| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| McAfee | RDN/Generic.dx | 20200823 | 6.0.6.653 |
| Alibaba | Trojan:Win32/Ymacco.856386cf | 20190527 | 0.3.0.5 |
| Baidu | 20190318 | 1.0.0.2 | |
| Avast | Win32:Malware-gen | 20200823 | 18.4.3895.0 |
| Tencent | Win32.Trojan.Crypt.Ljui | 20200824 | 1.0.0.1 |
| Kingsoft | 20200824 | 2013.8.14.323 | |
| CrowdStrike | win/malicious_confidence_60% (W) | 20190702 | 1.0 |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1619359828.178876 IsDebuggerPresent |
failed | 0 | 0 | |
|
1619359828.209876 IsDebuggerPresent |
failed | 0 | 0 |
| pdb_path | D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb |
| section | .gfids |
| resource name | PNG |
| domain | aashkanani22.ddns.net |
| description | RegSvcs.exe tried to sleep 168 seconds, actually delayed analysis time by 168 seconds | |||
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\15755881\pchnkplsh.docx |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\15755881\pcuv.docx |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\15755881\xtuwelwmkn.docx |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\15755881\bcghe.ppt |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\15755881\ouqvuga.pdf |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\15755881\cwkx.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\15755881\rpjuoi.pif |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\15755881\xfjbgtoao.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\15755881\owlwssmqgt.vbs |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\15755881\rpjuoi.pif |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\15755881\rpjuoi.pif |
| process | regsvcs.exe |
| buffer | Buffer with sha1: 317b147832168997f48117f1838201d814e9bebf |
| buffer | Buffer with sha1: 0b1d56cb450b04e41f0244b342f96a3b07d5bc3a |
| host | 172.217.24.14 | |||
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\WindowsUpdate | reg_value | C:\Users\ADMINI~1.OSK\AppData\Roaming\15755881\rpjuoi.pif C:\Users\ADMINI~1.OSK\AppData\Roaming\15755881\kqorovx.xkf | ||||||