| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| McAfee | Artemis!46324D0ECF6D | 20201211 | 6.0.6.653 |
| Alibaba | Trojan:Win32/AutoitCrypt.180 | 20190527 | 0.3.0.5 |
| CrowdStrike | win/malicious_confidence_100% (W) | 20190702 | 1.0 |
| Baidu | 20190318 | 1.0.0.2 | |
| Avast | AutoIt:Injector-JF [Trj] | 20201210 | 21.1.5827.0 |
| Kingsoft | Win32.Troj.Undef.(kcloud) | 20201211 | 2017.9.26.565 |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1619467899.283249 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
|
1619467899.283249 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
| suspicious_features | POST method with no referer header | suspicious_request | POST https://update.googleapis.com/service/update2?cup2key=10:1957845870&cup2hreq=693e5887861bb2eed7b1ce6a89261220eddabe9b495feac54ddca1e37068efbe | ||||||
| domain | rem-pounds.ddns.net |
| request | POST https://update.googleapis.com/service/update2?cup2key=10:1957845870&cup2hreq=693e5887861bb2eed7b1ce6a89261220eddabe9b495feac54ddca1e37068efbe |
| request | POST https://update.googleapis.com/service/update2?cup2key=10:1957845870&cup2hreq=693e5887861bb2eed7b1ce6a89261220eddabe9b495feac54ddca1e37068efbe |
| description | 46324d0ecf6d00075a9382451dc51b07.exe tried to sleep 205 seconds, actually delayed analysis time by 205 seconds | |||
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WMPDMC.lnk |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\klist\drvinst.exe.bat |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WMPDMC.lnk |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\klist\drvinst.exe.bat |
| process | 46324d0ecf6d00075a9382451dc51b07.exe |
| buffer | Buffer with sha1: 6814db9bf5ba7822eda634d228c3f1c1bb18897b |
| buffer | Buffer with sha1: 9e1aaa3d54f5452f0460ed392e8a988af809a937 |
| host | 172.217.24.14 | |||
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WMPDMC.lnk |