1.0
低危

268e78f5eb63f197e20b6daf2a50a440bc29fc4043090f6e54ece9eee7ffdfb3

268e78f5eb63f197e20b6daf2a50a440bc29fc4043090f6e54ece9eee7ffdfb3.exe

分析耗时

195s

最近分析

360天前

文件大小

81.6KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN DOWNLOADER UPATRE
鹰眼引擎
DACN 0.12
FACILE 1.00
IMCLNet 0.82
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba TrojanDownloader:Win32/Upatre.561466a4 20190527 0.3.0.5
Avast Win32:Evo-gen [Trj] 20240214 23.9.8494.0
Baidu Win32.Trojan.Kryptik.ke 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (W) 20231026 1.0
Kingsoft None 20230906 None
McAfee Upatre-FACE!E418C7B56A76 20240214 6.0.6.653
Tencent Malware.Win32.Gencirc.10beaf1b 20240214 1.0.0.1
行为判定
动态指标
网络通信
与未执行 DNS 查询的主机进行通信 (1 个事件)
host 114.114.114.114
文件已被 VirusTotal 上 66 个反病毒引擎识别为恶意 (50 out of 66 个事件)
ALYac Trojan.Upatre.EC
APEX Malicious
AVG Win32:Evo-gen [Trj]
Acronis suspicious
AhnLab-V3 Trojan/Win32.Upatre.R155932
Alibaba TrojanDownloader:Win32/Upatre.561466a4
Antiy-AVL Trojan[Downloader]/Win32.Upatre.cncx
Arcabit Trojan.Upatre.EC
Avast Win32:Evo-gen [Trj]
Avira TR/Dldr.Upatre.MH
Baidu Win32.Trojan.Kryptik.ke
BitDefender Trojan.Upatre.EC
BitDefenderTheta Gen:NN.ZexaF.36744.fmZ@aGFxA5j
Bkav W32.AIDetectMalware
CAT-QuickHeal TrjnDwnlder.Upatre.MUE.BC3
ClamAV Win.Packed.Upatre-9858706-0
CrowdStrike win/malicious_confidence_100% (W)
Cylance unsafe
Cynet Malicious (score: 100)
DeepInstinct MALICIOUS
DrWeb Trojan.DownLoader14.20135
ESET-NOD32 a variant of Win32/Kryptik.DNYS
Elastic malicious (high confidence)
Emsisoft Trojan.Upatre.EC (B)
F-Secure Trojan.TR/Dldr.Upatre.MH
FireEye Generic.mg.e418c7b56a765ad6
Fortinet W32/Waski.F!tr
GData Win32.Trojan-Downloader.Upatre.BK
Google Detected
Gridinsoft Trojan.Win32.Agent.vb!s1
Ikarus Trojan.Crypt
Jiangmin TrojanDownloader.Upatre.ryc
K7AntiVirus Trojan ( 004d3edb1 )
K7GW Trojan ( 004d3edb1 )
Kaspersky Trojan-Downloader.Win32.Upatre.cncx
Lionic Trojan.Win32.Upatre.tntU
MAX malware (ai score=85)
Malwarebytes Crypt.Trojan.Malicious.DDS
MaxSecure Trojan.Upatre.Gen
McAfee Upatre-FACE!E418C7B56A76
MicroWorld-eScan Trojan.Upatre.EC
Microsoft TrojanDownloader:Win32/Upatre.AK
NANO-Antivirus Trojan.Win32.Dwn.dtlugo
Panda Generic Suspicious
Rising Downloader.Waski!1.A489 (CLASSIC)
SUPERAntiSpyware Trojan.Agent/Gen-Upatre
Sangfor Suspicious.Win32.Save.a
SentinelOne Static AI - Malicious PE
Skyhigh BehavesLike.Win32.Upatre.mh
Sophos Troj/Upatre-LD
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

1997-10-26 05:19:52

PE Imphash

c95f69ea33142e6aac817e4d2ecc4e9c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00001250 0x00001e00 5.501931088352726
.data 0x00003000 0x00003000 0x00002c00 3.479053602375288
rsrc 0x00006000 0x000069f0 0x00006a00 5.606301048132516

Imports

Library netapi32.dll:
0x40301c DsGetDcCloseW
0x403020 DsGetDcNameA
Library oleaut32.dll:
0x403038 OleIconToCursor
0x40303c OleLoadPicture
0x403040 OleLoadPictureEx
0x403044 OleLoadPictureFile
Library ntprint.DLL:
0x403050 PSetupFreeDrvField
0x403054 PSetupFreeMem
Library REGAPI.dll:
0x40305c RegWdQueryA
0x403060 RegWdQueryA
0x403064 RegWdQueryA
0x403068 RegWdQueryA
0x40306c RegWdQueryA
0x403070 RegWdQueryA
Library msvcrt.dll:
0x403078 fopen
Library msvcrt.dll:
0x403080 fread
Library kernel32.dll:
0x403088 OutputDebugStringW
0x40308c IsDebuggerPresent
0x403090 MulDiv
0x403094 GetTickCount
0x403098 GetACP
0x40309c LoadLibraryA
0x4030a0 FindVolumeClose
0x4030a4 GetCommandLineA
Library kernel32.dll:
Library iashlpr.dll:
0x4030b4 AllocateAttributes
Library sti.dll:
0x4030bc StiCreateInstance
Library REGAPI.dll:
0x4030c4 RegWdQueryA
0x4030c8 RegWdQueryW
0x4030cc RegCdCreateW
0x4030d0 RegCdDeleteA
0x4030d4 RegCdDeleteW
0x4030d8 RegCdEnumerateA
0x4030dc RegCdEnumerateW
0x4030e0 RegCdQueryA
0x4030e4 RegCdQueryW
0x4030e8 RegCloseServer
0x4030ec RegUserConfigRename
0x4030f0 RegOpenServerA
0x4030f4 RegPdEnumerateA
Library msdart.dll:
0x4030fc ??0CCritSec@@QAE@XZ

L!This program cannot be run in DOS mode
@.data
8G6u(Le
}mp?aUV8ZwnAH]oXR
+]n]XYFed%}
6o4~=1wf
?td81rF
/^2R|f-3`N
iwyWA< 2%3Do6XGm
\jl`>_XbA
=08{!@=
u}m@U];,%2[#r0W
\[$'fCJr;
.]wrVx
rW_S5(
JoewL^e&D?FAa
+^GB6W[
Xqr[5;$
0(-=./F#B
2%.$2?1<@=B
+B/4;(/%9CF?%
+?%3>4-1
.2(5<,=
;(22E
&08* )!F
7'*.:1+.
-:0+;=96"
138=DCC
!*>?-'
://54
?*=:A"7
:&%-"/
/<243&
%-F9;"
(E;!:9
'.%=*B#@9?05
B2@<(1
C+<(B
)+90@
=BF$2D
-?.'6A6,"@!
//%7>;E
*G08*0#0
<.+F &)
E>"7"G
9%=>.'8
C86,B0F
"?4')*2
%C<9)5*
<B2 :F
4E)=;
7*@.;9
%A$A50
*@>>0
))91+B
48;6E@@
D1*D!!-
(A>GD
)D3D#,:
?!&*6
6C E,< #E-(
%&0-?
>=?12= ,=*
E1!/&D
B<.%D177DF
0=;!A8
@)B6D=
7D+!'<D
D-2E*$$7
>;0:D7
>16?+=
DsAddressToSiteNamesA
DsAddressToSiteNamesExA
DsAddressToSiteNamesExW
DsAddressToSiteNamesW
DsDeregisterDnsHostRecordsW
DsEnumerateDomainTrustsA
DsEnumerateDomainTrustsW
DsGetDcCloseW
DsGetDcNameA
netapi32.dll
OleCreateFontIndirect
OleCreatePictureIndirect
OleCreatePropertyFrame
OleCreatePropertyFrameIndirect
OleIconToCursor
OleLoadPicture
OleLoadPictureEx
OleLoadPictureFile
OleLoadPictureFileEx
oleaut32.dll
PSetupFreeDrvField
PSetupFreeMem
ntprint.DLL
RegWdQueryA
RegWdQueryA
RegWdQueryA
RegWdQueryA
RegWdQueryA
RegWdQueryA
REGAPI.dll
msvcrt.dll
msvcrt.dll
OutputDebugStringW
IsDebuggerPresent
MulDiv
GetTickCount
GetACP
LoadLibraryA
FindVolumeClose
GetCommandLineA
kernel32.dll
GetWindowsDirectoryA
kernel32.dll
AllocateAttributes
iashlpr.dll
StiCreateInstance
sti.dll
RegWdQueryA
RegWdQueryW
RegCdCreateW
RegCdDeleteA
RegCdDeleteW
RegCdEnumerateA
RegCdEnumerateW
RegCdQueryA
RegCdQueryW
RegCloseServer
RegUserConfigRename
RegOpenServerA
RegPdEnumerateA
REGAPI.dll
??0CCritSec@@QAE@XZ
??0CDoubleList@@QAE@XZ
msdart.dll
-xGtMn
DM4{`suJzj
a@@Pr|
fVa~Q@t
m<<Q<<
1WODWJ[
Y~QYLD@jA
`@j@yQj
k@@Zz@A<[
@i@@i@rQj@i@@i@sQo
@oQAs@@
~YA1Qo
@@oQ@QoQl
@@BJ~Qo@Zs
xtp@@RJ~K@AIp
@@ZQo<
<~t<@`t
xtpAo|t
@oQ@J~@QoIAL[
I@I@ztuQ1W+
Z)[;WWJ@ztQ6
@{ttW+WWJW
@ }tO h7l@atuQ
@7l@atQ
@7l@atQ @atQ
@atQ@atQ
WW@{tt@atQ1
W+@atQ
@atQ.
)-@atQ. @}tuQS@atQ @atQ
@atQ@atQ
t7lV~t
;z@A<~tt~tt
e~tt~tu~tb}:
|@@Zs@Zs@R@R@Y:
ZI[@}tW
7QYVZ)p[
;@}tr@ZyQ}tr@ZQ}tr@H@ZQ}trW@SQztr;AIpWxt@
tQ}trv_@
uQztr@p'Qxtr:
;@{tu@zt@}tr
Z)s@K@/QyTv+`@d@`
QO@QN@h
;<pAp<p
I@{ts@}tp@IQ
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="requireAdministrator" uiAccess="false">
</requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
</compatibility>
</assembly>
24gssvZz7Wpr
8G6u(Le
}mp?aUV8ZwnAH]oXR
#`"Q2%
Cc))GxTi
@<O$q*)ESZq
xt0PBd{~
hp5ZCz}
X[Eb(dmoXF
fvl>Rs
Sx$i+~$xVg/[X
]?=)qks)
T[j{.8
MYa\u3
g-NB7dYu
<Uo{B6
SsJMj]!
GAtn8TX(e:,42
sX,""B
.ctG\&wLln:
4^9F-Zsj4
s*3SZ"11jVf%*
~h&~}LR
;j`4E#
-XYrGQ
IW|~Y~=
TG,M|kg>{wD]MNe
o&DJ|&
~;S<V`E
o(^E?e
,\pUPOCp2
,UZ}[amW
Gz=YAWC@e~$]|
1O1%2^
2.s:udYCgv7z8;.\Yg
F`f8AkI
QC+,nNQ1bt
cU#7uHG-4
=k?(IV
TJ%v+PK
y*tJHjLM
'Z^V\Y[
0DKa{9^!l
5H/EaVA|zH
XV"goyZrI
HeV!;vG~
U>GY0xs9
AbFJ<F
h4qH_]j
mTT%]'@YjxJ3'sX
2Wb_je|
RUz!U&^
NXzntw
J[SE~[
YO`]}W
}%QbVX=pO1
o4t-(0J\
7\QSK>'
4[_~>#9
Cst8sa
J<Ux4El3
=vp2kVkA
GC#%rb/K*$XN+$b~
"a<qg7gX
l)KDYGR_6Cg3COg_'3jG.C16hNm
J2;eKW
:ce~gw
j@U|B.
]#C`PH
M|?\e.
X~YM,&T
'm0g,.^
w/7|6s%{b$5rLd
E1K2ne
AvOfW8#W%
Ed1\\Q"
5s1]oZ)Q]G
KA[o!s
@@.Coe
NhmKJ(/g:
xVQTMQ?
DwKW@G
WQl^o:+.@
?+a`/,.B
]f&xyZ
:412!l."D
vf=5]p[Z3_OX
AzQ{]AGX;
z`&TdQ+
w*j>?2KT9+
hIE=JE4
zZKuM4}
EU)z>z7
|<Qs^]
RROfZB
~zt"H)V
i;]"MNL`X
BiaxvM
kP1??zR
xW`&Yf"C
`$yXHOA
s$i3(z
;>ZT@7*"
2(c,')R?,
a?%"R?"
\?'Y?'
^?gizinxov}mq}oopmnlomnp}lrxmvxnt}nqnnqnooornp}np}orpsqtprpsqtpsrvrvtoooyx
' }' }' }%
' }' }' }' }'$
' }' }' }' }' }' }' }' }' }' }' }'
' }' }' }' }' }' }' }' }' }' }
' }' }/'/'/'/'/'/'/'%
(i`?2(
&{NG%
' }' }' }' }' }/'/'/'/'/'/'/''$
)")'"
um) '"&!& )#)#)#)#)#)#)#)#)#' }"
}}}xxxxxxxxxxxx}}}
' }' }/'.&/'/'/'/'/'( '
w%*"(")!#
tr,#/.!)#)#)#)#)#)#)#)#)#)#' }' }xxxpppkkkkkkkkkkkkzzzE
' }' }/'.&.&/'/'/'/')'
[W1 &,!&
nq%)(#&$)#)#)#)#)#)#)#)#)#' }' }sssffffffxxxa
' }' }/'.&/'/'/'/'/',"*
C;'!,$*$*$*$*$*$*$-%-%' }' }
' }' }/'.&/'/'/'/'/'+"&
`Y3'-%-%-%-%-%-%-%-%-%' }' }
' }' }/'.&/'/'/'/'/'-$'
.&.&.&.&.&.&.&-%)#' }' }
' }' }/'/'/'/'/'/'/'/&,
#&*A75-)
ts+'1(+')'/'/'/'/'/'/'/'-%)#' }' }
' }' }/'/'/'/'/'/'/'1',
&. |3($
{q4%1$1(/(/(/(/(/(/(/(-%-%-%' }' }
' }' }/'/'/'/'/'/'/'2).
-)0)0)0)0)0)0)-%-%-%' }' }b
' }' }/'/'/'/'/'/'/'/*/ 0&2)4)/!0
.0)2)2)2)2)2)-%-%-%' }' }
' }' }/'/'/'/'/'/'/'2+/"`brdqcq^B03!2(3*XPoamdpfF80'.)3)3 gerfpkqjsiTL3&4*4*4*4*4*4*-%-%-%' }' }
/'/'/'/'/'/'/'/'/'/'/'4-5+5.3,4-5,5.5+5+5+6)4*2-5.6,3.6,6,3,4-5.3,6,8+8+8+8+8+-%8+' }' }' }$
' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }' }
24gssvZz7Wpr
E1K2ne
AvOfW8#W%
Ed1\\Q"
<Uo{B6
SsJMj]!
GAtn8TX(e:,42
sX,""B
E1K2ne
AvOfW8#W%
Ed1\\Q"
5s1]oZ)Q]G
KA[o!s
@@.Coe
NhmKJ(/g:
xVQTMQ?
DwKW@G
<Uo{B6
SsJMj]!
GAtn8TX(e:,42
sX,""B
d[rQi*
g,uuDy
aPVOX)#z<
: us'G
}AP@29
TfdmhZ
k}i^$af:;>
>UJ/|"
5`UW}nc
|$"UUNBf
yANb}m
_/[.0 U]
ZS&upb'4\@<5e;
HUf57
Y).V}
Ne-(lzZ~q
*|K>LT
=rV'pK
i:hgh}t
UMwx@1W
,jpUf:
4`).:L,H/
i?kp5U{Fj
2w \?[
.Rw#\aC
.euUj[:f8
_hHnCE2{S
J%/,@\ _
`X?EHTy
hjy;$W
vbx2?f.<(/n]ZK8(Yp
*iTpooH
{]|ii|
qiV_7
H9}t"<
l1k4Xgg<j
j=zR_=BPm
uAqqnD
D>,6`5
WTR,"m
f V7~Xx
f9Uz.iUh,
a$y)npY
`T@C&q
wKA}H-
Ohp}Y3}
#t*.l1AV#
%=bOYJb}jY
3fIH,~
~!x.5`
XO{JJ"]<d|
[[SFmI
l5LS\Z^|{`&I`
u8#G).dV
jkY$BNC
7|*\YZ
$v.4'X
+^W-:/jy3
mQdy?8e
!UF >rG=D'r
fPa?jU_
cU&}L8
.M?7SQ
xh@:5-
30PQ`eUv
BZ9jNI\
x* EC0O2qM`
SM`^Giw5
4ltR{H
p#W]4D$y
c`QBcxhWE/,Kk\
>|r8"[
)!$YbP
2_<&c0
8+H {~
FtQUMQxXj
3Q0@N"@#r# \
!3{h5E
*eVJKi
J,+P}$h1n|z*L
>\{hV
n`&7)Q(^e
m6:s#{h^GB
'Y9lNoe5\
0.`@`[Kp{u:*r:G/md]e
UCDd#Oiu
y(Y,N^nYnr.
$b%*)} U[DYhUY/}24|%
qYA7Gq%3
hxK&UL(
X]DQCDe#
]W{aHP!dHr
+,sIw)F>
{v9XZB+S>]f
Q{XYkSX
_<\4C\gN
@U4PEV(
|S'&I/W
ZwH?@m
CU8x@u
?Qh#Ws-
Yix7,*(:)]o3
MPlA(!V;/*
.al{<vG%*ZR73s3hR3FHw4
ww.Xz5l
T2(:>p2$%d
$NFLSr
w=ADPr!R
B- Gvsk#
k:XHFo)
[Exxi\w
,??2]Sge;p'MTLLyI`L
1QoXa$
sMs0C1CD?
~`q$,3c
q~]y)#rB
"<vK#T`e
2PTK}oM/W
dykwdId
;:+]F.
%jK:`_h
<%Ag-l
,d"H`(nZ5
0j|}_mf
Bt$pabc3ixWI$i
}M9hB]g[
<q:cx)
)?Y&ew~o
PtXZYV
-F2$L&?bK{@
taokf_Z
]",!Wn
1ZOO@[G
0z=D#V
IWlL`P`?6G
lUW.>r!t
>yeWF!
`>KLlQ
Zec]o6
)OC5;R\
1=W8M@
`_LQKa
L>qp(w
'PeF@qG
d_U( A>s>"
5hui[Q
ClR$R`
/|n_RJ&
8xJMWW}Q
lTGi`[
z$'[0#S
cNRGMx
p:W.1)
[PW#ExNGI}j1]2VT9z
C0t3 ,^v
15@'B4~
v|ziYXXpH?
v),G_
#O[7syYF
kQR9#5z(5").XI
x[\S}HK|+>;
HU.FDYO<
f}OT%=d(#
X4^v[R
),_\BV`SIy
Kgoo7 XU
'm:f>\
j;cl8$#
bI;T/@1g
WX1J!nK)y>er
01qbZ%#
FeVA15
dur~*l
SYqX^2so
RrBVyQ9v
YJ8IR8J
ySZ~(S%O`I
Vf^)|`
$+nN%5P-qk
h=CbbK
M.@A?MfTqy\n
V3m`1}9Hcb
6XS4}i.f
&`Zw?I5
GoA.4"
\CjW,{LqH
MPM%`"
+zqd?(0T
ug*nQ'BV:x7$>
zH7sZv2
JQ&=c=i-
{#Hz^SI'a
*R)=(tT<C
~Bi&_X
GZ1"!,bdhfv
Sk:qDk
,c49{g$4h
r8;Rq"{LHA
;qC,hb
;Z]XDg
Zp\OrWYji
aUp,vj!{J
2R^v"\ q
0dK4-6R
kc;}?-m
y $Xya1
fCUvV}n[g
+U"NfH
j-\a&LV
c'.awWD,
q\hHAX
Tc7>6O
0tc*pY)wq4c[(y^
YQ*6q@r
QzJ:Qz
=94D{{2XN
XRwDJF`
%"dg#W-c
[IH4Tr
om&3_p
F8v>/jkwB
|+H("C5
GhF:p]W!Xz
V%=|jn%6a$@FU?)
'gxZJnz)*3O
UFOXpWA
qS}MY;Gy
sd>+rP([
tw%$Ag&
&##+L`f/4S!}f}
,:N(e`U
c2TNkc_|
^Nf`I3O:`:y,
{b.MHLI55O
w5J+"z
$*_}0n
?cIw73
HJ+racA
x}]&Vy:,Y
9{k}l)wJ
e//rA0
rR{.Da
_72yKrYa
WV:z`AY
7O~.jd!
,XOB=k3
~N6uLo
7.aSF<
*1x.C92
!pc;.5
D;S0'RH2UF1
HuNb]=0;
?NF)%Efb
;Xujdzr&B
:@t)u3"
,}47UNHc
Pmi-ew]r|`e9<
gpju|vzkA6~}
aPOIX)7`K
DA0FPiCu
r`MD;R
[Y576Gvl4L>0hg
/L_-mSP
:6pwPn_fQZ
{@D4pD2
ADnKU!i{7i9yS)B
'(qJeT_nm
&Od` /{
!1>rpuKb
{%h:Z`#
7Ug\RU
x$(+PLlk
megF`,
J=aSHT8q+
XxB9pg
:=8!R{{n
wp}l)t&;gF5I)#ep"
q.{d}1}!|i=Q
v#@o!.w+$
2 RffA
|%;/Q1
@;X$gj
Tp^ranf
gS^1!;dZw
\LA>]u)$o
cv6^X2
J/mfdmzsNHXa
H<e!{{
<6j9UZJ
#4;{ir3w
F(i*}Jm<1
d]]&}av
%sc_Kn!%:73Rz@
DuHMV%e
z,x)Qw
>4h,@`
jK)j* SzeB
yaA0V+_a
BU_19I
@"*w*2hWan
1@1Bt|N|
|"iDC(
c\x,.-1uo
;NgEK )
v1X^W7/s
7$4vweF
v7#"_&uhF
2`VB]5
.R+#g>
f|=z,d\
aQENkQ
IhL/)o
)\TDe}k#
@F_.6{bhd LcX
$:/fm-,Ke
6~:})oSe
p!]aR&
z ({1PX4XJ@
~JWTCU@Y
tj0t37k
Hf`OB"sUI
_Knxk*|{e
KlxULO
0+lk[O
Xdmh1}-{
b%B/Y38c
w#Cx76:b)@
OY7W_)na'uA)OG)MW|9
W];*n~up
+m4e ~u-
}x#Nd?
SCr"Fim}
J^g^E8?j
(;+DC*Y
WVytl<
ZTi8&Fp51niTuN-
ou{M<p:W
E}t2)Rp+GY
}^pC$3
:=$wXPof>
48U>>Do
2X!h#n
.@!@~~]X
^'6h3J^U
FmL~/5Yp"
BDh6W
o)%E:<B?v
':GJ9_
zcMh<Lrsxv>
7k,TnJ+Rt
I}1{4q
Xv-a5Dt
B{o o;/cL]
8ltx{/|FU&*
3\^5wSuRrVN!
GzT()%
lg'ZK.aH
^*km.3,5
,;nV6u
zF>F?x&%ei}ep4xN
Wq&;9cV\~
3=,/"k[
%80! KrR
=RC{%C%5
<y++_V
ijx'E(U>
zt.U?C
.AiiB7<R,
iVnrZ
=";iSG/({X
3-hN0kH
DA{|I)
FGj:pxI+e
)Py1zq
3*CM3i|ewe
NZnSN>`
GP]5(#
t(ZZV:!1UlCE
byr-}0t1V\u
"`@tihUW
ZnP@J!`*
G^mADRDpJ
->YV7;^/37a{
f$|/,f
MH|.Az!
!"&uuU
DwXh3@v5*
"=Y)7%tD
YY(Z-w
xqTY=%x
RQcR!^IVncv
qtN?sm9
PgZ"&'/)/e
|28u5K Q
)Bx5|{7
lm!VYxIy~@;4
LMwx!!0]
&~qc9@
`R|pl`
amh{2Eh`E"5Gg!:u
WJRL^`y.
cAi#G!69
oJe#aEF:]z!O%z)>l_?-~
D;,k_q
J}Q\@m
T7buME
|>AqP*FA=3
=Md~A'<
Gru9u(t
x0z{RVG
[$|pZG#t:
g(:2O7
&VvU5_DS
b@:%cS
e'&s5>x
?UAGEng
^h:((EX
])e:$],
tW[O<?j
sSIuwnt
[>I$TS6
TtR%b5Ce`
84S:p_?\
ac+ni@<0
&yH{eKW%
?[ k#Yr_-w
zHA[ B-
rn)x1>3\&%
f(/|{Q|X
C$Q0&}&
2G=vS8
&PcF<LW
vQj!$4q
qy}T\I
X{X.K$
BpmD2"u+/
PVmh^DCZ
>{[44v
Im`-MU
-p%1?j<Sb`
}J$LCO
C:\STDpdWjF.exe
C:\lSUCpPKg.exe
C:\ThMHRQfB.exe
C:\gngyhYl3.exe
C:\bUSvdFTK.exe
C:\4Fv6Xzsv.exe
C:\Ib_4eV9f.exe
C:\Ld1UwmEc.exe
C:\tPEwYXSV.exe
C:\HD3qatF0.exe
C:\ChRu90e0.exe
C:\K0Hc3sZH.exe
C:\f1RdvcCx.exe
C:\NFyMQuzu.exe
C:\nErN1ojS.exe
C:\6LZBdcj_.exe
C:\qQtTY2QV.exe
C:\tCpG__JJ.exe
C:\44bf15f1e4c866e048b5ecfafc8518a63fd1def0d5ef921d397a82a1c236a65e
C:\a93f7cf30f9af3dad4010717249143ea1e902e1aed25c5a0c28aaf0c4fdceed0
C:\9502554ef207ce04707bb0d46ee6ea8cfa29a5a3821c2169d0538c0de419921c
C:\117ea061f4b01802550f791ada56003b43508a768dce572d59c95bbb7a109475
C:\Raiden\Goat\FTP\Sample\7576B0CE90C3F054AA9A22C4D2107EA2.bin.exe
C:\Users\admin\Downloads\dd423088faa3a8c21de777e3db79a7a1.virus.exe
C:\14413848ec9f8d4cad2368aeeaa25e2fd264698ebecb3b1271d8d32afef5a08d
C:\Users\admin\Downloads\zaberpit.exe
C:\836f384041f5c33b00050bdc851d5476ced5e6c8ca082bbbce2257c6be55a561
C:\Users\admin\Downloads\zaberpit.exe
C:\5bf250958b144769eaf1355863b864d1e9867a47940dd37707e082418b6f1684
C:\Users\admin\Downloads\zaberpit.exe
C:\63bdfcf8a0f1af4e09e9be2c2e072296263dff06e4fc39d5280020117fa24a22
C:\Users\admin\Downloads\zaberpit.exe
C:\Documents and Settings\Administrator\Desktop\H8ZsZFqR.exe
C:\9c9f975d82d4c275f8f8ddc3b11c94bca293a31160e4eb64c2f58bd6fc293719
C:\a1614256a09df1d7627dbda948462a713b15ce050feac60fd7b8ca5678fb5ca6
C:\Users\admin\Downloads\zaberpit.exe
C:\59446396caad1b4390ed6304475762410eaceb319305cedbe608e1e065cc537e
C:\Users\admin\Downloads\zaberpit.exe
C:\d4e43e3fa849823f2f26c9bfc9b5b531d8c8472788db244eb45e4b31b72c8a36
C:\01cf8e4eeac743c1ccd19f0664dddb374b2df277175ea50ca1b4bb5ca20d0507
C:\84a5477166547c2a3695c428f4770a4e2f1026482e8c8615efc5c8866772998d
C:\Users\Administrator\AppData\Local\Temp\NcKmp.exe
C:\Raiden\Goat\FTP\Sample\44976F3BF7074D1708D7E0FAE624D58F.bin.exe
C:\11f429ae0a3a33f8c8fa2129aecff1ce6a8a41c249ce70ad4c5ba9298b8b6191
C:\6d45a289cea3941acf3ec61f8d7758328f6b35e258458c848d46052a87ac92d6
C:\Users\admin\Downloads\zaberpit.exe
C:\7a4885fc63423428828d7b00efef1f8a30af31f56a1e5984aeaf7a966f667693
C:\Raiden\Goat\FTP\Sample\9F068FAC3A70644BED86B6CFE14C6AB3.bin.exe
C:\Users\admin\Downloads\0458e9baf5cd733eb3bc90800358078c.virus.exe
C:\Users\Administrator\AppData\Local\Temp\EbZSUzhRQK.exe
C:\ec051678091d5e2756734489432a40a5d0e3b87a88ff5966a6f2185e96c3d392
C:\a8a0bf162e669a3a5b79db66dfeec16b4e22366896d48dfe773629591df2d146
C:\b4ff3b9b97b93008d1f858c4aef3b4f236cf976e92a957c28993148cbe23aebc
C:\a1472c249021b66e37db8a63e3f299c58ca2c4a9ae7563205e92154b84b5d51c
C:\3baa40cc997575c45c2a39bc7611767923d5d55c2c1de53cae36bb79ba4999b8
C:\Users\Petra\AppData\Local\Temp\zaberpit.pe32
C:\Users\Petra\AppData\Local\Temp\zaberpit.pe32
C:\Users\Petra\AppData\Local\Temp\zaberpit.pe32
C:\d36cefce392193aae5b129e819fa9206d878923e550231667b282fcaadec4e87
C:\53fab8f8268bdd6d30959d9f330d5eb9f11766c63f13c1ef12fc115fcc13bbaf
C:\face7b4b191fdbfe7340e29f863426206bce3be7d1faf6235349837dc4449643
C:\d07b9efd38058b10701989edbbef1f2dd49ba027fe2f90204604e8efc23d59b9
C:\Users\Petra\AppData\Local\Temp\zaberpit.pe32
C:\Users\admin\Downloads\206bb28c36597c2f_zaberpit.exe
C:\ef91f2984906158daac07d89d14421943b0d17f5ace47c465a0f69e438b6254a
C:\Users\admin\Downloads\zaberpit.exe
C:\Users\Petra\AppData\Local\Temp\zaberpit.pe32
C:\Users\admin\Downloads\5de2618385ab8910_zaberpit.exe
C:\21e6930e26cced02d7aace2ab045645a1f787ea27e8e54aa8b06e7f63563ffcd
C:\Users\admin\Downloads\zaberpit.exe
C:\Users\Petra\AppData\Local\Temp\zaberpit.pe32
C:\Users\admin\Downloads\923565a89a61e091_zaberpit.exe
C:\8f7e8e51ba72794e72a84f99ad4a6820f8a4f9a40926cc19e94cb9a3d3b86a8e
C:\478379e1cb8e9b2b8a643f527af8736cfe6fac7a9270e866d7b6a60077986223
C:\Users\Petra\AppData\Local\Temp\zaberpit.pe32
C:\Users\admin\Downloads\98739c289aed171b_zaberpit.exe
C:\c0819caec0e67b0e203e85007136f8516b808f023ef5be36fa335442edb832d9
C:\Users\admin\Downloads\zaberpit.exe
C:\e0f76f907984b953b082e4f6882e109ece70c989b28498c64879d05a626b2687
C:\Users\admin\Downloads\zaberpit.exe
C:\45fad733324cce1e19faed46b6cfd3e8824540966e95be0781047e948e8bc36a
C:\38f4378928b9cd7db5aefda5195f65e0e18f37324f9593fe0f1db95e66953ab5
C:\Users\Petra\AppData\Local\Temp\zaberpit.pe32
C:\d05c30eeb265e152bc10f3dbbdc7028eb27154f428c3480c38b37ed9806aacf8
C:\Users\admin\Downloads\zaberpit.exe
C:\915cd43ae49fe9b5a0cc9deb3ecfdb19abd66eca84c4083a5a2b09c23346b93e
C:\d76a45455c7bf1b17de1814468ce3bb70659b02bb90b0e02cde65c243f5c3140
C:\0970b822276f2f60a805ad5fd10117977d6356111ae1cdfd67eee9b3f10aa474
C:\Users\admin\Downloads\zaberpit.exe
C:\Users\Petra\AppData\Local\Temp\zaberpit.pe32
C:\2568507b95eba54d96a2c6c2b800fd5bafad4ebe2d6e786a20ff872e16226fee
C:\eec511822ed309f39130ae539e7c9efee561bef03eb46f14abab6c8285cdef49
C:\9dcff196c84f7254daed550b54782735a80cf3d08b07818671eb8dc0b1436274
C:\04b39c1bbb8f41c5580b072df3c4f8e64fec945b2944558708cbcb5d16133fa0
C:\Users\admin\Downloads\zaberpit.exe
C:\588ba2f422aa423a2c5bc847bb13f45cf16c4bf003e7a121a400cc7d510c039b
C:\Users\admin\Downloads\zaberpit.exe
C:\00359c5a3587b6f71ddeec421e86d30c5daa5bfb02920afc27f149a32c89f64c
C:\4e0ed686b97de918c6dbf5fcf212179ac6716b8f83e9d49fb67c200beca4f0a2
C:\e4a107d6f148a6b64b3afabbbbce1cc9630d7e9766b4f738ae1510243322af70
C:\Users\admin\Downloads\zaberpit.exe
C:\7e0fcf9ac5d6c7ef1b63fc2e1bac00efb14c13f3021b4330f6405e93219781bd
C:\49fbd2aeedcef1090c4ac584b4412a9ff7d5f360d0a7dba7088837191526c6ab
C:\9d7b9f458ac5533f9f011e193181e2df6dd1a2cedbe55d2f108f72f8be58c499
C:\75b6449d8324a4fe3e22676854009ac5579f6f87e3e6cb0ccaa532b4da508a73
C:\Users\Administrator\AppData\Local\Temp\KzXQNw.exe
C:\Users\admin\Downloads\de27bbfa34447a4ab979cfb32d1ec1a9.virus.exe
C:\ed384324db2758694c2af83f19ef774fe8e5f3074397f4c3c6044cf196aba295
C:\Users\admin\Downloads\zaberpit.exe
C:\b0a1b8b0d9b934499176ef318e300a07950aae42e8327f6d431f4e33272fbfb6
C:\cecb293b1c80df6ecda2966a33dcf22c73ca0e5c42292bc818cc8a68c7f2a78a
C:\Users\admin\Downloads\zaberpit.exe
C:\37723332711ba3a65380af9ac9e52ea74007730288c9fdcd13699247ced9edcd
C:\Users\admin\Downloads\zaberpit.exe
C:\c4aa3dad17468f2ab515f171fefaf83521622d6fce4946f1a2873adefd2ea60c
C:\41a6f4c75aaec315667c1912e38f9d36483502b456902717a5fc2380cb88d6f5
C:\Users\admin\Downloads\zaberpit.exe
C:\9f45d897d1a23c9ae69ac4bf9e4917298e95dff3be2f14a977370f7743ed4a54
C:\02d72d1be30594541c4c79c5db3c05d93e50bc2af3c7c71d28364d91fa53c6a9
C:\Users\admin\Downloads\zaberpit.exe
C:\608a811643a670474527f9fb6d056c95e007a6832508e59721dd73b4ee1479cd
C:\Users\admin\Downloads\zaberpit.exe
C:\8526b263cb441125459996afab783ae22dc70ee6f911a7e80b28c6e95016efa6

DNS

Name Response Post-Analysis Lookup
dns.msftncsi.com A 131.107.255.255 131.107.255.255
dns.msftncsi.com AAAA fd3e:4f5a:5b81::1 131.107.255.255

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 56933 114.114.114.114 53
192.168.56.101 138 192.168.56.255 138

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.