| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| Baidu | 20190318 | 1.0.0.2 | |
| Avast | Win32:Kryptik-PTA [Trj] | 20210223 | 21.1.5827.0 |
| Alibaba | Trojan:Win32/Emotet.72b8de06 | 20190527 | 0.3.0.5 |
| Kingsoft | 20210224 | 2017.9.26.565 | |
| McAfee | Emotet-FRV!08CC65DABC7B | 20210223 | 6.0.6.653 |
| Tencent | Malware.Win32.Gencirc.10cdee42 | 20210223 | 1.0.0.1 |
| CrowdStrike | win/malicious_confidence_100% (W) | 20210203 | 1.0 |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1619159905.656626 GetComputerNameA |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
| packer | Armadillo v1.71 |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1619159906.078626 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |
| entropy | 7.427959110276362 | section | {'size_of_data': '0x00033000', 'virtual_address': '0x0003d000', 'entropy': 7.427959110276362, 'name': '.rsrc', 'virtual_size': '0x00032230'} | description | A section with a high entropy has been found | |||||||||
| entropy | 0.4766355140186916 | description | Overall entropy of this PE file is high | |||||||||||
| process | eappcfg.exe |
| cmdline | C:\Windows\SysWOW64\tasklist\eappcfg.exe |
| host | 172.217.24.14 | |||
| host | 181.30.61.163 | |||
| host | 209.126.6.222 | |||
| host | 5.153.250.14 | |||
| service_name | eappcfg | service_path | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\"C:\Windows\SysWOW64\tasklist\eappcfg.exe" | ||||||