查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
---|---|---|---|
Alibaba | Trojan:Win32/Emotet.93c5e3e6 | 20190527 | 0.3.0.5 |
Baidu | 20190318 | 1.0.0.2 | |
Avast | Win32:Malware-gen | 20210309 | 21.1.5827.0 |
Tencent | Malware.Win32.Gencirc.10cde54c | 20210309 | 1.0.0.1 |
Kingsoft | 20210309 | 2017.9.26.565 | |
McAfee | Emotet-FRI!7CBC5A049D35 | 20210309 | 6.0.6.653 |
CrowdStrike | win/malicious_confidence_100% (W) | 20210203 | 1.0 |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620951550.79675 GetComputerNameA |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
packer | Armadillo v1.71 |
name | RT_ICON | language | LANG_CHINESE | offset | 0x0000f4c8 | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000128 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | offset | 0x0000f4c8 | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000128 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_CHINESE | offset | 0x0000f5f0 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000022 |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620951551.40675 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |
entropy | 7.77796948906129 | section | {'size_of_data': '0x00009000', 'virtual_address': '0x00006000', 'entropy': 7.77796948906129, 'name': '.data', 'virtual_size': '0x00008778'} | description | A section with a high entropy has been found | |||||||||
entropy | 0.6 | description | Overall entropy of this PE file is high |
process | 7cbc5a049d3589efce7c9c0848a25886.exe |
host | 172.217.24.14 | |||
host | 212.51.142.238 | |||
host | 76.27.179.47 |