查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
---|---|---|---|
McAfee | Artemis!8A2EC7C0246D | 20201202 | 6.0.6.653 |
Baidu | 20190318 | 1.0.0.2 | |
Alibaba | 20190527 | 0.3.0.5 | |
Tencent | 20201202 | 1.0.0.1 | |
Kingsoft | 20201202 | 2017.9.26.565 | |
CrowdStrike | 20190702 | 1.0 |
registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
registry | HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Mozilla Firefox |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\firefox.exe |
section | .ndata |
suspicious_features | POST method with no referer header | suspicious_request | POST https://update.googleapis.com/service/update2?cup2key=10:1157571492&cup2hreq=b6d00d388204ebf7b10f62ff4eda4c58b6aa6f2bad9841b9f5978ea6cab0a129 |
request | GET http://c6m7w2m9.ssl.hwcdn.net/playtech_compressed_assets/poker_dafa/index.7ze |
request | GET http://fallback.playtech-installer.com/playtech_compressed_assets/poker_dafa/index.7ze |
request | GET http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
request | GET http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D |
request | GET http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D |
request | GET http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEHSfdSPcp6pyLdnEz5lZ6ec%3D |
request | GET http://fallback.playtech-installer.com/playtech_compressed_assets/poker_dafa/templates/installer/new.7ze |
request | HEAD http://redirector.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe |
request | HEAD http://r1---sn-j5o76n7l.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.99&mm=28&mn=sn-j5o76n7l&ms=nvh&mt=1620927630&mv=m&mvi=1&pl=23&shardbypass=yes |
request | GET https://t8u4n6u7.ssl.hwcdn.net/stats.gif?data=XpTUP2h4XLebr67L8%2BT4Kur2d8hcows4lLP5%2ByfGgTzOK6oVj1e6XIfD8OLumam%2BAMvGctLbPM9qdqQOA9SQMgfD9zXJnFaxuvW9EkIncqpSm%2BJY0dFkeCcqMIrZr5ZxVxVtpJCr773BgytWr5%2BQQtgmaZ0PdPRXn6IiTCNo%2BmBJ6fdr4IqAgKPX85QY0%2FXZ6Ka34ppm7RAH4A%2BZmrmLvOtUP%2FiQq6Rwu4tqaB%2F%2F4%2FEBpY8SJXaiNcAKc3TGSCe9U7yfL7SmCgc6YhVCWkXTXb9UY9qRkOA3GLGyuW0QQ3RNhNmshPJQdBQT0O0tNfx7Pv%2BIKn6mMIe3WEiSjTxEKcZY5txRirtHw%2BGTe8C%2BwsKQrzXkuWk1ATPilVwQD5OiqRafuCB%2F9dcY72GZj0bRjxp26ZWBJ17u%2B%2BwlkZz6txcjlIobnyNCa%2Fvz7aI3%2BVsqdKQJAEPGparAHqE%2F7jcUCCULsskOjEYFJKvqZRCNsTs8K%2Fthas0e%2FRxGG%2F%2BMs0h8vW%2FWOUhgAzo%2Fddind9CyEqwu9RttcIzcPqpdsZ8n0DEJbBigFHz2UaQLYueGuoVBin6qNUD%2Bqv283XS2U5QYmzAhYckeYXy2nrxzNH4QYK%2FD7NJazLGzbVpwiXzByxi29zw9FHWBWniI5kprumxCYtKnSEeoNrmgvm8jT14haAE%3D |
request | GET https://t8u4n6u7.ssl.hwcdn.net/stats.gif?data=PEOUs7zGPGDtemJb%2FGRb%2F%2BviumaVZay3MmwrZGPiFoq3bvbhldQxgd2cRWcZc3pCvQQU5EqRWYrXd4Hlaz9%2BxTA8qycRHMHEhoyjc3OWC0aiM7nUJ%2BbCi%2B4OZ8J5ARmmpeKh8T0M%2BTaRURnrBx1xQQOzoud6yFYqnRZiR8xRr0x9t1FZl93P1i0rkIpNC3PTUhJ%2FgNI9X54nemUbyVEqEMC2ExnM0Xp0Wju54962lBW6otQKY6nU0wVhFyUiorBWvSCWGY6y1OL0mA1%2FARXGcXoeFireGP%2FVrQAaGaeThuLAbvgip8LdXtIC1wkOoBvXCeUkyYqBWAs5eWZZxkBbJjJBHavqdWr0b07thshLkFAKaefDqCaDl7n7WW4z3AswcnMn6sNsDNcum31sJ3VtQc5rBbQujhzj323Rj3kA0ge%2FwxOACeCExRWp0ShO%2FYfsS0V1NHImIlPcVcnCfKlkzl5nmv49mqHUIdEcykJtr3BzIEakBI36wn%2BRnB6Eu%2FIS4KUkQWD8Z4hEjScfjORD%2BiHPGmWOw%2BBnAs098dSy%2FYKshEElGDf4nqP0GRn52jiT8loI1T16HP09bmx6un4FQTb5ePGWDa10O0RRzuZKs%2B15fF4k7fSDLUdZD0CVkirZVyxz1QVwjBluSx0qCVyMzfv048Qh%2BzXqVETopRnsp28%3D |
request | GET https://c6m7w2m9.ssl.hwcdn.net/playtech_compressed_assets/poker_dafa/templates/installer/new.7ze |
request | POST https://update.googleapis.com/service/update2?cup2key=10:1157571492&cup2hreq=b6d00d388204ebf7b10f62ff4eda4c58b6aa6f2bad9841b9f5978ea6cab0a129 |
request | POST https://update.googleapis.com/service/update2?cup2key=10:1157571492&cup2hreq=b6d00d388204ebf7b10f62ff4eda4c58b6aa6f2bad9841b9f5978ea6cab0a129 |
registry | HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox |
registry | HKEY_CURRENT_USER\Software\Mozilla\Mozilla Firefox |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nse6222.tmp\internal8a2ec7c0246d9e2b42cd42e3e93a1d46.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nse6222.tmp\internal8a2ec7c0246d9e2b42cd42e3e93a1d46.exe |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620956572.279249 Process32NextW |
process_name:
pythonw.exe
snapshot_handle: 0x00000390 process_identifier: 2504 |
success | 1 | 0 |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620956573.341249 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |
host | 172.217.24.14 |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob |