| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| Alibaba | RiskWare:Win32/Ammyy.1b5ddcc8 | 20190527 | 0.3.0.5 |
| Avast | Win32:Malware-gen | 20210405 | 21.1.5827.0 |
| Tencent | 20210405 | 1.0.0.1 | |
| Baidu | 20190318 | 1.0.0.2 | |
| Kingsoft | Win32.Troj.Ammyy.ma.(kcloud) | 20210405 | 2017.9.26.565 |
| McAfee | Artemis!53108F9BE4CD | 20210405 | 6.0.6.653 |
| CrowdStrike | win/malicious_confidence_80% (D) | 20210203 | 1.0 |
| packer | Armadillo v1.71 |
| resource name | BINARY |
| resource name | None |
| suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://rl.ammyy.com/ | ||||||
| request | POST http://rl.ammyy.com/ |
| request | POST http://rl.ammyy.com/ |
| host | 136.243.104.242 | |||
| host | 172.217.24.14 | |||
| service_name | AmmyyAdmin_390 | service_path | C:\ProgramData\AMMYY\"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\53108f9be4cd0cb76360f80a64c08ea7.exe" -service -lunch | ||||||