| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| Alibaba | Trojan:Win32/AutoitCrypt.180 | 20190527 | 0.3.0.5 |
| Baidu | 20190318 | 1.0.0.2 | |
| Avast | AutoIt:Injector-JF [Trj] | 20200904 | 18.4.3895.0 |
| Tencent | Malware.Win32.Gencirc.10b639e7 | 20200904 | 1.0.0.1 |
| Kingsoft | 20200904 | 2013.8.14.323 | |
| McAfee | Artemis!3ABE5AAFBBB8 | 20200904 | 6.0.6.653 |
| CrowdStrike | win/malicious_confidence_100% (W) | 20190702 | 1.0 |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1619345049.975633 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
|
1619345049.991633 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
| domain | rem-pounds.ddns.net |
| description | 3abe5aafbbb8dd32b4efe2c050b9b0b8.exe tried to sleep 251 seconds, actually delayed analysis time by 251 seconds | |||
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WMPDMC.lnk |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\klist\drvinst.exe.bat |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WMPDMC.lnk |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\klist\drvinst.exe.bat |
| process | 3abe5aafbbb8dd32b4efe2c050b9b0b8.exe |
| buffer | Buffer with sha1: 57244f0676f3b6a09f8d2bd70d4b82c51ccab3c3 |
| buffer | Buffer with sha1: 6814db9bf5ba7822eda634d228c3f1c1bb18897b |
| host | 172.217.24.14 | |||
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WMPDMC.lnk |