| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| Alibaba | Trojan:Win32/AutoitCrypt.180 | 20190527 | 0.3.0.5 |
| Avast | AutoIt:Injector-JF [Trj] | 20201210 | 21.1.5827.0 |
| Baidu | 20190318 | 1.0.0.2 | |
| Kingsoft | Win32.Troj.Undef.(kcloud) | 20201211 | 2017.9.26.565 |
| McAfee | Artemis!2A072BE96423 | 20201211 | 6.0.6.653 |
| Tencent | Malware.Win32.Gencirc.10b639e7 | 20201211 | 1.0.0.1 |
| CrowdStrike | win/malicious_confidence_100% (W) | 20190702 | 1.0 |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1619340505.54725 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
|
1619340505.54725 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
| domain | rem-pounds.ddns.net |
| description | 2a072be964231aaddea5bca6590b88fe.exe tried to sleep 308 seconds, actually delayed analysis time by 308 seconds | |||
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WMPDMC.lnk |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\klist\drvinst.exe.bat |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WMPDMC.lnk |
| file | C:\Users\Public\Desktop\Google Chrome.lnk |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\klist\drvinst.exe.bat |
| process | 2a072be964231aaddea5bca6590b88fe.exe |
| buffer | Buffer with sha1: 6814db9bf5ba7822eda634d228c3f1c1bb18897b |
| buffer | Buffer with sha1: 9e1aaa3d54f5452f0460ed392e8a988af809a937 |
| host | 172.217.24.14 | |||
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WMPDMC.lnk |