1.8
低危

9f2ff48b631113eff82576d3e41cfe7023d96ed8f69de222bebbb9c79ee2a235

e26f1f9451b7adc32807ee78a110c824.exe

分析耗时

64s

最近分析

文件大小

554.6KB
静态报毒 动态报毒 100% AI SCORE=86 ALOF ATTRIBUTE BACKDOOR2 BHTA CMRTAZQYHUUZKC2SOK0VKJHPQ CONFIDENCE CRYPREN CRYPT0L0CKER CRYPTOLOCKER CUTWAIL DFQKCCB DNQGJC FFRU FILECODER GAMARUE GENCIRC HIGH CONFIDENCE HIGHCONFIDENCE HWZN IQ1@AIYVSDKI KVKX LGBTD6EVGR4 MALICIOUS PE MODERATE MXRESICN QVM10 R134831 RACK RANSOMWAREALTAS RDMK ROVNIX SCORE TEERAC TORRENTLOCKER UNSAFE XEMA ZEUS ZEXAF 更多
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
McAfee Trojan-FFRU!E26F1F9451B7 20200408 6.0.6.653
Alibaba 20190527 0.3.0.5
Baidu 20190318 1.0.0.2
Kingsoft 20200408 2013.8.14.323
Tencent Malware.Win32.Gencirc.10b8f3e5 20200408 1.0.0.1
Avast Win32:CryptoLocker-B [Trj] 20200407 18.4.3895.0
CrowdStrike win/malicious_confidence_100% (D) 20190702 1.0
静态指标
行为判定
动态指标
网络通信
Communicates with host for which no DNS query was performed (3 个事件)
host 151.139.128.14
host 172.217.24.14
host 52.218.63.28
File has been identified by 58 AntiVirus engines on VirusTotal as malicious (50 out of 58 个事件)
Bkav W32.RansomwareALTAS.Trojan
MicroWorld-eScan Trojan.Agent.BHTA
CAT-QuickHeal Worm.Gamarue.WR5
McAfee Trojan-FFRU!E26F1F9451B7
Cylance Unsafe
Zillya Trojan.Agent.Win32.508499
SUPERAntiSpyware Trojan.Agent/Gen-Rovnix
K7AntiVirus Trojan ( 004b5c0b1 )
K7GW Trojan ( 004b5c0b1 )
Cybereason malicious.451b7a
Arcabit Trojan.Agent.BHTA
Invincea heuristic
BitDefenderTheta Gen:NN.ZexaF.34106.Iq1@aiYvsDki
Cyren W32/Backdoor.KVKX-2352
Symantec ML.Attribute.HighConfidence
TotalDefense Win32/Cutwail.DFQKcCB
APEX Malicious
ClamAV Win.Malware.Bhta-7598462-0
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Trojan.Agent.BHTA
NANO-Antivirus Trojan.Win32.Agent.dnqgjc
Rising Trojan.Win32.Filecoder.v (RDMK:cmRtazqyHUUzKC2sOK0VkjHPq/Ss)
Ad-Aware Trojan.Agent.BHTA
Sophos Troj/Agent-ALOF
F-Secure Trojan.TR/Teerac.A.10
DrWeb Trojan.Encoder.847
VIPRE Trojan.Win32.Filecoder.dia (v)
McAfee-GW-Edition Trojan-FFRU!E26F1F9451B7
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.e26f1f9451b7adc3
Emsisoft Trojan.Agent.BHTA (B)
SentinelOne DFI - Malicious PE
F-Prot W32/Backdoor2.HWZN
Jiangmin Trojan/Rack.e
eGambit Unsafe.AI_Score_99%
Avira TR/Teerac.A.10
MAX malware (ai score=86)
Antiy-AVL Trojan/Win32.Agent
Microsoft TrojanDownloader:Win32/Cutwail
Endgame malicious (high confidence)
ZoneAlarm HEUR:Trojan.Win32.Generic
GData Trojan.Agent.BHTA
AhnLab-V3 Trojan/Win32.Xema.R134831
Acronis suspicious
VBA32 Trojan.Agent
ALYac Trojan.Agent.BHTA
Malwarebytes Ransom.Crypt0L0cker
ESET-NOD32 Win32/Filecoder.TorrentLocker.A
Tencent Malware.Win32.Gencirc.10b8f3e5
Yandex Trojan.Agent!lgBTD6EvGR4
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2014-12-06 04:25:05

Imports

Library KERNEL32.dll:
0x41000c GetCurrencyFormatA
0x410010 GetConsoleCP
0x410014 GetLastError
0x410018 VirtualAlloc
0x41001c OutputDebugStringA
0x410024 GetVersion
0x410028 VirtualFree
0x41002c ReadFile
0x410030 FlushFileBuffers
0x410034 WriteConsoleW
0x410038 SetStdHandle
0x41003c LoadLibraryW
0x410040 GetTickCount
0x410044 GetCurrentProcessId
0x410048 GetCommandLineW
0x410050 HeapSetInformation
0x410054 GetStartupInfoW
0x410058 RaiseException
0x41005c DecodePointer
0x410068 IsDebuggerPresent
0x41006c EncodePointer
0x410070 TerminateProcess
0x410074 GetCurrentProcess
0x410078 HeapAlloc
0x41007c HeapFree
0x410090 GetCPInfo
0x41009c GetACP
0x4100a0 GetOEMCP
0x4100a4 IsValidCodePage
0x4100a8 TlsAlloc
0x4100ac TlsGetValue
0x4100b0 TlsSetValue
0x4100b4 TlsFree
0x4100b8 GetModuleHandleW
0x4100bc SetLastError
0x4100c0 GetCurrentThreadId
0x4100c4 GetProcAddress
0x4100c8 WideCharToMultiByte
0x4100cc LCMapStringW
0x4100d0 MultiByteToWideChar
0x4100d4 Sleep
0x4100d8 GetFileAttributesW
0x4100dc ExitProcess
0x4100e0 WriteFile
0x4100e4 GetStdHandle
0x4100e8 GetModuleFileNameW
0x4100f4 SetHandleCount
0x4100f8 GetFileType
0x4100fc HeapCreate
0x410108 SetFilePointer
0x41010c GetConsoleMode
0x410110 RtlUnwind
0x410114 CloseHandle
0x410118 GetStringTypeW
0x41011c HeapReAlloc
0x410120 HeapSize
0x410124 CreateFileW
Library USER32.dll:
0x41012c IsZoomed
0x410130 GetDesktopWindow
0x410134 GetCursorPos
0x410138 GetMessageTime
Library ADVAPI32.dll:
0x410000 RegOpenKeyExW

Hosts

No hosts contacted.

TCP

Source Source Port Destination Destination Port
52.218.63.28 80 192.168.56.101 49187

UDP

Source Source Port Destination Destination Port
192.168.56.101 53237 114.114.114.114 53
192.168.56.101 53657 114.114.114.114 53
192.168.56.101 57756 114.114.114.114 53
192.168.56.101 62318 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 123 20.189.79.72 time.windows.com 123
192.168.56.101 49235 224.0.0.252 5355
192.168.56.101 49713 224.0.0.252 5355
192.168.56.101 50534 224.0.0.252 5355
192.168.56.101 50568 224.0.0.252 5355
192.168.56.101 51808 224.0.0.252 5355
192.168.56.101 51963 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 57874 224.0.0.252 5355
192.168.56.101 62191 224.0.0.252 5355
192.168.56.101 63429 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900
192.168.56.101 49714 239.255.255.250 3702
192.168.56.101 50569 239.255.255.250 3702

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.