| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| McAfee | GenericRXAA-AA!98FEED3D432C | 20201211 | 6.0.6.653 |
| Alibaba | Backdoor:Win32/Remcos.490feee7 | 20190527 | 0.3.0.5 |
| CrowdStrike | win/malicious_confidence_100% (W) | 20190702 | 1.0 |
| Baidu | 20190318 | 1.0.0.2 | |
| Avast | AutoIt:Injector-JF [Trj] | 20201210 | 21.1.5827.0 |
| Tencent | Malware.Win32.Gencirc.10b0d104 | 20201211 | 1.0.0.1 |
| Kingsoft | Win32.Heur.KVM007.a.(kcloud) | 20201211 | 2017.9.26.565 |
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
| file | C:\Program Files\Google\Chrome\Application\89.0.4389.114\chrome.dll |
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\chrome.exe\PATH |
| domain | daya4659.ddns.net |
| description | remcos.exe tried to sleep 142 seconds, actually delayed analysis time by 142 seconds | |||
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\CrashpadMetrics-spare.pma |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Crashpad\reports |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\First Run |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\BrowserMetrics-spare.pma |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\BrowserMetrics |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\ |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma~RF6f6c4a.TMP |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Local State |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-608BEC0C-848.pma |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Crashpad\metadata |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Crashpad |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\CrashpadMetrics-active.pma |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\medical-application-form.pdf |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\install.vbs |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\CapabilityAccessHandlers\sfc.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\RtDCpl64\driverquery.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos_agent_Protected.exe |
| cmdline | schtasks /create /tn WWAHost /tr "C:\Users\Administrator.Oskar-PC\AppData\Roaming\RtDCpl64\driverquery.exe" /sc minute /mo 1 /F |
| cmdline | "C:\Windows\SysWOW64\schtasks.exe" /create /tn WWAHost /tr "C:\Users\Administrator.Oskar-PC\AppData\Roaming\RtDCpl64\driverquery.exe" /sc minute /mo 1 /F |
| cmdline | "C:\Windows\System32\cmd.exe" /c "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" |
| cmdline | schtasks /create /tn setx /tr "C:\Users\Administrator.Oskar-PC\AppData\Roaming\CapabilityAccessHandlers\sfc.exe" /sc minute /mo 1 /F |
| cmdline | "C:\Windows\SysWOW64\schtasks.exe" /create /tn setx /tr "C:\Users\Administrator.Oskar-PC\AppData\Roaming\CapabilityAccessHandlers\sfc.exe" /sc minute /mo 1 /F |
| cmdline | C:\Windows\SysWOW64\svchost.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos_agent_Protected.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\medical-application-form.pdf |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\install.vbs |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos_agent_Protected.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\CapabilityAccessHandlers\sfc.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\RtDCpl64\driverquery.exe |
| cmdline | schtasks /create /tn WWAHost /tr "C:\Users\Administrator.Oskar-PC\AppData\Roaming\RtDCpl64\driverquery.exe" /sc minute /mo 1 /F |
| cmdline | "C:\Windows\SysWOW64\schtasks.exe" /create /tn WWAHost /tr "C:\Users\Administrator.Oskar-PC\AppData\Roaming\RtDCpl64\driverquery.exe" /sc minute /mo 1 /F |
| cmdline | schtasks /create /tn setx /tr "C:\Users\Administrator.Oskar-PC\AppData\Roaming\CapabilityAccessHandlers\sfc.exe" /sc minute /mo 1 /F |
| cmdline | "C:\Windows\SysWOW64\schtasks.exe" /create /tn setx /tr "C:\Users\Administrator.Oskar-PC\AppData\Roaming\CapabilityAccessHandlers\sfc.exe" /sc minute /mo 1 /F |
| buffer | Buffer with sha1: 131bff97dddde4dd254389e5cad75a3161a5c20f |
| buffer | Buffer with sha1: acaf4da504194a6727f8ff9d9141e640f454ae9b |
| buffer | Buffer with sha1: b123672a43a2e85b1248281905693a6721982fc5 |
| host | 172.217.24.14 | |||
| reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\remcos | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\remcos\remcos.exe" | ||||||
| cmdline | schtasks /create /tn WWAHost /tr "C:\Users\Administrator.Oskar-PC\AppData\Roaming\RtDCpl64\driverquery.exe" /sc minute /mo 1 /F | ||||||||
| cmdline | "C:\Windows\SysWOW64\schtasks.exe" /create /tn WWAHost /tr "C:\Users\Administrator.Oskar-PC\AppData\Roaming\RtDCpl64\driverquery.exe" /sc minute /mo 1 /F | ||||||||
| cmdline | schtasks /create /tn setx /tr "C:\Users\Administrator.Oskar-PC\AppData\Roaming\CapabilityAccessHandlers\sfc.exe" /sc minute /mo 1 /F | ||||||||
| cmdline | "C:\Windows\SysWOW64\schtasks.exe" /create /tn setx /tr "C:\Users\Administrator.Oskar-PC\AppData\Roaming\CapabilityAccessHandlers\sfc.exe" /sc minute /mo 1 /F | ||||||||