| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| McAfee | Artemis!56BCFE289E32 | 20200815 | 6.0.6.653 |
| Baidu | 20190318 | 1.0.0.2 | |
| Avast | 20200815 | 18.4.3895.0 | |
| Alibaba | 20190527 | 0.3.0.5 | |
| Kingsoft | 20200815 | 2013.8.14.323 | |
| Tencent | 20200815 | 1.0.0.1 | |
| CrowdStrike | 20190702 | 1.0 |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1620770006.05925 GetComputerNameA |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
| section | .ndata |
| suspicious_features | POST method with no referer header | suspicious_request | POST http://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=SDM_TotalProcessStart&sdmVersion=01.02.00.33&muid=30300030ADD1ADD2ADD33B4138C699FFE8F31000AB3B7B12C268C7715883755600067EDB | ||||||
| suspicious_features | POST method with no referer header | suspicious_request | POST http://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=SDM_OfferDisplayed&OfferId=10002&OfferOrder=1&sdmVersion=01.02.00.33&muid=30300030ADD1ADD2ADD33B4138C699FFE8F31000AB3B7B12C268C7715883755600067EDB | ||||||
| suspicious_features | POST method with no referer header | suspicious_request | POST http://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=SDM_Player_validation&isPlayerInstalled=0&beginUpgrade=0&existingPlayerVersion=0&sdmVersion=01.02.00.33&muid=30300030ADD1ADD2ADD33B4138C699FFE8F31000AB3B7B12C268C7715883755600067EDB | ||||||
| request | GET http://www.freeridegames.com/spdo/feeds/sdmConfig?camp=FRG_Website&serviceId=143&gameId=695150 |
| request | POST http://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=SDM_TotalProcessStart&sdmVersion=01.02.00.33&muid=30300030ADD1ADD2ADD33B4138C699FFE8F31000AB3B7B12C268C7715883755600067EDB |
| request | POST http://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=SDM_OfferDisplayed&OfferId=10002&OfferOrder=1&sdmVersion=01.02.00.33&muid=30300030ADD1ADD2ADD33B4138C699FFE8F31000AB3B7B12C268C7715883755600067EDB |
| request | POST http://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=SDM_Player_validation&isPlayerInstalled=0&beginUpgrade=0&existingPlayerVersion=0&sdmVersion=01.02.00.33&muid=30300030ADD1ADD2ADD33B4138C699FFE8F31000AB3B7B12C268C7715883755600067EDB |
| request | GET http://img.exent.com/free/frg/products/695150/boxshot.jpg |
| request | POST http://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=SDM_TotalProcessStart&sdmVersion=01.02.00.33&muid=30300030ADD1ADD2ADD33B4138C699FFE8F31000AB3B7B12C268C7715883755600067EDB |
| request | POST http://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=SDM_OfferDisplayed&OfferId=10002&OfferOrder=1&sdmVersion=01.02.00.33&muid=30300030ADD1ADD2ADD33B4138C699FFE8F31000AB3B7B12C268C7715883755600067EDB |
| request | POST http://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=SDM_Player_validation&isPlayerInstalled=0&beginUpgrade=0&existingPlayerVersion=0&sdmVersion=01.02.00.33&muid=30300030ADD1ADD2ADD33B4138C699FFE8F31000AB3B7B12C268C7715883755600067EDB |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Cookies |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\local_cookies-journal |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\local_cookies |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Local State |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\cookies-wal |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\local_cookies-wal |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\cookies-journal |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\SDM143\ExentCtlInstaller.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\SDM143\cmhelper.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\SDM143\resourceDll.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\SDM143\Free Ride Games.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\SDM143\Splasher.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsy78D5.tmp\System.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\SDM143\cmhelper.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsy78D5.tmp\System.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\SDM143\Splasher.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\SDM143\ExentCtlInstaller.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\SDM143\Free Ride Games.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\SDM143\cmhelper.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\SDM143\resourceDll.dll |
| McAfee | Artemis!56BCFE289E32 |
| APEX | Malicious |
| DrWeb | Adware.GameVance.283 |
| Ikarus | Trojan.Milum |
| Microsoft | PUA:Win32/Caypnamer.A!ml |
| ESET-NOD32 | Win32/Exent.B potentially unwanted |
| eGambit | Unsafe.AI_Score_98% |
| Fortinet | NSIS/Milum.A!tr |
| host | 172.217.24.14 | |||
| host | 203.208.40.98 | |||
| host | 216.58.200.78 | |||
| process | Free Ride Games.exe | useragent | AHTTPConnection | ||||||
| process | Free Ride Games.exe | useragent | Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) | ||||||
| dead_host | 172.217.24.14:443 |
| dead_host | 172.217.160.110:443 |
No hosts contacted.
| Source | Source Port | Destination | Destination Port |
|---|---|---|---|
| 192.168.56.101 | 49210 | 104.16.123.74 img.exent.com | 80 |
| 192.168.56.101 | 49180 | 104.16.41.24 www.freeridegames.com | 80 |
| 192.168.56.101 | 49204 | 104.16.41.24 www.freeridegames.com | 80 |
| 192.168.56.101 | 49205 | 104.16.41.24 www.freeridegames.com | 80 |
| 192.168.56.101 | 49207 | 104.16.41.24 www.freeridegames.com | 80 |
| Source | Source Port | Destination | Destination Port |
|---|---|---|---|
| 192.168.56.101 | 51808 | 114.114.114.114 | 53 |
| 192.168.56.101 | 51963 | 114.114.114.114 | 53 |
| 192.168.56.101 | 53380 | 114.114.114.114 | 53 |
| 192.168.56.101 | 55368 | 114.114.114.114 | 53 |
| 192.168.56.101 | 60123 | 114.114.114.114 | 53 |
| 192.168.56.101 | 60221 | 114.114.114.114 | 53 |
| 192.168.56.101 | 61680 | 114.114.114.114 | 53 |
| 192.168.56.101 | 62912 | 114.114.114.114 | 53 |
| 192.168.56.101 | 137 | 192.168.56.255 | 137 |
| 192.168.56.101 | 138 | 192.168.56.255 | 138 |
| 192.168.56.101 | 123 | 20.189.79.72 time.windows.com | 123 |
| 192.168.56.101 | 49713 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 50568 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 51378 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 53237 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 56804 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 57236 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 58367 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 62191 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 62318 | 224.0.0.252 | 5355 |
| URI | Data |
|---|---|
| http://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=SDM_TotalProcessStart&sdmVersion=01.02.00.33&muid=30300030ADD1ADD2ADD33B4138C699FFE8F31000AB3B7B12C268C7715883755600067EDB | POST /opTools/clientTracking.jsp?trackEvent=SDM_TotalProcessStart&sdmVersion=01.02.00.33&muid=30300030ADD1ADD2ADD33B4138C699FFE8F31000AB3B7B12C268C7715883755600067EDB HTTP/1.1 User-Agent: AHTTPConnection Host: www.freeridegames.com Content-Length: 0 Connection: Keep-Alive Cache-Control: no-cache Cookie: 143_TURNKEY=Default-461620741205049385; 143_FIRST_BROWSER="Default-MSIE 8.0"; 143_CAMPAIGN_SERIAL_ID=Default-FRG_Website |
| http://img.exent.com/free/frg/products/695150/boxshot.jpg | GET /free/frg/products/695150/boxshot.jpg HTTP/1.1 Accept: */* Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: img.exent.com Connection: Keep-Alive |
| http://www.freeridegames.com/spdo/feeds/sdmConfig?camp=FRG_Website&serviceId=143&gameId=695150 | GET /spdo/feeds/sdmConfig?camp=FRG_Website&serviceId=143&gameId=695150 HTTP/1.1 User-Agent: AHTTPConnection Host: www.freeridegames.com Connection: Keep-Alive Cache-Control: no-cache |
| http://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=SDM_Player_validation&isPlayerInstalled=0&beginUpgrade=0&existingPlayerVersion=0&sdmVersion=01.02.00.33&muid=30300030ADD1ADD2ADD33B4138C699FFE8F31000AB3B7B12C268C7715883755600067EDB | POST /opTools/clientTracking.jsp?trackEvent=SDM_Player_validation&isPlayerInstalled=0&beginUpgrade=0&existingPlayerVersion=0&sdmVersion=01.02.00.33&muid=30300030ADD1ADD2ADD33B4138C699FFE8F31000AB3B7B12C268C7715883755600067EDB HTTP/1.1 User-Agent: AHTTPConnection Host: www.freeridegames.com Content-Length: 0 Connection: Keep-Alive Cache-Control: no-cache Cookie: 143_TURNKEY=Default-461620741205049385; 143_FIRST_BROWSER="Default-MSIE 8.0"; 143_CAMPAIGN_SERIAL_ID=Default-FRG_Website |
| http://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=SDM_OfferDisplayed&OfferId=10002&OfferOrder=1&sdmVersion=01.02.00.33&muid=30300030ADD1ADD2ADD33B4138C699FFE8F31000AB3B7B12C268C7715883755600067EDB | POST /opTools/clientTracking.jsp?trackEvent=SDM_OfferDisplayed&OfferId=10002&OfferOrder=1&sdmVersion=01.02.00.33&muid=30300030ADD1ADD2ADD33B4138C699FFE8F31000AB3B7B12C268C7715883755600067EDB HTTP/1.1 User-Agent: AHTTPConnection Host: www.freeridegames.com Content-Length: 0 Connection: Keep-Alive Cache-Control: no-cache Cookie: 143_TURNKEY=Default-461620741205049385; 143_FIRST_BROWSER="Default-MSIE 8.0"; 143_CAMPAIGN_SERIAL_ID=Default-FRG_Website |
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts