| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| Alibaba | 20190527 | 0.3.0.5 | |
| Baidu | 20190318 | 1.0.0.2 | |
| Avast | 20190606 | 18.4.3895.0 | |
| Tencent | 20190606 | 1.0.0.1 | |
| Kingsoft | 20190606 | 2013.8.14.323 | |
| McAfee | Playtech | 20190606 | 6.0.6.653 |
| CrowdStrike | win/malicious_confidence_60% (D) | 20190212 | 1.0 |
| registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
| registry | HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Mozilla Firefox |
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\firefox.exe |
| section | .ndata |
| suspicious_features | POST method with no referer header | suspicious_request | POST https://update.googleapis.com/service/update2?cup2key=10:1099124988&cup2hreq=1b2e7249d05622699f4414200d2cc372a40ff784116fb6f142b1a1d57fca9bdf | ||||||
| request | GET http://c6m7w2m9.ssl.hwcdn.net/playtech_compressed_assets/casino_casinocom_new/index.7ze |
| request | GET http://fallback.playtech-installer.com/playtech_compressed_assets/casino_casinocom_new/index.7ze |
| request | GET http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
| request | GET http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D |
| request | GET http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D |
| request | GET http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEHSfdSPcp6pyLdnEz5lZ6ec%3D |
| request | GET http://fallback.playtech-installer.com/playtech_compressed_assets/casino_casinocom_new/templates/installer/casinocom_2016.7ze |
| request | HEAD http://redirector.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe |
| request | HEAD http://r1---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.100&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620742828&mv=m&mvi=1&pl=23&shardbypass=yes |
| request | HEAD http://r3---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5ok7e&req_id=db5d5534182bbf87&cms_redirect=yes&ipbypass=yes&mip=59.50.85.19&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620743071&mv=m&mvi=3 |
| request | GET https://t8u4n6u7.ssl.hwcdn.net/stats.gif?data=pMtHuT5Seu7PVl89Oje%2BIjpycslBpr5AIo6cU5hd6N%2FLT8sk6tZjjBIWHZL8ymQwJWkOAPWmDhMf7q9mrJ6fRizK8n%2FXJd4nevcPaaaFL0v3XeKEtDIMPlzJTe6LpuM7RcLPFlZrOCTONbgK1bHhwiOYpKB3Q9MYaXwVy23zlj5ggVkksjRqpP8cV3X6ciZpMpb5Cvpljls%2FvV6bEZYbeYI6%2BcZV5YTVCqlyitQ%2BRDhBwBv%2BRM5WEP5cC9wY8%2B54BVuASkdjAnmDM9Uv6TbM5OKgxmm%2FlD1KTmRu94Wuexf8ZP%2BPdN1gYkKNO5uggzYVaKJUhT0q0ZdHpcrbl7Fr58LgFd%2F3lFW1PVKPpdsdw787pPHcgzS23%2B%2FUuNHZkluZQRY2uTGnegb1NKKZ4uB31BcJMBkbrquOE4Z3IBpRJthk0rKXWxgW6UOu%2FTYLTV12uMhBslbREaZfukdpYjCkkcT7WWMDFECp4Y0BvBt%2BWEZBOWaF6ofuEP83v57JcMG0%2FjbBHddcbSQE9J82NA9bC3hsY8zXoDtly1wiOD6UdN2NHflexhFItBy3tNoLPQTlXyKaONDI6wPm2xPgeq%2B0UopDtwlPy8XHdzwEsnFGq%2BPQ%2FGMJyMEGi80Kfb6i9xNhveiAA1vT5IV6W9Bnlro7Z6%2BfngKhv7par00tmDxIGGQ%3D |
| request | GET https://t8u4n6u7.ssl.hwcdn.net/stats.gif?data=EyBkxlNSzUNwRB3hfrknPYSGG9fi7wzVmR2WLMyJ49myBC2SgYuGLIr%2F5YxDN3SzXW9R7AekRzUQlBDx0HVTL9rWnzUNfbc8wPmhb29O%2FPQiYHwjkg2gto8z7Kg5P86hTacYeolP0B06aWQdPZKNesm7Zd%2BLMSVQF6CoY3Hg1BdK4PTCr3LHnQWtWyjp6gCuD5IBsuIoWhQzQ7s9ayzfckwyyvrS5VCuQzYOK5eyo4OXewJTdR7CFLkF8OIS%2B37Mleeu%2F67yV0KCH7TKXCF4x4PPT0KUyBlLcLZIwvstloMzxNPI8QcknGUtj%2B%2FPu4L6B%2B%2BDRiLST1poWDPOP0JcmZ3dV1kYNBg%2FD7mdMXNFnKxZuoPhYmrPQbCYqzArIzp1231xk72GZSk7NIDB4xxNQzSxKPrYSU%2FHmE4Y5%2FimOu5dhy1IiRFHW7M0ulTH640gjZEPg%2FcK79R7pv0vKuZJwtsh41dhwQLgcfcgulxiafS6EmvlzflcrcQ3jIcTImFTC10RCjA5UNoLs35%2BRxnp%2FaAm7sSRkkDDCUN0bqM%2B%2BCfzcY2bimZUHQ774N0XYjRWez8Mkj%2BDuYEPrEadClRoBoql7%2FfsdzY2pxlPqTCXbVsrcfCMrMnMslLM0DKnzzl1B2IKhiLFsENEizOKYq7mNo9lBdA%2BecHMbKiZXjjmEZY%3D |
| request | GET https://c6m7w2m9.ssl.hwcdn.net/playtech_compressed_assets/casino_casinocom_new/templates/installer/casinocom_2016.7ze |
| request | POST https://update.googleapis.com/service/update2?cup2key=10:1099124988&cup2hreq=1b2e7249d05622699f4414200d2cc372a40ff784116fb6f142b1a1d57fca9bdf |
| request | POST https://update.googleapis.com/service/update2?cup2key=10:1099124988&cup2hreq=1b2e7249d05622699f4414200d2cc372a40ff784116fb6f142b1a1d57fca9bdf |
| registry | HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox |
| registry | HKEY_CURRENT_USER\Software\Mozilla\Mozilla Firefox |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsv8365.tmp\StdUtils.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsv8365.tmp\internal5bc7534dfd78e2d770537eab6c5d889b.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsv8365.tmp\StdUtils.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsv8365.tmp\internal5bc7534dfd78e2d770537eab6c5d889b.exe |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1620772007.535498 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |
| host | 172.217.24.14 | |||
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob |