}?XoJ:
v}O|oJ:
^}OdoJ:
^@K:x9
YQ1&y~
^x,r:TW
^x|q:TW
^xq:TW
00G:x5:
1G:x4:
2G:x3:
:0K:I^zHk<
:x$k:U
^x,k:gd*
C^xlj:
+>x`i:
Ln*zUL`J:W6:
^xp2:UL
Ln*zUL
`J:W+;
f~NvxE
Ln*zUL
`J:W+<
f~NvxD
P;G:x`):
<G:x):
Ln*zUL4`J:W
^x-:UL
Ln*zULD`J:W
Ln*zULT`J:W
">v${LW
AG:x$:
AG:x0#:
Ln*zULp`J:W
Ln*zUL`J:W
Ln*zULaJ:W
^x<$:UL
^xl#:UL
hW}TGL
:v$zzz
hW}TGL
:v`#zzz
:V+hWz>
wUJNAJ:W+
}v}bSU
9TG^TG_UG>
pPG:xP
SP'>y
}UG^%J:W/
}UGn6J:W?
}UG~XJ:WO
}UGmJ:W_
}UG}J:Wo/
}UGJ:W
w:JIF3
^YG:x8M9bS
^YG:xM9bS
l.fSULH{1
4H{ULH{
OK:E|9
sZ|WPK:O
PK:{`z
91Nm~w!9
f&wk9z
91Nm~wS9v
f&we9
I$N0"C`6
`Q9y~W
#^x,7:
#^x|7:
vdaCV`
P|*!C`6
L*DT"ct
r$DT"cq
P|&!C`6
^x0:vb
:<Nv<b
>3<nv0b
+Zx.:U
|80xh,:U
^xt,:H
+Nxl+:U
:ex+:U
WkP89
g9JIFw
+>xT*:
kPy";b6
:v=+NQ`<
[^LG:8
|~~~>v VQ
Q<:<EH8:
{dUI<>
yMEI?[(^m
IGDCSOB
:~eQV#C
T>N!^M
:WL:G-
RKdUK^
+tE[^9EIGh
=H%E|D
K^HW:Fv1ms
?I%PmIFh
kPw37=
:UH4bQ
S;H%ETD
'9w8#EtD
vw%9+E}D
9RPw7
9eQyzeQ
zd>G}v$~
ep-6%bR
O I'P/L
vnQI"N
L&feQ>"}vzu
>v|z`hd
>YbYQ
>Y^YQ
Ln*zUL_J:W
Ln*zUL_J:WZ
Ln*zUL_J:W
Ln*zUL_J:W
>YbYQ
>Y^YQ
Ln*zUL_J:W
Ln*zUL^J:Wz
Ln*zUL^J:W:
Ln*zUL^J:W
^pJ:W9
zLTG_UG>
:Fv@;
hn*zUL
ULpG:W
^x|;UL
*x 9UL
:x69UL
:x,9UL
:Qwg5<
9`w#8<
9Qwy6
^xP;UL
#W9NvT
9`w98<
:Qwg5<
9`w#8<
9Qwy6
+>xhy;
:GI$P8
9`wM1<
9`w[-<
^xpu;UL
#K9Nvt
:GI$P8
9`w#,<
9`w+3<
9`wu,<
>GI$N8
:GI$N8
LIN+sR
}zMW+N
^xPV;UL
:Qw 2<
+>x8J;
:GI$P8
^/RwT8
Ln*zUL/_J:W~.
Ln*zUL5_J:W
^x|9W
pQ0T{i
K^vExwy9
|~j{!
#8>v0<
uTJVwU8|
9xt8kLZ
^xc9w#7
^I=:~!
~vvh+X
uTJVwU8|
9x48itZ
^x|^9w#7
Ln*zUL}^J:W
Ln*zULw^J:W*J
Ln*zULq^J:WK
:LZUL"
:w8L"W
#^/Rwj9<
^/Qw8<
B~-F>vDs
NIF?IFg
#NIFAIFg
^x9w]6
IF#fC;
:~LDKP
@I}H1
:~LDKP
:~LDKP
@J}G.1
NW^yh9
:GI$N8
:~LDKP
;^INN
:~LDKP
;^INN
c^w0VF
NW^yA9
INO~vYZ
:~LDKP
IF{TbINNd
:~LDKM
LINNeSvT
:x8TGKTGLUGj
:GI$N8
GBQv&P
:xp8UL
:x@o8UL
:GI$N8
c9OoJ:V
:xg8UL
^x08UL
9`w(+<
9`w^1<
:Qw12<
9`wR'<
@Z}UL0I:
:xL8TGKTGLUGj
:GI$N8
GBQv&P
:x<X8UL
:xX8UL
9xX:UL
:GI$N8
c9OoJ:V
:xP8UL
9`w(+<
9`w^1<
:Qw12<
9`wR'<
N%p~&J
9xp:UL
9>ULI:
Kw9vv(
:vlzzz
+S9>UL
+%r|,W
:x18UL
}zMW+N
K8Vw>2
:xX.8UL
9>ULI:
Kw9vv(
:vlzzz
c9>vPo
+S9>UL
+%r|,W
:x$8UL
}zMW+N
K8Vw>2
:xX!8UL
~UHF,K:
:UHFHK:
8TJkbUMFHK:
hn*zUL
d.DTJW
9vCO{tW
9x7w49
ULpG:W
O.X|{c
@N}ULI:
<n*zUL
w.||KW9
9xH7wJ9
hn*zUL
v>vx@G
yu2|T
O.X||KW9
JUIBHK:
#^x7UJ
:`8V{:V|:W
:UJBHK:
hn*zUL
9x7wB9
.||KW9
:x7w8$
9x7w'9
:x|7w8L
^xN8UL
9x7w89
ULpG:W
O.X|{c
<n*zULUJ:W
I:xH8UL
f>v;h|e
&wp=Fv(1={J
&w<Fv0={J
"I:x,C8UL
JUI>HK:
:`8V{:V|:W
pG:WhW
~UG>HK:
'2>vLs
TULpG:
2>UL@UJ:W
O.X||W
y.~z|W
'2>v,k
+>xD:ws9
'2>vLh
+>x4:y
+>xd:ws9
GF8|>8{G
y.~z|W
+>xH:wm9
'2>v\a
+>xD:y
+>xt:ws9
x +8UL
+>xt:y
+>x:ws9
+>x0^8
I6Qv&P
[^vX:Q
4ULpG:W
zdVv\0=
}ULJI:
+>xh :W
[^vTS=W
w.N~Vv
#^xLO8
<n*zULYJ:W
f~Nv -n
+BVv`K9
+FN~vv
+FN~vvPI8
w99>}vx
&Q>}vD
L*W>vE8
^J:x@7
L*W>v E8
+BLL)aV
N{<Qd#cs
+BY~Nv<
K^vlu*
z:ULpG:
+Bf~Nv
#^xt?8
^x >8w.99
K^vLo2
TULpG:
2>ULYJ:W^h
^x\98yU
,n*zUL
<n*zULYJ:W
,n*zUL
<n*zUL
Ln*zULYJ:W@r
Ln*zULYJ:Wr
:>vL.
#^x$.8
#^x,-8
&Q>}v
sI:x 7
`sI:x`7
tI:x7
vI:x 7
`vI:x`7
I>W8WOG
wI:x7
yI:x 7
I>W8WG
`yI:x`7
zI:x7
|I:x 7
}I:x`7
R}I:xp7
;^;z#0h
9x(_7wv8>}v
N|aWc:
PI:x`7UL
^xK7TLUL
J|TITI
9TLwR9
d.D]W:
]FVP:y
MBD]W;
9xT7w795
:TMw8>}v
>v|>wf9
(cjw{9
MRVQ;{+
VP:VQ:
4ULPSJ:Wr
dB^2\NW
S@{D;h
,w8>UL
JBDLFVP;
9Vwx9wa9
pG:WFV
9x 7UL
9x8J7wh9
F9>}v{w29s
^xP7w8
^J:xG7w<68
J:8K:W':
N>v,eQ
J:8K:W':
P>vLUIj
FFvPJ
K^v<d
hn*zUL
0SJ:Wz
l"x47UL
LTIUGHK:
l"x7UL
LTIUGHK:1
~UHBK:W
^x 7UL
P>v$3^
:{wx9
hn*zUL
~UHK:W
hn*zUL
~UHK:W
hn*zUL
l"x7UL
TV{:W{
:x9/kE
:UHHK:
:xl9/kE
:UHHK:
hn*zUL
l"x7UL
l"xT7UL
:x9/{E
:x9/{E
>v,Wby
^x#7W
^xd#7W
+Bx7w7
:TGJUGN
:TG^TG_TG
:TGJUGN
:TG^TG_TG
VvTCby F7
VvB_Q>vhxVvB_Q
VvdB_Q>vwVvPB_Q
I%PkbU
I%PkYU
^xM7wa9
|\J:W>
^xlK7wa9
LF~Nv@
^xJ7wa9
^x\H7wa9
^xI9wj9`
:TGJTGKTGLUGN
:VJ:Q
:TGJTGKTGLUGN
:VJ:Q
#^x6bS
#^xd6bS
^x@9wj9`
:TGJTGKTGLUGN
:VJ:Q
:TGJTGKTGLUGN
:VJ:Q
#^x46bS
#^x6bS
:~LDKM
#^INNd
9DRVyY
:~LDKM
#^INN`
IF#IF@
IF@DI;
LNDO;y~
J:x`U7
^x`6UL
J:xPS7
^x@6UL
J:x O7
J:xpN7
J:xPL7
^xP6UL
J:x0J7
J:xpI7
I>i<K:W
J:x0G7
I>W<K:W
^@K:W=
^pJ:W<
^pJ:W9
9V{:N0V|:"
+>x[8TNw79VF':~^
:HK:Ww:
^x,6UL
:V{:V|:W
W(J:x<7UL
:HK:Ww:
:V{:V|:W
Xz>"cQ~
R#fSTL,
LN:>Q|
s9|wd9
z=y`&
TULpG:
:N>v$d
:N>vdc
:N>v$a
:N>vd`
:N>v$^
:N>vd]
+>x`9wv9
+>x:8TJ
Ln*zULYJ:W
Ln*zULYJ:W
Xd}v<N
f~Nv$4
4UL,VJ:W
HB#9{R
+>y8g9
+>yHs9
+>yHt9
'k''l:
pp||y~Zk
pp||y~Zjs
pp||y~Z
pp||y~Z}kZ
{nt{:zz
pAj{hf
{ntzu:zz
S}VHS}LN
_j:n>rimj:n>rI}M:
9m=qhlJ~
{[:[:[:[:[:[:[:[:[:[:[:
{ljlvi
l:k:|:
L4QgOP:l
v:lOH0:
h5hjjvni?p
HUHZ{'z
YT|7rdwUB. aG
|YT\TH6<Ss1Mm
3-:JVm#
WN#6Hc
&RaGZ+6-G:
&ltkl{
lkMUH:
{H9hS:
:!:>,=
:!:>,=
:":N!=
:#:^%=
:s':+=
:4+:><
:V,:^<
:z2:^<
: 8:><
:08:><
:V8:.<
:f8:.<
:=9:f=
:N;:":
:\;:6#:
:;:.c<
:<:.c<
:<:^c<
:<:^c<
:[?:.a<
:k?:.a<
:M@:b<
:UD:P<
:yD:P<
:E:.L<
:E:.L<
:0E:K<
:aE:nT<
:wE:nT<
:IF:NG<
:[F:NG<
: G:i<
:IG:.{<
:ZG:.{<
:1H:g<
:BH:g<
:QI:~\<
:gI:~\<
:'J:R=
:K:>+:
:_K: :
:L:~!:
:5M:~=
:@N:>=
:T:~=<
:T:~=<
:MU:^=
:E]:><
:!g:.<
:sh:^<
:%i:~<
:Il:~<
:_l:~<
:7m:><
:Hm:><
:`n:~<
:+o:n<
:Ut:n<
:cv:><
:}v:><
:+|:n<
:A|:n<
:y|:><
:d:n!:
:|:F*:
: :N":
:h:~#:
:;:N1:
:a:~<=
:l:>@=
:<:NC=
:|:^;
:0:>>=
:j:>>=
:U:~C:
:K:NJ:
:T:.e:
:{:nZ:
:Z:6:
:s:N$:
:?:f+:
:y:> :
::.[=
:I:.[=
:g:n^=
:':.I=
:K:.I=
: ;NF=
: ;NF=
:!;5=
:G!;5=
:9";.y=
:T";.y=
:#;~x=
:#;~x=
:2#;^%;
:$;N%;
:$;N%;
:6$;{=
:}$;~8=
:%;~8=
:.%;n;=
:3&;f=
:f&;f=
:$);&=
:Y+;&=
:#-;&=
:k0;&=
:4;nh=
:Q6;^;
:8;^r=
:9;^r=
:$9;#;
:Q9;#;
:d>;~;
:xG;s=
:{J;N;
:O;^];
:%O;^];
:Q;&;
:BY;N;
:._;~;
:[_;~;
:(o; ;
:o;&):
:dp;^:
:Ls;>:
:vs;~:
:ht;~:
:Mu;N:
:}u;N:
:#v;n:
:ix;~:
:Jy;.:
:${;.:
:?{;^:
:z{;M:
:)|;.M:
:)~;.:
:v;F:
<fZ6#:
:i;&G:
_qPP+1](T3{'o
.pS1VKF
D6o K"~bL
j7xScqVH
CCCCCCCCCCCCCC
AAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA
AAAAAAAAAAAA
AAAAAA
CCCCCC
CCCCCC

DNS

Name Response Post-Analysis Lookup
dns.msftncsi.com A 131.107.255.255
dns.msftncsi.com AAAA fd3e:4f5a:5b81::1

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 56933 114.114.114.114 53
192.168.56.101 138 192.168.56.255 138

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.