| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| Alibaba | Trojan:Win32/NetWire.6cc74a37 | 20190527 | 0.3.0.5 |
| Baidu | 20190318 | 1.0.0.2 | |
| Avast | Win32:Trojan-gen | 20201227 | 21.1.5827.0 |
| Tencent | Win32.Trojan.Netwire.Ecun | 20201227 | 1.0.0.1 |
| Kingsoft | 20201227 | 2017.9.26.565 | |
| McAfee | RDN/Generic.grp | 20201227 | 6.0.6.653 |
| CrowdStrike | win/malicious_confidence_70% (W) | 20190702 | 1.0 |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1619694399.918374 IsDebuggerPresent |
failed | 0 | 0 | |
|
1619694399.934374 IsDebuggerPresent |
failed | 0 | 0 | |
|
1619694413.543249 IsDebuggerPresent |
failed | 0 | 0 |
| pdb_path | D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb |
| section | .gfids |
| resource name | PNG |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\75399505\ubxblwi.pdf |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\75399505\uvvjqllj.docx |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\75399505\bvqwe.xls |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\75399505\qnobmqxm.ppt |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\75399505\nfxnnhj.pdf |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\75399505\kopqbag.docx |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\75399505\qscxgm.pdf |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\75399505\ljmlxaowb.vbs |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\75399505\clvcgtxdlo.pif |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\75399505\qfhw.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\75399505\ourvxdtr.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\75399505\uuedtf.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\75399505\itdqp.cpl |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\75399505\abgionriu.cpl |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\75399505\vtssuai.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\75399505\mkjht.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\75399505\clvcgtxdlo.pif |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\75399505\clvcgtxdlo.pif |
| process | regsvcs.exe |
| buffer | Buffer with sha1: 86c4889d43f14293a8c89cf928b487641304697c |
| buffer | Buffer with sha1: 50654f42a5aeac70c61839037b6b81df8a02d6c6 |
| host | 154.16.93.179 | |||
| host | 172.217.24.14 | |||
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\WindowsUpdate | reg_value | 0\75399505\clvcgtxdlo.pif 0\75399505\mtlfndvtbb.ugp | ||||||