查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
---|---|---|---|
McAfee | 20180416 | 6.0.6.653 | |
Baidu | 20180413 | 1.0.0.2 | |
Alibaba | 20180416 | 1.0 | |
Avast | 20180416 | 18.3.3860.0 | |
Tencent | 20180416 | 1.0.0.1 | |
Kingsoft | 20180416 | 2013.8.14.323 | |
CrowdStrike | malicious_confidence_60% (W) | 20170201 | 1.0 |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620762792.00025 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
1620762792.07825 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
section | .ndata |
suspicious_features | POST method with no referer header | suspicious_request | POST https://update.googleapis.com/service/update2?cup2key=10:2580132817&cup2hreq=fae295154c260d75d61d24d4f359dbecae7cd2c9ab8c055afe76a8f0f80f16ac |
request | GET http://www.dualdesk.net/unreg/1-466054372.txt |
request | HEAD http://redirector.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe |
request | HEAD http://r1---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.100&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620746660&mv=m&mvi=1&pl=23&shardbypass=yes |
request | HEAD http://r3---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5ok7e&req_id=d16be656edbfb757&cms_redirect=yes&ipbypass=yes&mip=59.50.85.19&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620746660&mv=m&mvi=3 |
request | POST https://update.googleapis.com/service/update2?cup2key=10:2580132817&cup2hreq=fae295154c260d75d61d24d4f359dbecae7cd2c9ab8c055afe76a8f0f80f16ac |
request | POST https://update.googleapis.com/service/update2?cup2key=10:2580132817&cup2hreq=fae295154c260d75d61d24d4f359dbecae7cd2c9ab8c055afe76a8f0f80f16ac |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsq8D77.tmp\nsExec.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nst899F.tmp\DD_69.21.166.242_5107.exe |
file | C:\Program Files (x86)\DD20.4.8202105112352\StopDD.reg |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsq8D77.tmp\cad.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DualDesk.lnk |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsq8D77.tmp\DualDesk.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsisdt.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nst899F.tmp\Splash.dll |
file | C:\Program Files (x86)\DD20.4.8202105112352\ToolBox\DualDesk.lnk |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsq8D77.tmp\ddUninst.exe |
file | C:\Program Files (x86)\DD20.4.8202105112352\ToolBox\DualDesk.lnk |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DualDesk.lnk |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsq8D77.tmp\ns9131.tmp |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsq8D77.tmp\nsExec.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nst899F.tmp\Splash.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsisdt.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nst899F.tmp\DD_69.21.166.242_5107.exe |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620775807.285875 ShellExecuteExW |
parameters:
/flushdns
filepath: ipconfig.exe filepath_r: ipconfig.exe show_type: 0 |
success | 1 | 0 |
NANO-Antivirus | Trojan.Win32.Generic.dirald |
DrWeb | Trojan.Inject1.36291 |
Zillya | Trojan.InstallCoreCRTD.Win32.4334 |
CrowdStrike | malicious_confidence_60% (W) |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620775775.223875 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |
cmdline | C:\Users\ADMINI~1.OSK\AppData\Local\Temp\nsq8D77.tmp\nsD82.tmp REG.EXE DELETE "SYSTEM\CurrentControlSet\Services\DD_Service" /f |
cmdline | REG.EXE DELETE "SYSTEM\CurrentControlSet\Services\DD_Service\DependOnService" /f |
cmdline | C:\Users\ADMINI~1.OSK\AppData\Local\Temp\nsq8D77.tmp\nsF93B.tmp REG.EXE DELETE "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DD_Service\Enum" /f |
cmdline | "sc.exe" delete DD_Service |
cmdline | REG.EXE DELETE "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DD_Service" /f |
cmdline | C:\Users\ADMINI~1.OSK\AppData\Local\Temp\nsq8D77.tmp\nsFE0E.tmp REG.EXE DELETE "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DD_Service" /f |
cmdline | REG.EXE DELETE "SYSTEM\CurrentControlSet\Services\DD_Service\Description" /f |
cmdline | C:\Users\ADMINI~1.OSK\AppData\Local\Temp\nsq8D77.tmp\nsB40E.tmp "net.exe" stop DD_CAD |
cmdline | C:\Users\ADMINI~1.OSK\AppData\Local\Temp\nsq8D77.tmp\nsC015.tmp "sc.exe" delete DD_Service |
cmdline | "netsh.exe" firewall add allowedprogram "C:\Program Files (x86)\DD20.4.8202105112352\DualDesk.exe" "DualDesk-Server" ENABLE ALL |
cmdline | C:\Users\ADMINI~1.OSK\AppData\Local\Temp\nsq8D77.tmp\nsCC1D.tmp "netsh.exe" firewall add allowedprogram "C:\Program Files (x86)\DD20.4.8202105112352\DualDesk.exe" "DualDesk-Server" ENABLE ALL |
cmdline | REG.EXE DELETE "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DD_Service\Enum" /f |
cmdline | "net.exe" stop DD_CAD |
cmdline | "sc.exe" stop DD_CAD |
cmdline | "sc.exe" stop DD_Service |
cmdline | C:\Users\ADMINI~1.OSK\AppData\Local\Temp\nsq8D77.tmp\nsF561.tmp REG.EXE DELETE "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DD_Service\Security" /f |
cmdline | C:\Users\ADMINI~1.OSK\AppData\Local\Temp\nsq8D77.tmp\nsBF.tmp REG.EXE DELETE "SYSTEM\CurrentControlSet\Services\DD_Service\Description" /f |
cmdline | C:\Users\ADMINI~1.OSK\AppData\Local\Temp\nsq8D77.tmp\ns870.tmp REG.EXE DELETE "SYSTEM\CurrentControlSet\Services\DD_Service\DependOnService" /f |
cmdline | C:\Users\ADMINI~1.OSK\AppData\Local\Temp\nsq8D77.tmp\nsAB91.tmp "net.exe" stop DD_Service |
cmdline | "net.exe" stop DD_Service |
cmdline | "netsh.exe" firewall add allowedprogram "C:\Program Files (x86)\DD20.4.8202105112352\DualDesk.exe" "DualDesk-Server" ENABLE |
cmdline | C:\Users\ADMINI~1.OSK\AppData\Local\Temp\nsq8D77.tmp\ns9FE7.tmp "sc.exe" stop DD_CAD |
cmdline | "C:\Windows\System32\ipconfig.exe" /flushdns |
cmdline | REG.EXE DELETE "HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DD_Service\Security" /f |
cmdline | C:\Users\ADMINI~1.OSK\AppData\Local\Temp\nsq8D77.tmp\nsED61.tmp "netsh.exe" firewall add allowedprogram "C:\Program Files (x86)\DD20.4.8202105112352\DualDesk.exe" "DualDesk-Server" ENABLE |
cmdline | "sc.exe" delete DD_CAD |
cmdline | ipconfig.exe /flushdns |
cmdline | C:\Users\ADMINI~1.OSK\AppData\Local\Temp\nsq8D77.tmp\ns9131.tmp "sc.exe" stop DD_Service |
cmdline | C:\Users\ADMINI~1.OSK\AppData\Local\Temp\nsq8D77.tmp\nsC2E4.tmp "sc.exe" delete DD_CAD |
cmdline | REG.EXE DELETE "SYSTEM\CurrentControlSet\Services\DD_Service" /f |
host | 172.217.24.14 | |||
host | 69.21.166.242 |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620775774.723875 EnumServicesStatusA |
service_handle:
0x005dc438
service_type: 48 service_status: 3 |
failed | 0 | 0 |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DualDesk.lnk |
process: potential process injection target | explorer.exe |
dead_host | 172.217.160.110:443 |
dead_host | 172.217.24.14:443 |
dead_host | 69.21.166.242:5107 |
dead_host | 172.217.160.78:443 |
No hosts contacted.
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 49254 | 108.163.248.178 www.dualdesk.net | 80 |
192.168.56.101 | 49269 | 113.108.239.194 r1---sn-j5o7dn7e.gvt1.com | 80 |
192.168.56.101 | 49270 | 113.108.239.196 r3---sn-j5o7dn7e.gvt1.com | 80 |
192.168.56.101 | 49266 | 203.208.40.34 update.googleapis.com | 443 |
192.168.56.101 | 49268 | 203.208.41.65 redirector.gvt1.com | 80 |
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 51963 | 114.114.114.114 | 53 |
192.168.56.101 | 53237 | 114.114.114.114 | 53 |
192.168.56.101 | 53500 | 114.114.114.114 | 53 |
192.168.56.101 | 55169 | 114.114.114.114 | 53 |
192.168.56.101 | 55368 | 114.114.114.114 | 53 |
192.168.56.101 | 56539 | 114.114.114.114 | 53 |
192.168.56.101 | 57236 | 114.114.114.114 | 53 |
192.168.56.101 | 57367 | 114.114.114.114 | 53 |
192.168.56.101 | 58970 | 114.114.114.114 | 53 |
192.168.56.101 | 60088 | 114.114.114.114 | 53 |
192.168.56.101 | 60384 | 114.114.114.114 | 53 |
192.168.56.101 | 60911 | 114.114.114.114 | 53 |
192.168.56.101 | 62912 | 114.114.114.114 | 53 |
192.168.56.101 | 137 | 192.168.56.255 | 137 |
192.168.56.101 | 138 | 192.168.56.255 | 138 |
192.168.56.101 | 123 | 20.189.79.72 time.windows.com | 123 |
192.168.56.101 | 49713 | 224.0.0.252 | 5355 |
192.168.56.101 | 53210 | 224.0.0.252 | 5355 |
192.168.56.101 | 53657 | 224.0.0.252 | 5355 |
192.168.56.101 | 54178 | 224.0.0.252 | 5355 |
URI | Data |
---|---|
http://redirector.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe | HEAD /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe HTTP/1.1 Connection: Keep-Alive Accept: */* Accept-Encoding: identity User-Agent: Microsoft BITS/7.5 X-Old-UID: cnt=0 X-Last-HR: 0x0 X-Last-HTTP-Status-Code: 0 X-Retry-Count: 0 X-HTTP-Attempts: 1 Host: redirector.gvt1.com |
http://r3---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5ok7e&req_id=d16be656edbfb757&cms_redirect=yes&ipbypass=yes&mip=59.50.85.19&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620746660&mv=m&mvi=3 | HEAD /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5ok7e&req_id=d16be656edbfb757&cms_redirect=yes&ipbypass=yes&mip=59.50.85.19&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620746660&mv=m&mvi=3 HTTP/1.1 Connection: Keep-Alive Accept: */* Accept-Encoding: identity User-Agent: Microsoft BITS/7.5 X-Old-UID: cnt=0 X-Last-HR: 0x0 X-Last-HTTP-Status-Code: 0 X-Retry-Count: 0 X-HTTP-Attempts: 1 Host: r3---sn-j5o7dn7e.gvt1.com |
http://r1---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.100&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620746660&mv=m&mvi=1&pl=23&shardbypass=yes | HEAD /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.100&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620746660&mv=m&mvi=1&pl=23&shardbypass=yes HTTP/1.1 Connection: Keep-Alive Accept: */* Accept-Encoding: identity User-Agent: Microsoft BITS/7.5 X-Old-UID: cnt=0 X-Last-HR: 0x0 X-Last-HTTP-Status-Code: 0 X-Retry-Count: 0 X-HTTP-Attempts: 1 Host: r1---sn-j5o7dn7e.gvt1.com |
http://www.dualdesk.net/unreg/1-466054372.txt | GET /unreg/1-466054372.txt HTTP/1.1 Accept: */* Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: www.dualdesk.net Connection: Keep-Alive |
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts