分析类型 | 开始时间 | 结束时间 | 持续时间 | 分析引擎版本 |
---|---|---|---|---|
FILE | 2022-05-28 00:43:45 | 2022-05-28 00:44:19 | 34 秒 | 1.4-Maldun |
虚拟机机器名 | 标签 | 虚拟机管理 | 开机时间 | 关机时间 |
---|---|---|---|---|
win7-sp1-x64-shaapp03-1 | win7-sp1-x64-shaapp03-1 | KVM | 2022-05-28 00:43:46 | 2022-05-28 00:44:23 |
魔盾分数 |
---|
10.0恶意的 |
文件名 | blyat.exe |
---|---|
文件大小 | 662528 字节 |
文件类型 | PE32 executable (GUI) Intel 80386, for MS Windows |
CRC32 | 24EAE8A2 |
MD5 | bc7fc83ce9762eb97dc28ed1b79a0a10 |
SHA1 | 54df8f078ea7d43b25daea54e4f0a30da530289e |
SHA256 | fea935d2d0fb1abadb900f009b4c40bb8a91fd9e25cc76ed4f9dae08960566d5 |
SHA512 | 3b83de962fe1eae9362e659bd5efa61598da94983d0889e0859fd3488444e4d75ad295dc8089ef1ff37db0ce0bc3a2cb1e42f7e038d7b7d907d63e1633541ff2 |
Ssdeep | 12288:egJbjIuu9HRr/nJIGaINK/lGRgOUqmq9kR6lhKXghaQlwt2NYtahQjqOeb:egKJRr7NK/cRgOnmq9g61Xm2z |
PEiD | 无匹配 |
Yara |
|
VirusTotal |
VirusTotal链接 VirusTotal扫描时间: 2018-12-17 17:34:55 扫描结果: 45/68 |
IP地址 | 端口 |
---|---|
23.33.33.178 | 80 |
IP地址 | 端口 |
---|---|
192.168.122.1 | 53 |
URL | HTTP数据 |
---|---|
http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip | GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1 Accept: */* If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT User-Agent: IPM Host: acroipm.adobe.com Connection: Keep-Alive Cache-Control: no-cache |
初始地址 | 0x00400000 |
---|---|
入口地址 | 0x00401000 |
声明校验值 | 0x000a976a |
实际校验值 | 0x000a976a |
最低操作系统版本要求 | 5.1 |
编译时间 | 2018-06-12 21:40:25 |
载入哈希 | 1d4128d8d965e4b46d890fb87b60b15c |
图标 | |
图标精确哈希值 | fb1093bdb81a01abef2584f71d265f39 |
图标相似性哈希值 | 3d7c03120ff255d136b551b9ed191d74 |
LegalCopyright: | Copyright\xc21988-2018 Kingsoft Corporation. All rights reserved. |
MIMEType: | |
InternalName: | ksolaunch |
FileVersion: | 10,1,0,7671 |
CompanyName: | Zhuhai Kingsoft Office Software Co.,Ltd |
ProductName: | WPS Office |
ProductVersion: | 10,1,0,7671 |
FileDescription: | WPS Office |
OriginalFilename: | ksolaunch.exe |
Translation: | 0x0000 0x04b0 |
名称 | 虚拟地址 | 虚拟大小 | 原始数据大小 | 特征 | 熵(Entropy) |
---|---|---|---|---|---|
0x00001000 | 0x00069000 | 0x0002f000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 8.00 | |
0x0006a000 | 0x00023000 | 0x0000d000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 8.00 | |
0x0008d000 | 0x00024000 | 0x0000e200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 8.00 | |
.rsrc | 0x000b1000 | 0x00005000 | 0x00004200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 5.00 |
0x000b6000 | 0x00008000 | 0x00005000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 7.99 | |
0x000be000 | 0x00006000 | 0x00000000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 0.00 | |
.data | 0x000c4000 | 0x0004c000 | 0x0004b200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 7.92 |
.adata | 0x00110000 | 0x00001000 | 0x00000000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 0.00 |
.vmp0 | 0x00111000 | 0x00002e5f | 0x00003000 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ | 6.67 |
.reloc | 0x00114000 | 0x00000064 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ | 1.50 |
名称 | 偏移量 | 大小 | 语言 | 子语言 | 熵(Entropy) | 文件类型 |
---|---|---|---|---|---|---|
RT_ICON | 0x000b47e0 | 0x00000468 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 4.65 | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000b47e0 | 0x00000468 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 4.65 | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000b47e0 | 0x00000468 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 4.65 | GLS_BINARY_LSB_FIRST |
RT_GROUP_ICON | 0x000b4c48 | 0x00000030 | LANG_CHINESE | SUBLANG_CHINESE_SIMPLIFIED | 2.46 | MS Windows icon resource - 3 icons, 48x48 |
RT_VERSION | 0x000b4c78 | 0x0000036c | LANG_ENGLISH | SUBLANG_ENGLISH_US | 3.51 | data |
RT_MANIFEST | 0x000b4fe4 | 0x0000015a | LANG_ENGLISH | SUBLANG_ENGLISH_US | 4.80 | ASCII text, with CRLF line terminators |