Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 2, 2024, 2:32 p.m. | Oct. 2, 2024, 2:35 p.m. |
-
SPOOF.exe "C:\Users\test22\AppData\Local\Temp\SPOOF.exe"
2544
Name | Response | Post-Analysis Lookup |
---|---|---|
api3.ruikeyz.com |
CNAME
u52h4gvr.waf.dnsv.com.cn
|
165.154.119.234 |
api2.ruikeyz.com |
CNAME
2fxy4v57.waf.dnsv.com.cn
|
165.154.8.83 |
api.ruikeyz.com | 139.99.30.177 |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
packer | Armadillo v1.71 |
resource name | TEXTINCLUDE |
suspicious_features | POST method with no referer header | suspicious_request | POST http://api.ruikeyz.com/NetVer/webapi | ||||||
suspicious_features | POST method with no referer header | suspicious_request | POST http://api2.ruikeyz.com/NetVer/webapi |
request | POST http://api.ruikeyz.com/NetVer/webapi |
request | POST http://api2.ruikeyz.com/NetVer/webapi |
request | POST http://api.ruikeyz.com/NetVer/webapi |
request | POST http://api2.ruikeyz.com/NetVer/webapi |
name | TEXTINCLUDE | language | LANG_CHINESE | filetype | C source, ASCII text, with CRLF line terminators | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00ae4dac | size | 0x00000151 | ||||||||||||||||||
name | TEXTINCLUDE | language | LANG_CHINESE | filetype | C source, ASCII text, with CRLF line terminators | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00ae4dac | size | 0x00000151 | ||||||||||||||||||
name | TEXTINCLUDE | language | LANG_CHINESE | filetype | C source, ASCII text, with CRLF line terminators | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00ae4dac | size | 0x00000151 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00ae7d44 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00ae7d44 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00ae7d44 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00ae7d44 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00ae7d44 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00ae7d44 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00ae7d44 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00ae7d44 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00ae7d44 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00ae7d44 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00ae7d44 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00ae7d44 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00ae7d44 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00ae7d44 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00ae7d44 | size | 0x00000144 | ||||||||||||||||||
name | RT_MENU | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aec4cc | size | 0x00000284 | ||||||||||||||||||
name | RT_MENU | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aec4cc | size | 0x00000284 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aed714 | size | 0x0000018c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aed714 | size | 0x0000018c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aed714 | size | 0x0000018c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aed714 | size | 0x0000018c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aed714 | size | 0x0000018c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aed714 | size | 0x0000018c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aed714 | size | 0x0000018c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aed714 | size | 0x0000018c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aed714 | size | 0x0000018c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aed714 | size | 0x0000018c | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee15c | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee15c | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee15c | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee15c | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee15c | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee15c | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee15c | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee15c | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee15c | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee15c | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee15c | size | 0x00000024 | ||||||||||||||||||
name | RT_GROUP_CURSOR | language | LANG_CHINESE | filetype | Lotus unknown worksheet or configuration, revision 0x2 | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee1e4 | size | 0x00000022 | ||||||||||||||||||
name | RT_GROUP_CURSOR | language | LANG_CHINESE | filetype | Lotus unknown worksheet or configuration, revision 0x2 | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee1e4 | size | 0x00000022 | ||||||||||||||||||
name | RT_GROUP_CURSOR | language | LANG_CHINESE | filetype | Lotus unknown worksheet or configuration, revision 0x2 | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee1e4 | size | 0x00000022 | ||||||||||||||||||
name | RT_GROUP_CURSOR | language | LANG_CHINESE | filetype | Lotus unknown worksheet or configuration, revision 0x2 | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee1e4 | size | 0x00000022 | ||||||||||||||||||
name | RT_GROUP_CURSOR | language | LANG_CHINESE | filetype | Lotus unknown worksheet or configuration, revision 0x2 | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee1e4 | size | 0x00000022 | ||||||||||||||||||
name | RT_GROUP_CURSOR | language | LANG_CHINESE | filetype | Lotus unknown worksheet or configuration, revision 0x2 | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee1e4 | size | 0x00000022 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee230 | size | 0x00000014 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee230 | size | 0x00000014 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00aee230 | size | 0x00000014 |
section | {u'size_of_data': u'0x00957000', u'virtual_address': u'0x00131000', u'entropy': 7.0284472384314425, u'name': u'.rdata', u'virtual_size': u'0x009565c8'} | entropy | 7.02844723843 | description | A section with a high entropy has been found | |||||||||
entropy | 0.87454279444 | description | Overall entropy of this PE file is high |
process | spoof.exe |
dead_host | 51.79.193.76:80 |
Bkav | W32.AIDetectMalware |
Lionic | Trojan.Win32.Generic.lwoF |
tehtris | Generic.Malware |
Cynet | Malicious (score: 100) |
Skyhigh | BehavesLike.Win32.Generic.vc |
Cylance | Unsafe |
CrowdStrike | win/malicious_confidence_70% (D) |
K7GW | Trojan ( 005246d51 ) |
K7AntiVirus | Trojan ( 005246d51 ) |
Symantec | ML.Attribute.HighConfidence |
Elastic | malicious (high confidence) |
ESET-NOD32 | a variant of Win32/Packed.FlyStudio.AA potentially unwanted |
APEX | Malicious |
Avast | Win32:Malware-gen |
ClamAV | Win.Malware.Genkryptik-10034801-0 |
Rising | Trojan.MalCert!1.E0C6 (CLASSIC) |
DrWeb | Trojan.DownLoad4.15026 |
McAfeeD | Real Protect-LS!801832B0EB4D |
Trapmine | suspicious.low.ml.score |
Sophos | Mal/Generic-S |
SentinelOne | Static AI - Malicious PE |
FireEye | Generic.mg.801832b0eb4d855a |
Antiy-AVL | RiskWare/Win32.FlyStudio.a |
Kingsoft | Win32.Troj.Unknown.a |
Gridinsoft | Trojan.Win32.Packed.sa |
Xcitium | TrojWare.Win32.Agent.OSCF@5rs7jr |
Microsoft | Trojan:Win32/Emotet!ml |
GData | Win32.Trojan.PSE.11U3QNE |
Varist | W32/Agent.EW.gen!Eldorado |
AhnLab-V3 | Malware/Gen.Generic.C1027866 |
Acronis | suspicious |
McAfee | Artemis!801832B0EB4D |
DeepInstinct | MALICIOUS |
Malwarebytes | Generic.Malware.AI.DDS |
Ikarus | Trojan.Win32.Agent |
MaxSecure | Dropper.Dinwod.frindll |
Fortinet | W32/CoinMiner.PHP!tr |
AVG | Win32:Malware-gen |
Paloalto | generic.ml |
alibabacloud | Virus:Win/KillFiles.AZ |