查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
---|---|---|---|
Alibaba | Trojan:Win32/Dialer.df269bf8 | 20190527 | 0.3.0.5 |
Baidu | 20190318 | 1.0.0.2 | |
Avast | Win32:Dialer-ACP [Trj] | 20210316 | 21.1.5827.0 |
Tencent | Malware.Win32.Gencirc.10b493c2 | 20210316 | 1.0.0.1 |
Kingsoft | 20210316 | 2017.9.26.565 | |
McAfee | GenericRXAA-AA!3DA72242EA74 | 20210316 | 6.0.6.653 |
CrowdStrike | win/malicious_confidence_80% (W) | 20210203 | 1.0 |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620946604.291972 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
1620946606.385972 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
packer | UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser |
resource name | DAT |
resource name | JPG |
file | C:\Users\Administrator.Oskar-PC\Desktop\105-2-1-61.lnk |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\105-2-1-61.lnk |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\105-2-1-61.lnk |
file | C:\Users\Administrator.Oskar-PC\Desktop\105-2-1-61.lnk |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\105-2-1-61.lnk |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\105-2-1-61.lnk |
entropy | 7.9409964416208965 | section | {'size_of_data': '0x00015a00', 'virtual_address': '0x00015000', 'entropy': 7.9409964416208965, 'name': 'UPX1', 'virtual_size': '0x00016000'} | description | A section with a high entropy has been found | |||||||||
entropy | 0.9453551912568307 | description | Overall entropy of this PE file is high |
section | UPX0 | description | Section name indicates UPX | ||||||
section | UPX1 | description | Section name indicates UPX |
host | 172.217.24.14 |
reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\105-2-1-61 | reg_value | c:\program files\Webdialer\3da72242ea74703699fd8aade322f -m |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:18 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:19 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:13 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:14 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:15 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:16 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:17 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:21 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:20 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:23 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:22 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:25 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:24 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:27 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:26 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:29 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:28 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:32 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:33 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:30 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:31 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:36 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:37 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:34 |
mutex | Global\{89fcecff-287c-445f-8dc3-446ec943d2df}:sqlce_se_lck:35 |
mutex | {3AB0621E-56B8-4698-9989-29514AE790A6}_global |
udp | {'src': '192.168.56.101', 'dst': '224.0.0.252', 'offset': 11943, 'time': 6.985234975814819, 'dport': 5355, 'sport': 49235} |
udp | {'src': '192.168.56.101', 'dst': '224.0.0.252', 'offset': 12271, 'time': 6.672683000564575, 'dport': 5355, 'sport': 51963} |
udp | {'src': '192.168.56.101', 'dst': '224.0.0.252', 'offset': 12599, 'time': 81.35311198234558, 'dport': 5355, 'sport': 53380} |
udp | {'src': '192.168.56.101', 'dst': '224.0.0.252', 'offset': 12919, 'time': 5.976869106292725, 'dport': 5355, 'sport': 56804} |
udp | {'src': '192.168.56.101', 'dst': '224.0.0.252', 'offset': 13247, 'time': 10.388719081878662, 'dport': 5355, 'sport': 57756} |
udp | {'src': '192.168.56.101', 'dst': '224.0.0.252', 'offset': 13583, 'time': 10.387336015701294, 'dport': 5355, 'sport': 57874} |
udp | {'src': '192.168.56.101', 'dst': '224.0.0.252', 'offset': 13911, 'time': 7.501659154891968, 'dport': 5355, 'sport': 58367} |
udp | {'src': '192.168.56.101', 'dst': '224.0.0.252', 'offset': 14239, 'time': 13.615447044372559, 'dport': 5355, 'sport': 60384} |
udp | {'src': '192.168.56.101', 'dst': '224.0.0.252', 'offset': 14567, 'time': 19.180435180664062, 'dport': 5355, 'sport': 61680} |
udp | {'src': '192.168.56.101', 'dst': '224.0.0.252', 'offset': 14895, 'time': 6.285251140594482, 'dport': 5355, 'sport': 62191} |
udp | {'src': '192.168.56.101', 'dst': '224.0.0.252', 'offset': 15223, 'time': 6.478644132614136, 'dport': 5355, 'sport': 63429} |
udp | {'src': '192.168.56.101', 'dst': '239.255.255.250', 'offset': 15559, 'time': 6.67024302482605, 'dport': 1900, 'sport': 1900} |
udp | {'src': '192.168.56.101', 'dst': '239.255.255.250', 'offset': 38353, 'time': 9.236704111099243, 'dport': 1900, 'sport': 49240} |
udp | {'src': '192.168.56.101', 'dst': '239.255.255.250', 'offset': 43629, 'time': 8.344204187393188, 'dport': 3702, 'sport': 58368} |
udp | {'src': '192.168.56.101', 'dst': '239.255.255.250', 'offset': 46357, 'time': 6.63281512260437, 'dport': 3702, 'sport': 58707} |
udp | {'src': '192.168.56.101', 'dst': '239.255.255.250', 'offset': 61033, 'time': 13.905409097671509, 'dport': 3702, 'sport': 60385} |
udp | {'src': '192.168.56.101', 'dst': '239.255.255.250', 'offset': 63889, 'time': 26.589149951934814, 'dport': 3702, 'sport': 61681} |
udp | {'src': '192.168.56.101', 'dst': '239.255.255.250', 'offset': 66617, 'time': 36.52428913116455, 'dport': 3702, 'sport': 61683} |
dead_host | 172.217.160.78:443 |
Bkav | W32.AIDetect.malware1 |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Gen:Variant.Razy.43087 |
ALYac | Gen:Variant.Razy.43087 |
Cylance | Unsafe |
Zillya | Trojan.Scar.Win32.72351 |
Sangfor | Trojan.Win32.Save.a |
K7AntiVirus | Riskware ( 0040eff71 ) |
Alibaba | Trojan:Win32/Dialer.df269bf8 |
K7GW | Riskware ( 0040eff71 ) |
Cybereason | malicious.2ea747 |
Arcabit | Trojan.Razy.DA84F |
Cyren | W32/Webdialer.gen!GSA |
APEX | Malicious |
Avast | Win32:Dialer-ACP [Trj] |
ClamAV | Win.Trojan.Dialer-202 |
Kaspersky | Trojan.Win32.Scar.fmke |
BitDefender | Gen:Variant.Razy.43087 |
NANO-Antivirus | Trojan.Win32.Scar.exuuur |
Paloalto | generic.ml |
AegisLab | Riskware.Win32.Generic.l0jn |
Tencent | Malware.Win32.Gencirc.10b493c2 |
Ad-Aware | Gen:Variant.Razy.43087 |
Emsisoft | Gen:Variant.Razy.43087 (B) |
Comodo | ApplicUnsaf.Win32.Dialer.Generic@jux8x |
DrWeb | Dialer.Online.2 |
VIPRE | BehavesLike.Win32.Malware.bsc (vs) |
TrendMicro | DIAL_RAS.HE |
McAfee-GW-Edition | BehavesLike.Win32.Dialer.nc |
MaxSecure | Trojan.Malware.4018820.susgen |
FireEye | Generic.mg.3da72242ea747036 |
Sophos | Dial/190-A |
SentinelOne | Static AI - Suspicious PE |
ESET-NOD32 | a variant of Win32/Dialer.0190-Dialers |
Avira | DIAL/000293 |
MAX | malware (ai score=82) |
Gridinsoft | Trojan.Win32.Scar.vb |
Microsoft | Program:Win32/Vigram.A |
ViRobot | Trojan.Win32.A.Scar.62513[UPX] |
GData | Gen:Variant.Razy.43087 |
Cynet | Malicious (score: 100) |
AhnLab-V3 | Adware/Win32.Dialer.R21773 |
Acronis | suspicious |
McAfee | GenericRXAA-AA!3DA72242EA74 |
VBA32 | Trojan.Scar |
Malwarebytes | Malware.AI.1848512977 |
TrendMicro-HouseCall | DIAL_RAS.HE |
Rising | HackTool.PornDialer!1.6613 (CLOUD) |
Ikarus | Dialer |
eGambit | Unsafe.AI_Score_99% |
No hosts contacted.
Name | Response | Post-Analysis Lookup |
---|---|---|
dns.msftncsi.com | A 131.107.255.255 | 131.107.255.255 |
time.windows.com |
A 20.189.79.72
CNAME time.microsoft.akadns.net |
|
clients2.google.com |
A 172.217.160.78
CNAME clients.l.google.com |
172.217.160.78 |
dns.msftncsi.com | AAAA fd3e:4f5a:5b81::1 | 131.107.255.255 |
teredo.ipv6.microsoft.com |
No TCP connections recorded.
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 50002 | 114.114.114.114 | 53 |
192.168.56.101 | 51808 | 114.114.114.114 | 53 |
192.168.56.101 | 53210 | 114.114.114.114 | 53 |
192.168.56.101 | 53657 | 114.114.114.114 | 53 |
192.168.56.101 | 62318 | 114.114.114.114 | 53 |
192.168.56.101 | 65004 | 114.114.114.114 | 53 |
192.168.56.101 | 137 | 192.168.56.255 | 137 |
192.168.56.101 | 138 | 192.168.56.255 | 138 |
192.168.56.101 | 123 | 20.189.79.72 time.windows.com | 123 |
192.168.56.101 | 49235 | 224.0.0.252 | 5355 |
192.168.56.101 | 51963 | 224.0.0.252 | 5355 |
192.168.56.101 | 53380 | 224.0.0.252 | 5355 |
192.168.56.101 | 56804 | 224.0.0.252 | 5355 |
192.168.56.101 | 57756 | 224.0.0.252 | 5355 |
192.168.56.101 | 57874 | 224.0.0.252 | 5355 |
192.168.56.101 | 58367 | 224.0.0.252 | 5355 |
192.168.56.101 | 60384 | 224.0.0.252 | 5355 |
192.168.56.101 | 61680 | 224.0.0.252 | 5355 |
192.168.56.101 | 62191 | 224.0.0.252 | 5355 |
192.168.56.101 | 63429 | 224.0.0.252 | 5355 |
No HTTP requests performed.
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts