| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| McAfee | Artemis!027CB9F54905 | 20201010 | 6.0.6.653 |
| Alibaba | 20190527 | 0.3.0.5 | |
| Baidu | 20190318 | 1.0.0.2 | |
| Avast | 20201010 | 18.4.3895.0 | |
| Kingsoft | 20201010 | 2013.8.14.323 | |
| CrowdStrike | 20190702 | 1.0 |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1620119655.250567 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
|
1620119675.797567 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
| resource name | IMAGE |
| suspicious_features | POST method with no referer header | suspicious_request | POST https://gnapi.com/restapi | ||||||
| request | GET http://apps.identrust.com/roots/dstrootcax3.p7c |
| request | GET http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
| request | GET http://crl.identrust.com/DSTROOTCAX3CRL.crl |
| request | GET http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgRxed%2BT0HpJ1CHMtyKy5e9ySQ%3D%3D |
| request | GET http://fs0.gamenet.ru/installers/qgna/reborn/live/reborn_inner.exe |
| request | POST https://gnapi.com/restapi |
| request | POST https://gnapi.com/restapi |
| domain | gnlogin.ru | description | Russian Federation domain TLD | ||||||
| domain | fs0.gamenet.ru | description | Russian Federation domain TLD | ||||||
| wmi | |
| wmi | <INVALID POINTER> |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1620119623.235567 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |
| entropy | 7.103327529965888 | section | {'size_of_data': '0x0003d200', 'virtual_address': '0x0004c000', 'entropy': 7.103327529965888, 'name': '.rsrc', 'virtual_size': '0x0003d12c'} | description | A section with a high entropy has been found | |||||||||
| entropy | 0.4453551912568306 | description | Overall entropy of this PE file is high | |||||||||||
| host | 172.217.24.14 | |||
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\Blob |
| FireEye | Generic.mg.027cb9f549052c73 |
| CAT-QuickHeal | PUA.RiskwareRI.S7394825 |
| McAfee | Artemis!027CB9F54905 |
| Cylance | Unsafe |
| Zillya | Trojan.Bublik.Win32.17657 |
| K7AntiVirus | Unwanted-Program ( 005603311 ) |
| K7GW | Unwanted-Program ( 005603311 ) |
| Cybereason | malicious.6cd5d7 |
| Invincea | Generic PUA JE (PUA) |
| Cyren | W32/S-d505b73b!Eldorado |
| Paloalto | generic.ml |
| Kaspersky | not-a-virus:HEUR:Downloader.Win32.Generic |
| Comodo | TrojWare.Win32.Agent.KDV@4x3daa |
| VIPRE | Trojan.Win32.Generic!BT |
| McAfee-GW-Edition | Artemis |
| Sophos | Generic PUA JE (PUA) |
| Ikarus | Trojan.SuspectCRC |
| Jiangmin | TrojanDownloader.Generic.aiis |
| Webroot | W32.Malware.Gen |
| ZoneAlarm | not-a-virus:HEUR:Downloader.Win32.Generic |
| AhnLab-V3 | PUP/Win32.Helper.R250104 |
| MAX | malware (ai score=95) |
| VBA32 | Downloader.Soft32 |
| Malwarebytes | Trojan.Downloader |
| ESET-NOD32 | a variant of Win32/Syncopate.C potentially unsafe |
| Yandex | PUA.Downloader! |
| SentinelOne | DFI - Suspicious PE |
| eGambit | Unsafe.AI_Score_53% |
| Fortinet | Riskware/Syncopate |
| Qihoo-360 | Win32/Virus.Downloader.c27 |
No hosts contacted.
| Source | Source Port | Destination | Destination Port |
|---|---|---|---|
| 192.168.56.101 | 49184 | 123.52.189.35 www.download.windowsupdate.com | 80 |
| 192.168.56.101 | 49181 | 192.35.177.64 apps.identrust.com | 80 |
| 192.168.56.101 | 49185 | 23.218.94.25 crl.identrust.com | 80 |
| 192.168.56.101 | 49186 | 23.32.248.65 r3.o.lencr.org | 80 |
| 192.168.56.101 | 49178 | 31.25.227.143 gnlogin.ru | 443 |
| 192.168.56.101 | 49187 | 31.25.227.152 gnapi.com | 443 |
| 192.168.56.101 | 49190 | 31.25.227.152 gnapi.com | 443 |
| 192.168.56.101 | 49192 | 31.25.231.2 fs0.gamenet.ru | 80 |
| Source | Source Port | Destination | Destination Port |
|---|---|---|---|
| 192.168.56.101 | 50534 | 114.114.114.114 | 53 |
| 192.168.56.101 | 51963 | 114.114.114.114 | 53 |
| 192.168.56.101 | 53657 | 114.114.114.114 | 53 |
| 192.168.56.101 | 54991 | 114.114.114.114 | 53 |
| 192.168.56.101 | 56539 | 114.114.114.114 | 53 |
| 192.168.56.101 | 56743 | 114.114.114.114 | 53 |
| 192.168.56.101 | 58070 | 114.114.114.114 | 53 |
| 192.168.56.101 | 60221 | 114.114.114.114 | 53 |
| 192.168.56.101 | 61680 | 114.114.114.114 | 53 |
| 192.168.56.101 | 62318 | 114.114.114.114 | 53 |
| 192.168.56.101 | 65004 | 114.114.114.114 | 53 |
| 192.168.56.101 | 137 | 192.168.56.255 | 137 |
| 192.168.56.101 | 138 | 192.168.56.255 | 138 |
| 192.168.56.101 | 49235 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 49713 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 50568 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 51808 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 53380 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 54260 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 56804 | 224.0.0.252 | 5355 |
| URI | Data |
|---|---|
| http://crl.identrust.com/DSTROOTCAX3CRL.crl | GET /DSTROOTCAX3CRL.crl HTTP/1.1 Connection: Keep-Alive Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: crl.identrust.com |
| http://apps.identrust.com/roots/dstrootcax3.p7c | GET /roots/dstrootcax3.p7c HTTP/1.1 Connection: Keep-Alive Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: apps.identrust.com |
| http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1 Cache-Control: max-age = 3600 Connection: Keep-Alive Accept: */* If-Modified-Since: Wed, 03 Mar 2021 06:32:16 GMT If-None-Match: "0d8f4f3f6fd71:0" User-Agent: Microsoft-CryptoAPI/6.1 Host: www.download.windowsupdate.com |
| http://fs0.gamenet.ru/installers/qgna/reborn/live/reborn_inner.exe | GET /installers/qgna/reborn/live/reborn_inner.exe HTTP/1.1 Accept: */* User-Agent: Installer (compatible; MSIE 6.0b; Windows NT 5.0; .NET CLR 1.0.2914) Host: fs0.gamenet.ru Connection: Keep-Alive |
| http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgRxed%2BT0HpJ1CHMtyKy5e9ySQ%3D%3D | GET /MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgRxed%2BT0HpJ1CHMtyKy5e9ySQ%3D%3D HTTP/1.1 Connection: Keep-Alive Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: r3.o.lencr.org |
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts