| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| Alibaba | TrojanDropper:Win32/Agentoit.c0fea914 | 20190527 | 0.3.0.5 |
| CrowdStrike | win/malicious_confidence_70% (W) | 20190702 | 1.0 |
| Baidu | 20190318 | 1.0.0.2 | |
| Avast | Win32:Malware-gen | 20201210 | 21.1.5827.0 |
| Tencent | 20201211 | 1.0.0.1 | |
| Kingsoft | 20201211 | 2017.9.26.565 | |
| McAfee | Artemis!2F9186916440 | 20201211 | 6.0.6.653 |
| description | 2f918691644023afcfc516c442c1f57e.exe tried to sleep 176 seconds, actually delayed analysis time by 176 seconds | |||
| file | C:\Users\Administrator.Oskar-PC\plasrv\cipher.exe |
| file | C:\Users\Administrator.Oskar-PC\plasrv\plasrv.vbs |
| entropy | 7.905473030205145 | section | {'size_of_data': '0x00062200', 'virtual_address': '0x000c4000', 'entropy': 7.905473030205145, 'name': '.rsrc', 'virtual_size': '0x00062120'} | description | A section with a high entropy has been found | |||||||||
| entropy | 0.32831451275616896 | description | Overall entropy of this PE file is high | |||||||||||
| buffer | Buffer with sha1: 95d0df073056e260fea2c40711269fdcca9fdaaa |
| host | 172.217.24.14 | |||
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\plasrv.url |