| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| McAfee | Artemis!07F2151979B2 | 20200708 | 6.0.6.653 |
| Alibaba | TrojanSpy:Win32/Injector.9118b8c2 | 20190527 | 0.3.0.5 |
| Baidu | 20190318 | 1.0.0.2 | |
| Avast | Script:SNH-gen [Trj] | 20200708 | 18.4.3895.0 |
| Kingsoft | 20200708 | 2013.8.14.323 | |
| Tencent | Msil.Trojan-spy.Noon.Iis | 20200708 | 1.0.0.1 |
| CrowdStrike | win/malicious_confidence_80% (W) | 20190702 | 1.0 |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1620125341.517124 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
|
1620125341.533124 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
| suspicious_features | POST method with no referer header | suspicious_request | POST https://livdecor.pt/work/Panel/index.php | ||||||
| request | GET http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
| request | GET http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D |
| request | GET http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D |
| request | POST https://livdecor.pt/work/Panel/index.php |
| request | POST https://livdecor.pt/work/Panel/index.php |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1620125342.564124 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |
| entropy | 7.575564905408762 | section | {'size_of_data': '0x0008ca00', 'virtual_address': '0x000c4000', 'entropy': 7.575564905408762, 'name': '.rsrc', 'virtual_size': '0x0008c8f4'} | description | A section with a high entropy has been found | |||||||||
| entropy | 0.4119370194068107 | description | Overall entropy of this PE file is high | |||||||||||
| buffer | Buffer with sha1: 2de30e293fc192df976032c0b64e8134b5aa4b22 |
| host | 172.217.24.14 | |||