Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | June 25, 2021, 3:15 p.m. | June 25, 2021, 3:27 p.m. |
-
download.aspx "C:\Users\test22\AppData\Local\Temp\download.aspx"
2236 -
explorer.exe C:\Windows\Explorer.EXE
1848
Name | Response | Post-Analysis Lookup |
---|---|---|
jsy.newitboy.com | 112.126.77.190 |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | .gfids |
section | .giats |
resource name | AFX_DIALOG_LAYOUT |
resource name | BINARY |
request | GET http://jsy.newitboy.com/wllinfo/newoemjsy/oemtianm.txt |
name | AFX_DIALOG_LAYOUT | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00428048 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00428048 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00428048 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00428048 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00428048 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00428048 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00428048 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00428048 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00428048 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00428048 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00428048 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00428048 | size | 0x00000002 | ||||||||||||||||||
name | BINARY | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0169c97c | size | 0x0002a800 | ||||||||||||||||||
name | BINARY | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0169c97c | size | 0x0002a800 | ||||||||||||||||||
name | BINARY | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0169c97c | size | 0x0002a800 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c8308 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c8308 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c8308 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c8308 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c8308 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c8308 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c8308 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c8308 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c8308 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c8308 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c8308 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c8308 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c8308 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c8308 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c8308 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c8308 | size | 0x00000134 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c84f4 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c84f4 | size | 0x00000144 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | dBase III DBT, version number 0, next free block index 40 | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016c8638 | size | 0x00010828 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016d9220 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016d9220 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016d9220 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016d9220 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016d9220 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016d9220 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016d9220 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016d9220 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016d9220 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016d9220 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016d9220 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016d9220 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016d9220 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016d9220 | size | 0x00000034 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016da7cc | size | 0x0000053e | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x016da7cc | size | 0x0000053e |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\MiniThunderPlatform.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\ThunderFW.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\msvcr71.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\QEMU\libssp-0.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\PECMD.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\bcdedit.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\QEMU\QEMU.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\XLBugReport.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\zlib1.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\minizip.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\7z.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\GDisk.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\xldl.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\msvcp71.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\bootsect.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\fbinst.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\dl_peer_id.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\Etfsboot.com |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\oscdimg.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\QEMU\libpdcurses.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\download_engine.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\atl71.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\XLBugHandler.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\MiniTPFw.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\QEMU\SDL.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\QEMU\libz-1.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\UltraISO.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\bootice.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\msvcr71.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\bootmgr.exe.mui |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\bootsect.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\xldl.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\atl71.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\dl_peer_id.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\QEMU\libssp-0.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\MiniThunderPlatform.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\bootice.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\download_engine.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\msvcp71.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\bcdedit.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\minizip.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\XLBugHandler.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\zlib1.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\QEMU\libz-1.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\XLBugReport.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\QEMU\libpdcurses.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\MiniTPFw.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\GDisk.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\UltraISO.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\oscdimg.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\QEMU\QEMU.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\bootmgfw.efi.mui |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\7z.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\QEMU\SDL.dll |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\download\ThunderFW.exe |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\fbinst.exe |
wmi | SELECT * FROM Win32_OperatingSystem WHERE (Csdversion IS NOT NULL) |
wmi | SELECT * FROM Win32_BaseBoard WHERE (Product IS NOT NULL) |
wmi | SELECT * FROM Win32_SystemEnclosure |
wmi | SELECT * FROM Win32_VideoController WHERE (description IS NOT NULL) |
wmi | SELECT * FROM Win32_Processor WHERE (Name IS NOT NULL) |
wmi | SELECT * FROM Win32_ComputerSystem WHERE (Model IS NOT NULL) |
wmi | SELECT * FROM Win32_OperatingSystem WHERE (Caption IS NOT NULL) |
section | {u'size_of_data': u'0x012b4600', u'virtual_address': u'0x00427000', u'entropy': 7.998913812335768, u'name': u'.rsrc', u'virtual_size': u'0x012b4410'} | entropy | 7.99891381234 | description | A section with a high entropy has been found | |||||||||
entropy | 0.813053167781 | description | Overall entropy of this PE file is high |
wmi | SELECT * FROM Win32_Processor WHERE (Name IS NOT NULL) |
wmi | SELECT * FROM Win32_ComputerSystem WHERE (Model IS NOT NULL) |
file | C:\Users\test22\AppData\Local\Temp\0l50AsnmYC\tools\PECMD.exe |
K7AntiVirus | Riskware ( 0040eff71 ) |
K7GW | Riskware ( 0040eff71 ) |
APEX | Malicious |
Avast | FileRepMalware |
Kaspersky | HEUR:Trojan.Win32.Fsysna.gen |
McAfee-GW-Edition | Artemis |
Sophos | Generic ML PUA (PUA) |
AegisLab | Trojan.Win32.Fsysna.4!c |
AhnLab-V3 | Malware/Gen.Generic.C4212733 |
McAfee | Artemis!465403A9D41D |
VBA32 | BScope.Trojan.Fsysna |
Tencent | Win32.Trojan.Fsysna.Pbyy |
AVG | FileRepMalware |