分析类型 | 开始时间 | 结束时间 | 持续时间 | 分析引擎版本 |
---|---|---|---|---|
FILE | 2024-04-23 13:58:47 | 2024-04-23 14:01:04 | 137 秒 | 1.4-Maldun |
虚拟机机器名 | 标签 | 虚拟机管理 | 开机时间 | 关机时间 |
---|---|---|---|---|
win7-sp1-x64-shaapp03-1 | win7-sp1-x64-shaapp03-1 | KVM | 2024-04-23 13:58:50 | 2024-04-23 14:01:06 |
魔盾分数 |
---|
7.125恶意的 |
文件名 | MuuXop.exe |
---|---|
文件大小 | 14371344 字节 |
文件类型 | PE32+ executable (GUI) x86-64, for MS Windows |
CRC32 | C952C087 |
MD5 | 9e76a96c6320842c49385c5c95abed5d |
SHA1 | 822dd3bf7d84aae6e93ef615d7943597be7aca49 |
SHA256 | e178bc2bbba202092a44f6018c0d9a0a444e79ebdcee3d90729a8013acfbda3a |
SHA512 | 79141981021d30ef4c2a510da5357cdd1761ea9f14f735a1f56c09cc996ea7348bfa0418807d09aee3ebadc5287b3737f9cc59d0a4a13c9665bf2e192b8625a1 |
Ssdeep | 196608:5LchDWjyFhMLYmYFyeS4gzs8Lj6XeLMlQeuLIGzYR6REaW/KPZYxDj69B9:5kDWWFCIhStI8LSeLMKt/w67WkWj69B9 |
PEiD | 无匹配 |
Yara |
|
VirusTotal | VirusTotal查询失败 |
直接访问 | IP地址 | 国家名 |
---|---|---|
是 | 103.230.14.225 | unknown |
是 | 103.251.113.36 | Hong Kong |
是 | 185.240.102.74 | unknown |
是 | 51.222.31.217 | United Kingdom |
是 | 51.38.37.194 | United Kingdom |
IP地址 | 端口 |
---|---|
103.251.113.36 | 3333 |
23.219.38.35 | 80 |
IP地址 | 端口 |
---|---|
192.168.122.1 | 53 |
URL | HTTP数据 |
---|---|
http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip | GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1 Accept: */* If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT User-Agent: IPM Host: acroipm.adobe.com Connection: Keep-Alive Cache-Control: no-cache |
源地址 | 目标地址 | ICMP类型 | ICMP数据 |
---|---|---|---|
192.168.122.201 | 103.230.14.225 | 8 | \x1133w |
103.230.14.225 | 192.168.122.201 | 0 | \x1133w |
192.168.122.201 | 103.251.113.36 | 8 | \x1133w |
103.251.113.36 | 192.168.122.201 | 0 | \x1133w |
192.168.122.201 | 185.240.102.74 | 8 | \x1133w |
185.240.102.74 | 192.168.122.201 | 0 | \x1133w |
192.168.122.201 | 51.222.31.217 | 8 | \x1133w |
51.222.31.217 | 192.168.122.201 | 0 | \x1133w |
192.168.122.201 | 51.38.37.194 | 8 | \x1133w |
51.38.37.194 | 192.168.122.201 | 0 | \x1133w |
初始地址 | 0x140000000 |
---|---|
入口地址 | 0x14151d058 |
声明校验值 | 0x00dba938 |
实际校验值 | 0x00dbd3d3 |
最低操作系统版本要求 | 6.0 |
编译时间 | 2024-04-20 22:09:04 |
载入哈希 | 22402abe221b6efa466ca4190864858f |
名称 | 虚拟地址 | 虚拟大小 | 原始数据大小 | 特征 | 熵(Entropy) |
---|---|---|---|---|---|
0x00001000 | 0x000f72e0 | 0x00084a00 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ | 7.98 | |
0x000f9000 | 0x0004e824 | 0x00026200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 7.96 | |
0x00148000 | 0x0000a49c | 0x00000a00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 7.74 | |
0x00153000 | 0x00009798 | 0x00005c00 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 7.68 | |
0x0015d000 | 0x0000015c | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 3.40 | |
0x0015e000 | 0x000001e8 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 4.78 | |
0x0015f000 | 0x00000e38 | 0x00000800 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ | 7.65 | |
0x00160000 | 0x00001000 | 0x00000400 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 3.30 | |
0x00161000 | 0x00001000 | 0x00000200 | IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 0.28 | |
0x00162000 | 0x00001000 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 4.76 | |
0x00163000 | 0x013ba000 | 0x00000000 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 0.00 | |
0x0151d000 | 0x00d01e00 | 0x00d01e00 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ | 7.95 | |
0x0221f000 | 0x00001000 | 0x00000010 | IMAGE_SCN_MEM_READ | 2.35 |
名称 | 偏移量 | 大小 | 语言 | 子语言 | 熵(Entropy) | 文件类型 |
---|---|---|---|---|---|---|
RT_MANIFEST | 0x00162058 | 0x00000188 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 4.90 | XML 1.0 document text |