特征低危险等级 中危险等级 高危险等级文件已被至少一个VirusTotal上的反病毒引擎检测为病毒
Cylance: Unsafe
WhiteArmor: Malware.HighConfidence
二进制文件可能包含加密或压缩数据
section: name: , entropy: 8.00, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x000dec00, virtual_size: 0x00254000
section: name: , entropy: 8.00, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00016200, virtual_size: 0x0006f000
section: name: , entropy: 7.98, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00008000, virtual_size: 0x00223000
section: name: .rsrc, entropy: 7.18, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00022000, virtual_size: 0x000a3000
section: name: .data, entropy: 6.97, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00019000, virtual_size: 0x00019000
异常的二进制特征
anomaly: Found duplicated section names
anomaly: Entrypoint of binary points to a non-executable code section
运行截图     
|