| section | .lol\x0a\x09\x090 |
| section | .lol\x0a\x09\x091 |
| file | c:\install.exe .exe |
| file | c:\Users .exe |
| file | c:\globdata.ini .exe |
| file | c:\360Downloads .exe |
| file | c:\ProgramData .exe |
| file | c:\VC_RED.cab .exe |
| file | c:\Windows .exe |
| file | c:\vcredist.bmp .exe |
| file | c:\Program Files .exe |
| file | c:\vuxmqoevu .exe |
| file | c:\PerfLogs .exe |
| file | c:\System Volume Information .exe |
| file | c:\pagefile.sys .exe |
| file | c:\Program Files (x86) .exe |
| file | c:\eula.2052.txt .exe |
| file | c:\Python27 .exe |
| file | c:\install.res.2052.dll .exe |
| file | c:\VC_RED.MSI .exe |
| file | c:\gcoxh .exe |
| file | c:\Documents and Settings .exe |
| file | c:\$Recycle.Bin .exe |
| file | c:\install.ini .exe |
| file | c:\Recovery .exe |
| file | C:\ProgramData\khbcj.exe |
| file | C:\ProgramData\khbcj.exe |
| section | {'name': '.lol\\x0a\\x09\\x091', 'virtual_address': '0x0004b000', 'virtual_size': '0x00021a6d', 'size_of_data': '0x00021c00', 'entropy': 7.798763438893083} | entropy | 7.798763438893083 | description | 发现高熵的节 | |||||||||
| section | {'name': '.rsrc', 'virtual_address': '0x0006d000', 'virtual_size': '0x000067b8', 'size_of_data': '0x00006800', 'entropy': 7.019781766993854} | entropy | 7.019781766993854 | description | 发现高熵的节 | |||||||||
| entropy | 1.0 | description | 此PE文件的整体熵值较高 | |||||||||||
| host | 114.114.114.114 | |||
| reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Microsoftᆴ Windowsᆴ Operating System | reg_value | C:\ProgramData\khbcj.exe | ||||||
| Name | Virtual Address | Virtual Size | Size of Raw Data | Entropy |
|---|---|---|---|---|
| .text | 0x00001000 | 0x0003be78 | 0x00000000 | 0.0 |
| .data | 0x0003d000 | 0x00000260 | 0x00000000 | 0.0 |
| .rdata | 0x0003e000 | 0x000024a8 | 0x00000000 | 0.0 |
| .bss | 0x00041000 | 0x00004890 | 0x00000000 | 0.0 |
| .idata | 0x00046000 | 0x000008a4 | 0x00000000 | 0.0 |
| .lol\x0a\x09\x090 | 0x00047000 | 0x0000364a | 0x00000000 | 0.0 |
| .lol\x0a\x09\x091 | 0x0004b000 | 0x00021a6d | 0x00021c00 | 7.798763438893083 |
| .rsrc | 0x0006d000 | 0x000067b8 | 0x00006800 | 7.019781766993854 |
| Name | Offset | Size | Language | Sub-language | File type |
|---|---|---|---|---|---|
| RT_ICON | 0x00072fec | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x00072fec | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x00072fec | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x00072fec | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x00072fec | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x00072fec | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x00072fec | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x00072fec | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x00072fec | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_GROUP_ICON | 0x00073454 | 0x00000084 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_VERSION | 0x000734d8 | 0x000002e0 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| IP |
|---|
| 114.114.114.114 |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| dns.msftncsi.com | A 131.107.255.255 | 131.107.255.255 |
| dns.msftncsi.com | AAAA fd3e:4f5a:5b81::1 | 131.107.255.255 |
No TCP connections recorded.
| Source | Source Port | Destination | Destination Port |
|---|---|---|---|
| 192.168.56.101 | 53179 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 49642 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 137 | 192.168.56.255 | 137 |
| 192.168.56.101 | 61714 | 114.114.114.114 | 53 |
| 192.168.56.101 | 56933 | 114.114.114.114 | 53 |
| 192.168.56.101 | 138 | 192.168.56.255 | 138 |
No HTTP requests performed.
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts
| Name | 93fec0b363a963fe_eula.2052.txt .exe |
|---|---|
| Filepath | C:\eula.2052.txt .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | f4c3a4eb77623d47e910d4dfe759c00a |
| SHA1 | 37bf5c4660814673f010a089ee143f1d38c264d5 |
| SHA256 | 93fec0b363a963fef4dc55a94d9ddea36b3fd82b51db5cea5f6fd8e52f187aa0 |
| CRC32 | 8CC8888C |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 987857c27c443f93_program files .exe |
|---|---|
| Filepath | C:\Program Files .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | d92c9b168686a38d1f64e454a7c13a08 |
| SHA1 | f709b560a8ff90984a5a52d5da40808b1f2d5aa2 |
| SHA256 | 987857c27c443f937983761f4b3cd4e0c2f50eb30c00a3de35498ea275603719 |
| CRC32 | 1B790351 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 8136e78b5a09fbe9_documents and settings .exe |
|---|---|
| Filepath | C:\Documents and Settings .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 1ddeffa7dbed41cce839dd55c72a11d0 |
| SHA1 | 5abe1267dfe37b67581d9e6c1df40fc5530770b0 |
| SHA256 | 8136e78b5a09fbe9a2315222805ea65466c17156c4ed0686400338c8ccbedb8b |
| CRC32 | E2A0B741 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 45520ab2b28db114_users .exe |
|---|---|
| Filepath | C:\Users .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 11cfb1b5ee482d2ee9f49551ff6111dd |
| SHA1 | a672745dc85e71e48afcb69dda2f0ba4fe2b97e7 |
| SHA256 | 45520ab2b28db114dffbfcbe100e44b3f6ff186915f63f12bcdb9638675890a5 |
| CRC32 | 4F667B5A |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 7ce061c5d1185999_install.ini .exe |
|---|---|
| Filepath | C:\install.ini .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | bfb8eaf4caccdd97dc125aca9960f5d0 |
| SHA1 | c289041822da96e9a02ac17868105c5a106864ad |
| SHA256 | 7ce061c5d11859999eea74769c40ed963185f713afb00c70bb1bf9cf201756e6 |
| CRC32 | E4D20F23 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 4e1920d930929ba9_$recycle.bin .exe |
|---|---|
| Filepath | C:\$Recycle.Bin .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) 1332 (0dfcccee2ce21f4ba754adb7ff091a4120729e533cfe01b16e8f9ea2d9415637.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 31e144244bbd493de5f941be35780654 |
| SHA1 | ae2bc2c91a487538fd554d720853474fb05d4d86 |
| SHA256 | 4e1920d930929ba9bee2208bb110a4cf32bdac7c220a138cac8fe08c7a4ddcf5 |
| CRC32 | A5673F24 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 0e66ea6f3bf07024_vc_red.cab .exe |
|---|---|
| Filepath | C:\VC_RED.cab .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | aa78c6ad33c516d2575610ff5ec10492 |
| SHA1 | 7bd6df5ef7f356ff7bf489369aa6d7a0f435d06b |
| SHA256 | 0e66ea6f3bf07024ced3ba8677d72b42623a1da2854b0aef007ef41e9bee5a45 |
| CRC32 | AE7EA1A2 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 8446a4b56760a260_programdata .exe |
|---|---|
| Filepath | C:\ProgramData .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | e2d6ca32f962f0febf667c06b7d1f028 |
| SHA1 | 47a0dd5a0dd5bf48826b4612a18b7dcfe204f396 |
| SHA256 | 8446a4b56760a260c0ec4d27669c475e8b280141250eaacc53a8509c922a324d |
| CRC32 | 5DD98E29 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 1480ea547da05ea9_pagefile.sys .exe |
|---|---|
| Filepath | C:\pagefile.sys .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | d16fbe94ed7c83bed27ae0db9cc8e406 |
| SHA1 | 9719e93c1514194aab5b77e6a7da2f1a8d7094c1 |
| SHA256 | 1480ea547da05ea91f12a9fc7b6519a78ae27308897b01059cdb4ebf1c5d4c3e |
| CRC32 | AB30024F |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 3ca9302502bd4e86_install.exe .exe |
|---|---|
| Filepath | C:\install.exe .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 23029a12da0c0b0357bb7b4faa675531 |
| SHA1 | 03f457d25a02e3fc457c7e5d0489f181335bed75 |
| SHA256 | 3ca9302502bd4e86b1e0e69970b5f315fc5fa4bf78f668eb8c1e10d42c1b389f |
| CRC32 | BC72B195 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | a5bb185a34c29507_vuxmqoevu .exe |
|---|---|
| Filepath | C:\vuxmqoevu .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 9b1dd17a1a190361f41a92f15f9787e8 |
| SHA1 | d9ae5f03ff29f577bf0a22a320dae0657b5dd8e0 |
| SHA256 | a5bb185a34c295078f2b0cdffb9b0d6b45a4c0fa40108502502a134db401bda3 |
| CRC32 | CE6E775E |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 9933f4e01e6dacbf_gcoxh .exe |
|---|---|
| Filepath | C:\gcoxh .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | a55a12f673a5440b1ee07f08af1f952f |
| SHA1 | 38c1c5fff12a8f2555097b120dad6b29713641a1 |
| SHA256 | 9933f4e01e6dacbf7f84d09797c068aef2ee01e7bbf6565ce3741fa90b9ba64b |
| CRC32 | C57909AC |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 466fec039591ef45_python27 .exe |
|---|---|
| Filepath | C:\Python27 .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 3c0096a7547d36a1671eab4c79626b5a |
| SHA1 | 531450813c6252934ee635ad11d4afb96d90bb69 |
| SHA256 | 466fec039591ef45702b6fc54bba2d40c91dcb6ccffed0901fa73a0be86730fd |
| CRC32 | 9EB12C4D |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 9934dc2e72bd0bf5_windows .exe |
|---|---|
| Filepath | C:\Windows .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 9f0ac385197672b112b618237243648c |
| SHA1 | 0110fdbad5de8291354c487a46e48c0bea4b56ed |
| SHA256 | 9934dc2e72bd0bf547611c306dd90df38a79c3de7e2a276dc0ebc8af4b2c4b1e |
| CRC32 | FAF932F9 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | f8d2c17bdf34ccfb_mira.h |
|---|---|
| Filepath | C:\ProgramData\Saaaalamm\Mira.h |
| Size | 136.7KB |
| Processes | 1332 (0dfcccee2ce21f4ba754adb7ff091a4120729e533cfe01b16e8f9ea2d9415637.exe) 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | cb4c442a26bb46671c638c794bf535af |
| SHA1 | 8a742d0b372f2ddd2d1fdf688c3c4ac7f9272abf |
| SHA256 | f8d2c17bdf34ccfb58070ac8b131a8d95055340101a329f9a7212ac5240d0c25 |
| CRC32 | AEE8DC88 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | c355cb45cd8bcd03_vc_red.msi .exe |
|---|---|
| Filepath | C:\VC_RED.MSI .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | c004cc91325c052bbea97e848a942059 |
| SHA1 | 1baf0d2600bf838f602e8c347e1a92c5b9ab7ded |
| SHA256 | c355cb45cd8bcd03c84cc75dbbca6937f7071f27c0a232488f920662345180c8 |
| CRC32 | 126634BE |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | a2b289d56c3819f2_globdata.ini .exe |
|---|---|
| Filepath | C:\globdata.ini .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 506a5fa2e8439416fef6941d6057b580 |
| SHA1 | bbf2aa13d9f3f540786f38d19bd3b136ba7c01d1 |
| SHA256 | a2b289d56c3819f2e89a1e188bea8cf6f8940e2c7f435cf9c07b5029e2287f31 |
| CRC32 | F84B4C33 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | b86b06f88eba3d17_vcredist.bmp .exe |
|---|---|
| Filepath | C:\vcredist.bmp .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 2e6d19fe6e01649ae30045e1dae51228 |
| SHA1 | e3706ce0e11b4e3d0ee3337d35ded783b023fc5e |
| SHA256 | b86b06f88eba3d17609a9b4fd55b8f8da4a554a853656803c3593ddc33196346 |
| CRC32 | 95F152AC |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 5ce05532b2a4c7de_khbcj.exe |
|---|---|
| Filepath | C:\ProgramData\khbcj.exe |
| Size | 258.4KB |
| Processes | 1332 (0dfcccee2ce21f4ba754adb7ff091a4120729e533cfe01b16e8f9ea2d9415637.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | a668d45c3056f5fc1752520490aa1765 |
| SHA1 | 39aa5e30548b14d49acc3fb31c1f742ab1f0a3c4 |
| SHA256 | 5ce05532b2a4c7deb17544e1b1d2461a3fcbc8880dddbe32668052638a941506 |
| CRC32 | 4C468515 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | eb23cde7cf118f41_recovery .exe |
|---|---|
| Filepath | C:\Recovery .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 75afa1b6118a5298f1e9ff2b5a4e43cb |
| SHA1 | c80e13378a00277e1bac5fe95e19085c1b80fddb |
| SHA256 | eb23cde7cf118f41e5cc4dd915df304efe8486dbbd40b10f1eb216f27e41911b |
| CRC32 | 94CE5C28 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | ed8978822270ac98_360downloads .exe |
|---|---|
| Filepath | C:\360Downloads .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | fecafa6d86702f297d5be856c724ac2c |
| SHA1 | 4667f603381fd53b6071cc6db20995c6450261ce |
| SHA256 | ed8978822270ac98f17b761ea59419c93831c82ccf444ace06e3c2bd41d7ea3f |
| CRC32 | 3BE0C81A |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | cf2a0dc131be54f9_perflogs .exe |
|---|---|
| Filepath | C:\PerfLogs .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 36f7926f465ad12fc03255b7a76a303e |
| SHA1 | 1cac1c891254b77828b40e4ba218e3432262092f |
| SHA256 | cf2a0dc131be54f900c832054ebb3f91e4de1ef908c267af3036cd599fb410e0 |
| CRC32 | BFF9CDB3 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | e7b7fdfa4ce81fd1_program files (x86) .exe |
|---|---|
| Filepath | C:\Program Files (x86) .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | ba57c5f869febb26107edb59a43ef32f |
| SHA1 | 5fdf148df5d02ebd374b5ef88e61fd321c9de2df |
| SHA256 | e7b7fdfa4ce81fd1b31e3ae4e70e1b720269f22aa4a047faa2908a9d57c5319a |
| CRC32 | 0C2840BE |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | e3b0c44298fc1c14_Mirad |
|---|---|
| Size | 0.0B |
| Type | empty |
| MD5 | d41d8cd98f00b204e9800998ecf8427e |
| SHA1 | da39a3ee5e6b4b0d3255bfef95601890afd80709 |
| SHA256 | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 |
| CRC32 | 00000000 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | e4b96b707620467b_install.res.2052.dll .exe |
|---|---|
| Filepath | C:\install.res.2052.dll .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 2394ea315ecdf8fd3f60004360a23025 |
| SHA1 | 8fb96fde278a90ddb877a10719b90d90fa095f00 |
| SHA256 | e4b96b707620467b4c8600ee45c58eb763f7383ca65fc0b6cb2b7abd59c1dc41 |
| CRC32 | 44BE6883 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |
| Name | 61e98b8bd4d07d01_system volume information .exe |
|---|---|
| Filepath | C:\System Volume Information .exe |
| Size | 395.2KB |
| Processes | 3052 (khbcj.exe) |
| Type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5 | 26dd91de4aa2b687dacb2827927fbced |
| SHA1 | ca7e913189430c2dbebdd0742dc158191b3f54bc |
| SHA256 | 61e98b8bd4d07d01717ee44e068418557122a2148b2ec15fc1db706ee29148c2 |
| CRC32 | 15B9BB76 |
| ssdeep | None |
| Yara | None matched |
| VirusTotal | Search for analysis |