查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
---|---|---|---|
Alibaba | 20190402 | 0.3.0.4 | |
Baidu | 20190318 | 1.0.0.2 | |
Avast | 20190417 | 18.4.3895.0 | |
Kingsoft | 20190417 | 2013.8.14.323 | |
McAfee | 20190417 | 6.0.6.653 | |
Tencent | 20190417 | 1.0.0.1 | |
CrowdStrike | 20190212 | 1.0 |
registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
registry | HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Mozilla Firefox |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\firefox.exe |
section | .ndata |
suspicious_features | POST method with no referer header | suspicious_request | POST https://update.googleapis.com/service/update2?cup2key=10:16223434&cup2hreq=3e239dfc3179a133673c4f14e481b6f2672f9449539f9d8fbf5085ff2ad348ab |
request | GET http://c6m7w2m9.ssl.hwcdn.net/playtech_compressed_assets/casino_casinocomit/index.7ze |
request | GET http://fallback.playtech-installer.com/playtech_compressed_assets/casino_casinocomit/index.7ze |
request | GET http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
request | GET http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D |
request | GET http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D |
request | GET http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEHSfdSPcp6pyLdnEz5lZ6ec%3D |
request | GET http://fallback.playtech-installer.com/playtech_compressed_assets/casino_casinocomit/templates/installer/casinocomit_new.7ze |
request | HEAD http://redirector.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe |
request | HEAD http://r1---sn-j5o76n7l.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.99&mm=28&mn=sn-j5o76n7l&ms=nvh&mt=1620945620&mv=m&mvi=1&pl=23&shardbypass=yes |
request | GET https://t8u4n6u7.ssl.hwcdn.net/stats.gif?data=IMKkThQicBBlpmGfWXygUKmU5d84Ey24TOzm1E0YrG2DRMGOIq7ZgOA0Hq6iC5goQ8%2FExZCM58qIdViwK%2FtatfcqUhG9H52thUiMNlzo2jpVPv4DVkOmlfvX5bu%2Bp3c%2FaKd8NlEoUKT%2BeiJJSW%2F3rsZmrEzZMlT8ZFNFJr0sNFaOSHTibQVNSq8OJo%2FfGk39cbkLo8ikFO3I15xOYOt7M1ahbJosPLPUEtlGpSbjeiHq%2B3hJu8VcmRXLguf11S97SLP4ef8di9tMZr%2BirElAotdi7CBGVjiO9LZtvV2ouukTScSe%2FBeR8ZHHjOEPsmSmHhL0jh1tZK19T%2F%2FeluT4%2FziZzASTyhQEWxdkdt8JWFJg%2FDe34T7I%2FBj10DW71ucSbe0IlAH%2FqVs0QdPFM5OjWc0eKMsqRirpAypHqKsCEysT%2FXOotUYGimZybBqXWS66aiYIE%2BLY3HOqLBt392ufic6gpQH7N0Mv9fz7tphPHPHWLEYFsjxZbHGli0uJRGGrcVMkWvpm8v68bKJ%2BAanzLEYmXZPAK%2BXdJKK1I9YhC%2BEAsJWyDpsunF%2FFBcEPaAX9HDbDb4qgQEfRALoIU5Roabuk%2B7zMNMf7TK%2BYJ2heCqv6w6xsIgUiTjb9zER6X5JfActyqEcC4KpAmrx2SFrZ39GFPS5TDrlmrncPJ%2FJNFGA%3D |
request | GET https://t8u4n6u7.ssl.hwcdn.net/stats.gif?data=0Ec2pT8bFpp3ZmkSS1tI%2BYWhJbq1siLRan7ZnvfGzcUchbBAfXYoKDIntuO%2Boe%2FyR35aPzlQ1Jc5eXhqnJKiEVE3D1viLZtc1YCNSSJzSLx14pOVdQszIuys70E%2Bd24ku2vhpjWQnjyrKqJfkxmObcuJ%2FkTra4%2BaNlwSvy3JtfdvTWcPQGK2j%2Fg3ME1vjuw53jlHGPc4YmFtIuH5hnaVskCwhE0BdEhEOEK53NoTZnLyfjznZU79qpTOoom%2BbLzTfX66kwMNH%2BLysMQaFl1qBuQJfRHViWu%2FGC6k9YOeiIvKQfnNf8easPFwumGO0x7sWn%2BMiIrc3CdlNk8S6kwUawLbTW6wkGfORcjKJ1O%2FXSZfLWCN1xVB9L6EUrdG0YTkj2AjkqRYPhoKr0fpV2ltr7tDibVmp0Qwvbt%2F8%2BZ0ltdILK2buTWTRIiUpqlfh%2FCIX8lcPdegRUQ%2B7pcn9EC3jSvOUAk627Q3tAECoO88c9MRCfYUioYWvRAFUfSof%2BrWglXYJB2MbUj8CvM4Yb2O7HM7KWzutAldjfLqQOoU5eL75eD2EKLjo7U3ozybKmR%2BalhgZrasn5lv802tMxawNIsJRx5jMWXHewuHa5%2Fpd40%2FMjzX8tEKN7QImYILG%2FYENuL8WVlah0E2emxK8aAc%2Ff4oylz48wSF2biqUNdfXrs%3D |
request | GET https://c6m7w2m9.ssl.hwcdn.net/playtech_compressed_assets/casino_casinocomit/templates/installer/casinocomit_new.7ze |
request | POST https://update.googleapis.com/service/update2?cup2key=10:16223434&cup2hreq=3e239dfc3179a133673c4f14e481b6f2672f9449539f9d8fbf5085ff2ad348ab |
request | POST https://update.googleapis.com/service/update2?cup2key=10:16223434&cup2hreq=3e239dfc3179a133673c4f14e481b6f2672f9449539f9d8fbf5085ff2ad348ab |
registry | HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox |
registry | HKEY_CURRENT_USER\Software\Mozilla\Mozilla Firefox |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsm61D4.tmp\internal47331f16d928c8ab5e671beed12c0027.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsm61D4.tmp\internal47331f16d928c8ab5e671beed12c0027.exe |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620974940.82975 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |
host | 159.69.101.238 | |||
host | 172.217.24.14 |
Bkav | W32.HfsAdware.D664 |
Cylance | Unsafe |
Rising | PUA.CrossRider!8.84 (CLOUD) |
F-Secure | Heuristic.HEUR/AGEN.1039999 |
Invincea | heuristic |
Avira | HEUR/AGEN.1039999 |
Antiy-AVL | GrayWare[AdWare]/Win32.PlayTech.a |
Microsoft | PUA:Win32/Playtech |
Endgame | malicious (high confidence) |
ESET-NOD32 | a variant of Win32/PlayTech.A potentially unwanted |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob |