查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
---|---|---|---|
McAfee | 20190425 | 6.0.6.653 | |
Alibaba | 20190402 | 0.3.0.4 | |
Baidu | 20190318 | 1.0.0.2 | |
Avast | 20190425 | 18.4.3895.0 | |
Tencent | 20190425 | 1.0.0.1 | |
Kingsoft | 20190425 | 2013.8.14.323 | |
CrowdStrike | win/malicious_confidence_60% (D) | 20190212 | 1.0 |
registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
registry | HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Mozilla Firefox |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\firefox.exe |
section | .ndata |
suspicious_features | POST method with no referer header | suspicious_request | POST https://update.googleapis.com/service/update2?cup2key=10:222280109&cup2hreq=06ecd5e13a0915da810207ca9da9eb99e4a57f12b3a6ecdb04eddd431963152e |
request | GET http://c6m7w2m9.ssl.hwcdn.net/playtech_compressed_assets/casino_casinocom_new/index.7ze |
request | GET http://fallback.playtech-installer.com/playtech_compressed_assets/casino_casinocom_new/index.7ze |
request | GET http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
request | GET http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D |
request | GET http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D |
request | GET http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEHSfdSPcp6pyLdnEz5lZ6ec%3D |
request | HEAD http://redirector.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe |
request | HEAD http://r1---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.100&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620954736&mv=m&mvi=1&pl=23&shardbypass=yes |
request | HEAD http://r3---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5ok7e&req_id=54617f20f8feed61&cms_redirect=yes&ipbypass=yes&mip=59.50.85.19&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620954736&mv=m&mvi=3 |
request | GET https://t8u4n6u7.ssl.hwcdn.net/stats.gif?data=OHBPm7SK4E0mhyNFdHhEaafnMTUk%2F%2FwUCpmW1o4T76jUopPCu8cNUuZxgKXnXd4OVYGDLGPfFRpar1zRsLJOxaElXruIy6bS5MaidtF%2FWZnxyolEryTJplaFbSPXms2T99f34gzCpfWeIiNVQMCZ6zmeADBYHiWS1uEsm0rS5DznQDb5x0s%2BJ%2FcYo0msVGvv0F7XUBY6q1X%2BFO4oAUNQl0OLxSAI6bdFboEutG9PpTTSWbSblpxnDsHXyYK%2BhkKeBauXpGrcwSE5ACB4r53gvp9TFMizp9kzXnG6prUkKnpXu23KE03xruBcUsMSMquTN5U2G7SqiaXexPP7N%2BcmIYWBgyPFSYW3StPgRgvjRLBK07k3un1qbEb%2FBBZS%2BAzJ1DB8MUTEizsmCknlcYuC06PjYUYUwGqSWu7cO91eoqZmZmkW9RJXgkGrInrANjZ3cGkd3iWft5AKDO2KhDi2NO%2FifG4uEUu2akNj0SD2QNnUD9QuRvSevwycFyJFW82JV%2BL57v03p36jixVKiOUJoClVjA6eg4E7lKUeQJ4klRlYRkbQdUwkKWtdR08tyPaVw5UbxNYf6jKV0Nglb6F4557jrLX2g2U4TVNt2pwZLNL5wd4JPLdV4OEizOdGJ4jePBs6Uh43T4neTyugN3Lcywgwq5mQLqzY2gSgUW68LaY%3D |
request | GET https://t8u4n6u7.ssl.hwcdn.net/stats.gif?data=AWPQeFh6i%2BBetvRYFJpL55WZ%2BDJcZtwlI9Q9HLuQeWbuHkz2YH3dN7OQOD%2B9olCAomTr4mnAveMM7SEg9XjJyk56i5RBMFuUufvrQUDRtoorL%2BIXXxcalCrjpbbkYFbpthZv94ggAso7CWoayxdt7GNqhBagwlHhjwKY0vHTscW0Bki9cm7n1mnODYHqgST1u8pvj02jWxTXqJvz7kgQADKdY4LyEinBRfRfKXdDUVp191KcMjt8sRYoTfmw6CCICyzXPsSQemYkrCaeNSNyZ2P3BJjR%2Fq%2FBHRTbkJgACgAgWMNDf0euMVDeKitv2z3q5ZyKKlSVfLcr%2FsKgnRoM4MQ4HgZ8jdx9zsRw%2BhxniJsM7OaaQGNsIlUolPT1OrnzXxnm1byl%2BRSNBs7l0oOc1fJ4K25KHpzDQRX1GwfOvsXztFJz0VPdZ5S0vvz%2BRuQ4Y4OoXKbVK%2FMmHH4LH27M63loNZE3w7OO%2FhMR9OXAG1LhKD2ODeqo6LghqlJpXh3Smg45KEA3bCHjxCvMchRgGj7e0WFTGkccUmXMzEQT6O1JzV9l9rCgmU%2BuGZ%2FOV%2BP7VCshDTrlooNtjIBxUhy%2Bn3wmqQLWyG%2BCDGVdx9aocMzo6bDJ1wJYzebgLhBT6rd81Ey6sbudIXfj%2FxARdrRs0e42wf9QEZsSY%2BeTJzE7p7M%3D |
request | POST https://update.googleapis.com/service/update2?cup2key=10:222280109&cup2hreq=06ecd5e13a0915da810207ca9da9eb99e4a57f12b3a6ecdb04eddd431963152e |
request | GET https://t8u4n6u7.ssl.hwcdn.net/stats.gif?data=Fx4HQFaG74sgz1qVBX5E30jRtp8%2FMb8i%2BWkMHPsNYRFOedtmFFGapX6fYXlz79LZ0WDxLEDEHl9QYlhMR89wtMw7KJo3H79m7ebt89yHSGaBmCVNKwp4%2BFWEIJsU1PEWAhz9vByYQyukNfAD2KJexaY3QKKvNtRqjlkv69U6JD9dj%2BcxBa9AJtLU7a9Wl36Y%2BnhRoOch1TwF297SL%2Fd%2Ba9tSP16W5ByqslgiWJtaEJU74YuFX2Yh6T3Ql58tYj8y1R3tEAA1RQqsh9GoAEzeVkJQuk2%2FLUq4X9Nps2Q7Ds2oTpGpuRw5l2I4FiQ1PexolR9VbBSETIOJEfExHXfliFdU9B0P6JJpaXYnEh14bVa7AODS5oHvcU4RQP7qy76EegMedpXadr5JbspqcuSd8nK9blnH%2F3Lg0IirtQiaAfj3Oh7FJn%2BTTPnaDplxRodqggJkBrddX%2BH%2FHR73GFMgzR%2BfHZ%2BjUdzE4dMAFhL5Lr484jL8w56dSU6txufflAi4iAu%2FtOVwy8vMoh9%2FBB5xkc%2FGKrs3mYoeT9VtDJ3OOsDGgIYAvQfZoP47fIOt13kKSXdooldLhGNLrEUnnIfifzbAlBY15BTaSEUSWgN8pKo%2BMsZigyu2JWntsJ1Uu6ZEbhbn2YT1IZo11JZnbYysH%2BYQSRBh913HwOa%2Fy0h4cZU%3D |
request | POST https://update.googleapis.com/service/update2?cup2key=10:222280109&cup2hreq=06ecd5e13a0915da810207ca9da9eb99e4a57f12b3a6ecdb04eddd431963152e |
registry | HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox |
registry | HKEY_CURRENT_USER\Software\Mozilla\Mozilla Firefox |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nst5A71.tmp\StdUtils.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nst5A71.tmp\internal60c7c72a6ae9352fa4e0338ef21c87ab.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nst5A71.tmp\internal60c7c72a6ae9352fa4e0338ef21c87ab.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nst5A71.tmp\StdUtils.dll |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620983811.134501 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |
host | 172.217.24.14 |
Bkav | W32.HfsAdware.D664 |
K7AntiVirus | Riskware ( 005475191 ) |
CAT-QuickHeal | Trojan.CGeneric |
K7GW | Riskware ( 005475191 ) |
TrendMicro | PUA.Win32.PlayTech.AK.component |
TrendMicro-HouseCall | PUA.Win32.PlayTech.AK.component |
Paloalto | generic.ml |
Invincea | heuristic |
McAfee-GW-Edition | BehavesLike.Win32.Suspicious.bc |
Antiy-AVL | GrayWare[AdWare]/Win32.PlayTech.a |
Microsoft | PUA:Win32/Playtech |
Zoner | PUA.Win32.65045 |
ESET-NOD32 | Win32/PlayTech.A potentially unwanted |
Rising | PUA.CrossRider!8.84 (CLOUD) |
CrowdStrike | win/malicious_confidence_60% (D) |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob |