| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1619721619.534626 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
|
1619721619.549626 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
| suspicious_features | POST method with no referer header | suspicious_request | POST https://update.googleapis.com/service/update2?cup2key=10:1042157151&cup2hreq=5967685af06203fda52f846d5ed7f43157d63328ff65e19e4ece518390a546f9 | ||||||
| domain | rem-pounds.ddns.net |
| request | HEAD http://redirector.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe |
| request | HEAD http://r1---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.100&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1619692577&mv=m&mvi=1&pl=23&shardbypass=yes |
| request | HEAD http://r3---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&mvi=3&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5ok7e&req_id=e22c4ba72a38461b&cms_redirect=yes&ipbypass=yes&mip=59.50.85.19&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1619692577&mv=m |
| request | POST https://update.googleapis.com/service/update2?cup2key=10:1042157151&cup2hreq=5967685af06203fda52f846d5ed7f43157d63328ff65e19e4ece518390a546f9 |
| request | POST https://update.googleapis.com/service/update2?cup2key=10:1042157151&cup2hreq=5967685af06203fda52f846d5ed7f43157d63328ff65e19e4ece518390a546f9 |
| description | 846db618421d39b1a21b27749fe28005.exe tried to sleep 260 seconds, actually delayed analysis time by 260 seconds | |||
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WMPDMC.lnk |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\klist\drvinst.exe.bat |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WMPDMC.lnk |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\klist\drvinst.exe.bat |
| process | 846db618421d39b1a21b27749fe28005.exe |
| buffer | Buffer with sha1: 6814db9bf5ba7822eda634d228c3f1c1bb18897b |
| buffer | Buffer with sha1: 9e1aaa3d54f5452f0460ed392e8a988af809a937 |
| host | 172.217.24.14 | |||
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WMPDMC.lnk |