查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
---|---|---|---|
Alibaba | 20190527 | 0.3.0.5 | |
Baidu | 20190318 | 1.0.0.2 | |
Avast | 20200910 | 18.4.3895.0 | |
Tencent | 20200910 | 1.0.0.1 | |
Kingsoft | 20200910 | 2013.8.14.323 | |
McAfee | Artemis!76F828EB3FB8 | 20200910 | 6.0.6.653 |
CrowdStrike | 20190702 | 1.0 |
section | .ndata |
suspicious_features | HTTP version 1.0 used | suspicious_request | GET http://logs.bytefence.com/event?Eventname=NsisInstaller&status=Start&Product=ByteFence&i_data=&ruserid=&tag=2.0.50727&OSVersion=6.1.0.0&version=5.4.1.13&tag2={00000000-0000-0000-0000-000000000000} | ||||||
suspicious_features | HTTP version 1.0 used | suspicious_request | GET http://logs.bytefence.com/event?Eventname=NsisInstaller&status=Finish&Product=ByteFence&i_data=&ruserid=&tag=2.0.50727&OSVersion=6.1.0.0&version=5.4.1.13&tag2={00000000-0000-0000-0000-000000000000} |
request | GET http://logs.bytefence.com/event?Eventname=NsisInstaller&status=Start&Product=ByteFence&i_data=&ruserid=&tag=2.0.50727&OSVersion=6.1.0.0&version=5.4.1.13&tag2={00000000-0000-0000-0000-000000000000} |
request | GET http://logs.bytefence.com/event?Eventname=NsisInstaller&status=Finish&Product=ByteFence&i_data=&ruserid=&tag=2.0.50727&OSVersion=6.1.0.0&version=5.4.1.13&tag2={00000000-0000-0000-0000-000000000000} |
file | C:\Program Files\ByteFence\rsEngineHelper.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsnA46A.tmp\nsExec.dll |
file | C:\Program Files\ByteFence\x64\rsEngineFW_x64.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsnA46A.tmp\nsDialogs.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsnA46A.tmp\System.dll |
file | C:\Program Files\ByteFence\websocket-sharp.dll |
file | C:\Program Files\ByteFence\x86\ext_x86.dll |
file | C:\Program Files\ByteFence\x86\msdia140.dll |
file | C:\Program Files\ByteFence\x86\lz4_x86.dll |
file | C:\Program Files\ByteFence\amd64\KernelTraceControl.dll |
file | C:\Program Files\ByteFence\x64\rsEnginePM_x64.dll |
file | C:\Program Files\ByteFence\ByteFence.exe |
file | C:\Program Files\ByteFence\ByteFenceGUI.dll |
file | C:\Program Files\ByteFence\x64\rsLggrServer_x64.dll |
file | C:\Program Files\ByteFence\amd64\msdia140.dll |
file | C:\Program Files\ByteFence\x64\ext_x64.dll |
file | C:\Program Files\ByteFence\x86\rsLggrServer_x86.dll |
file | C:\Program Files\ByteFence\ByteFenceService.exe |
file | C:\Program Files\ByteFence\Uninstall.exe |
file | C:\Program Files\ByteFence\x86\rsEngineFW_x86.dll |
file | C:\Program Files\ByteFence\x86\7z86.dll |
file | C:\Program Files\ByteFence\Microsoft.Diagnostics.Tracing.TraceEvent.dll |
file | C:\Program Files\ByteFence\rsEngine.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsnA46A.tmp\nsisdl.dll |
file | C:\Program Files\ByteFence\x64\7z64.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\InstallTools.exe |
file | C:\Program Files\ByteFence\x64\System.Data.SQLite.dll |
file | C:\Program Files\ByteFence\x64\lz4_x64.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\bytefence-installer-5.4.1.13.exe |
file | C:\Program Files\ByteFence\Microsoft.Win32.TaskScheduler.dll |
file | C:\Program Files\ByteFence\rsUtils.dll |
file | C:\Program Files\ByteFence\ByteFenceScan.exe |
file | C:\Program Files\ByteFence\x86\KernelTraceControl.dll |
file | C:\Program Files\ByteFence\rsMessages.dll |
file | C:\Program Files\ByteFence\x86\rsEnginePM_x86.dll |
file | C:\Program Files\ByteFence\protobuf-net.dll |
file | C:\Program Files\ByteFence\x86\System.Data.SQLite.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsnA46A.tmp\nsisdl.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\InstallTools.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsnA46A.tmp\nsDialogs.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsnA46A.tmp\nsExec.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsnA46A.tmp\System.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\bytefence-installer-5.4.1.13.exe |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "ByteFenceScan.exe") |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "ByteFenceService.exe") |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "rsEngineHelper.exe") |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "ByteFence.exe") |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "rsLggr.exe") |
cmdline | taskkill /f /im ByteFenceScan.exe |
cmdline | taskkill /f /im rsLggr.exe |
cmdline | taskkill /f /im ByteFence.exe |
cmdline | taskkill /f /im rsEngineHelper.exe |
cmdline | taskkill /f /im ByteFenceService.exe |
host | 172.217.24.14 | |||
host | 192.35.177.64 |
Cylance | Unsafe |
K7AntiVirus | Trojan ( 00555f5d1 ) |
K7GW | Riskware ( dec003101 ) |
Cyren | W32/Trojan.RFDL-4325 |
ClamAV | Win.Dropper.Wanna-6651539-0 |
DrWeb | Program.Unwanted.4920 |
Invincea | ByteFence Anti-Malware (PUA) |
Sophos | ByteFence Anti-Malware (PUA) |
Microsoft | Misleading:Win32/Fybents |
GData | Win32.Trojan.Agent.C0P2B6 |
McAfee | Artemis!76F828EB3FB8 |
Malwarebytes | PUP.Optional.ByteFence |
ESET-NOD32 | MSIL/ByteFence.C potentially unwanted |
dead_host | 192.168.56.101:49181 |
No hosts contacted.
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 49209 | 216.58.200.78 clients2.google.com | 443 |
192.168.56.101 | 49252 | 216.58.200.78 clients2.google.com | 443 |
192.168.56.101 | 49182 | 52.73.13.23 logs.bytefence.com | 80 |
192.168.56.101 | 49204 | 52.73.13.23 logs.bytefence.com | 80 |
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 49713 | 114.114.114.114 | 53 |
192.168.56.101 | 50002 | 114.114.114.114 | 53 |
192.168.56.101 | 51808 | 114.114.114.114 | 53 |
192.168.56.101 | 57756 | 114.114.114.114 | 53 |
192.168.56.101 | 58367 | 114.114.114.114 | 53 |
192.168.56.101 | 61680 | 114.114.114.114 | 53 |
192.168.56.101 | 62318 | 114.114.114.114 | 53 |
192.168.56.101 | 137 | 192.168.56.255 | 137 |
192.168.56.101 | 138 | 192.168.56.255 | 138 |
192.168.56.101 | 123 | 20.189.79.72 time.windows.com | 123 |
192.168.56.101 | 49235 | 224.0.0.252 | 5355 |
192.168.56.101 | 50534 | 224.0.0.252 | 5355 |
192.168.56.101 | 50568 | 224.0.0.252 | 5355 |
192.168.56.101 | 51378 | 224.0.0.252 | 5355 |
192.168.56.101 | 51963 | 224.0.0.252 | 5355 |
192.168.56.101 | 53237 | 224.0.0.252 | 5355 |
192.168.56.101 | 56804 | 224.0.0.252 | 5355 |
192.168.56.101 | 62191 | 224.0.0.252 | 5355 |
192.168.56.101 | 63429 | 224.0.0.252 | 5355 |
192.168.56.101 | 1900 | 239.255.255.250 | 1900 |
URI | Data |
---|---|
http://logs.bytefence.com/event?Eventname=NsisInstaller&status=Start&Product=ByteFence&i_data=&ruserid=&tag=2.0.50727&OSVersion=6.1.0.0&version=5.4.1.13&tag2={00000000-0000-0000-0000-000000000000} | GET /event?Eventname=NsisInstaller&status=Start&Product=ByteFence&i_data=&ruserid=&tag=2.0.50727&OSVersion=6.1.0.0&version=5.4.1.13&tag2={00000000-0000-0000-0000-000000000000} HTTP/1.0 Host: logs.bytefence.com User-Agent: NSISDL/1.2 (Mozilla) Accept: */* |
http://logs.bytefence.com/event?Eventname=NsisInstaller&status=Finish&Product=ByteFence&i_data=&ruserid=&tag=2.0.50727&OSVersion=6.1.0.0&version=5.4.1.13&tag2={00000000-0000-0000-0000-000000000000} | GET /event?Eventname=NsisInstaller&status=Finish&Product=ByteFence&i_data=&ruserid=&tag=2.0.50727&OSVersion=6.1.0.0&version=5.4.1.13&tag2={00000000-0000-0000-0000-000000000000} HTTP/1.0 Host: logs.bytefence.com User-Agent: NSISDL/1.2 (Mozilla) Accept: */* |
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts