| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| McAfee | DriverTalent | 20190401 | 6.0.6.653 |
| Alibaba | 20190401 | 0.3.0.4 | |
| Baidu | 20190318 | 1.0.0.2 | |
| Avast | 20190401 | 18.4.3895.0 | |
| Tencent | Win32.Risk.Uws.Hyah | 20190401 | 1.0.0.1 |
| Kingsoft | 20190401 | 2013.8.14.323 | |
| CrowdStrike | 20190212 | 1.0 |
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\MachineGuid |
| file | C:\Program Files\Google\Chrome\Application\chrome.exe |
| resource name | DAR |
| resource name | DATA |
| suspicious_features | POST method with no referer header | suspicious_request | POST http://os.bestupdatemeta.com/FusionOSToto_New/ | ||||||
| suspicious_features | POST method with no referer header | suspicious_request | POST http://rp.bestupdatemeta.com/ | ||||||
| suspicious_features | POST method with no referer header | suspicious_request | POST http://os2.bestupdatemeta.com/FusionOSToto_New/ | ||||||
| request | GET http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
| request | POST http://os.bestupdatemeta.com/FusionOSToto_New/ |
| request | POST http://rp.bestupdatemeta.com/ |
| request | GET http://1223.dragonparking.com/?site=os.bestupdatemeta.com |
| request | GET http://1223.dragonparking.com/?site=rp.bestupdatemeta.com |
| request | GET http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D |
| request | GET http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQS14tALDViBvqCf47YkiQRtKz1BAQUpc436uuwdQ6UZ4i0RfrZJBCHlh8CEAPcYwoSMi%2FL8DFvBZHrSfY%3D |
| request | GET http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D |
| request | GET http://crl.verisign.com/pca3-g5.crl |
| request | GET http://sf.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEE1ZQDhNmtKTlI4sQBPCBNA%3D |
| request | POST http://os2.bestupdatemeta.com/FusionOSToto_New/ |
| request | GET http://1223.dragonparking.com/?site=os2.bestupdatemeta.com |
| request | GET https://dp.diandongzhi.com/?acct=1223&site=rp.bestupdatemeta.com |
| request | GET https://dp.diandongzhi.com/?acct=1223&site=os.bestupdatemeta.com |
| request | GET https://dp.diandongzhi.com/?acct=1223&site=os2.bestupdatemeta.com |
| request | POST http://os.bestupdatemeta.com/FusionOSToto_New/ |
| request | POST http://rp.bestupdatemeta.com/ |
| request | POST http://os2.bestupdatemeta.com/FusionOSToto_New/ |
| description | 9aff9c981c046a89b172f6f26901bce7.exe tried to sleep 242 seconds, actually delayed analysis time by 242 seconds | |||
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\ZxcvbnData\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\MEIPreload\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\pnacl\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\ShaderCache\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\SafetyTips\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\SwReporter\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Floc\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\OriginTrials\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\ThirdPartyModuleList64\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Subresource Filter\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\TLSDeprecationConfig\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\ |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Safe Browsing\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\BrowserMetrics\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\hyphen-data\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Cache\ |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Crowd Deny\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\FontLookupTableCache\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\FileTypePolicies\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Crashpad\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\CertificateRevocation\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\AutofillStates\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\WidevineCdm\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\RecoveryImproved\Cache |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\GrShaderCache\Cache |
| name | DAR | language | LANG_CHINESE | offset | 0x0101accc | filetype | Lua bytecode, | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x0000d88a | ||||||||||||||||||
| name | DAR | language | LANG_CHINESE | offset | 0x0101accc | filetype | Lua bytecode, | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x0000d88a | ||||||||||||||||||
| name | DAR | language | LANG_CHINESE | offset | 0x0101accc | filetype | Lua bytecode, | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x0000d88a | ||||||||||||||||||
| name | DATA | language | LANG_CHINESE | offset | 0x01d8a974 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x001df8ef | ||||||||||||||||||
| name | DATA | language | LANG_CHINESE | offset | 0x01d8a974 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x001df8ef | ||||||||||||||||||
| name | RT_ICON | language | LANG_CHINESE | offset | 0x01f98560 | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000468 | ||||||||||||||||||
| name | RT_ICON | language | LANG_CHINESE | offset | 0x01f98560 | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000468 | ||||||||||||||||||
| name | RT_ICON | language | LANG_CHINESE | offset | 0x01f98560 | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000468 | ||||||||||||||||||
| name | RT_ICON | language | LANG_CHINESE | offset | 0x01f98560 | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000468 | ||||||||||||||||||
| name | RT_ICON | language | LANG_CHINESE | offset | 0x01f98560 | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000468 | ||||||||||||||||||
| name | RT_ICON | language | LANG_CHINESE | offset | 0x01f98560 | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000468 | ||||||||||||||||||
| name | RT_ICON | language | LANG_CHINESE | offset | 0x01f98560 | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000468 | ||||||||||||||||||
| name | RT_ICON | language | LANG_CHINESE | offset | 0x01f98560 | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000468 | ||||||||||||||||||
| name | RT_ICON | language | LANG_CHINESE | offset | 0x01f98560 | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000468 | ||||||||||||||||||
| name | RT_DIALOG | language | LANG_CHINESE | offset | 0x01f989cc | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000072 | ||||||||||||||||||
| name | RT_GROUP_ICON | language | LANG_CHINESE | offset | 0x01f98a44 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000084 | ||||||||||||||||||
| name | RT_VERSION | language | LANG_CHINESE | offset | 0x01f98acc | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x00000554 | ||||||||||||||||||
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\Fusion.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\Hot96CC.tmp\DTInstUI.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\Hot96CC.tmp\substat.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\Hot96CC.tmp\pcid.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\Hot96CC.tmp\AdModule.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\Hot96CC.tmp\DTInstUI.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\Hot96CC.tmp\substat.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\Fusion.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\Hot96CC.tmp\pcid.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\Hot96CC.tmp\AdModule.dll |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1620825102.865374 GetAdaptersAddresses |
flags:
15
family: 0 |
failed | 111 | 0 |
| entropy | 7.922369539981519 | section | {'size_of_data': '0x00038000', 'virtual_address': '0x00fdc000', 'entropy': 7.922369539981519, 'name': 'UPX1', 'virtual_size': '0x00038000'} | description | A section with a high entropy has been found | |||||||||
| entropy | 7.994933216784226 | section | {'size_of_data': '0x00f85800', 'virtual_address': '0x01014000', 'entropy': 7.994933216784226, 'name': '.rsrc', 'virtual_size': '0x00f86000'} | description | A section with a high entropy has been found | |||||||||
| entropy | 1.0 | description | Overall entropy of this PE file is high | |||||||||||
| process | 9aff9c981c046a89b172f6f26901bce7.exe |
| section | UPX0 | description | Section name indicates UPX | ||||||
| section | UPX1 | description | Section name indicates UPX | ||||||
| host | 172.217.24.14 | |||
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\9aff9c981c046a89b172f6f26901bce7.exe:Zone.Identifier:$DATA |
| registry | HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion |
| registry | HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString |
| K7AntiVirus | Trojan ( 00523a021 ) |
| McAfee | DriverTalent |
| Malwarebytes | PUP.Optional.DriveTheLife |
| K7GW | Trojan ( 00523a021 ) |
| Cyren | W32/Trojan.NGKA-4994 |
| ESET-NOD32 | a variant of Win32/UwS.DriverTalent.A |
| Tencent | Win32.Risk.Uws.Hyah |
| McAfee-GW-Edition | DriverTalent |
| Sophos | Driver Talent (PUA) |
| Microsoft | PUA:Win32/SuspiciousProcStarter |
| Endgame | malicious (moderate confidence) |
| Rising | Malware.Undefined!8.C (CLOUD) |
| Fortinet | W32/Driver_Talent.A |
| Qihoo-360 | Trojan.Generic |
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob |
No hosts contacted.
| Source | Source Port | Destination | Destination Port |
|---|---|---|---|
| 192.168.56.101 | 49192 | 104.207.153.254 1223.dragonparking.com | 80 |
| 192.168.56.101 | 49195 | 117.18.237.29 ocsp.digicert.com | 80 |
| 192.168.56.101 | 49198 | 117.18.237.29 ocsp.digicert.com | 80 |
| 192.168.56.101 | 49185 | 124.225.105.97 www.download.windowsupdate.com | 80 |
| 192.168.56.101 | 49193 | 172.67.70.101 dp.diandongzhi.com | 443 |
| 192.168.56.101 | 49194 | 172.67.70.101 dp.diandongzhi.com | 443 |
| 192.168.56.101 | 49190 | 204.11.56.48 os.bestupdatemeta.com | 80 |
| 192.168.56.101 | 49191 | 204.11.56.48 os.bestupdatemeta.com | 80 |
| 192.168.56.101 | 49201 | 204.11.56.48 os.bestupdatemeta.com | 80 |
| 192.168.56.101 | 49205 | 204.11.56.48 os.bestupdatemeta.com | 80 |
| 192.168.56.101 | 49206 | 204.11.56.48 os.bestupdatemeta.com | 80 |
| 192.168.56.101 | 49207 | 204.11.56.48 os.bestupdatemeta.com | 80 |
| 192.168.56.101 | 49196 | 23.52.155.27 sf.symcd.com | 80 |
| 192.168.56.101 | 49199 | 23.52.155.27 sf.symcd.com | 80 |
| Source | Source Port | Destination | Destination Port |
|---|---|---|---|
| 192.168.56.101 | 50320 | 114.114.114.114 | 53 |
| 192.168.56.101 | 51963 | 114.114.114.114 | 53 |
| 192.168.56.101 | 52812 | 114.114.114.114 | 53 |
| 192.168.56.101 | 53210 | 114.114.114.114 | 53 |
| 192.168.56.101 | 53500 | 114.114.114.114 | 53 |
| 192.168.56.101 | 54178 | 114.114.114.114 | 53 |
| 192.168.56.101 | 56743 | 114.114.114.114 | 53 |
| 192.168.56.101 | 57995 | 114.114.114.114 | 53 |
| 192.168.56.101 | 58070 | 114.114.114.114 | 53 |
| 192.168.56.101 | 58333 | 114.114.114.114 | 53 |
| 192.168.56.101 | 58367 | 114.114.114.114 | 53 |
| 192.168.56.101 | 59990 | 114.114.114.114 | 53 |
| 192.168.56.101 | 60123 | 114.114.114.114 | 53 |
| 192.168.56.101 | 60215 | 114.114.114.114 | 53 |
| 192.168.56.101 | 60911 | 114.114.114.114 | 53 |
| 192.168.56.101 | 61908 | 114.114.114.114 | 53 |
| 192.168.56.101 | 63429 | 114.114.114.114 | 53 |
| 192.168.56.101 | 63802 | 114.114.114.114 | 53 |
| 192.168.56.101 | 64874 | 114.114.114.114 | 53 |
| 192.168.56.101 | 137 | 192.168.56.255 | 137 |
| URI | Data |
|---|---|
| http://crl.verisign.com/pca3-g5.crl | GET /pca3-g5.crl HTTP/1.1 Connection: Keep-Alive Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: crl.verisign.com |
| http://os.bestupdatemeta.com/FusionOSToto_New/ | POST /FusionOSToto_New/ HTTP/1.1 Accept: */* Host: os.bestupdatemeta.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2 Content-Length: 2688 Cache-Control: no-cache |
| http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQS14tALDViBvqCf47YkiQRtKz1BAQUpc436uuwdQ6UZ4i0RfrZJBCHlh8CEAPcYwoSMi%2FL8DFvBZHrSfY%3D | GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBQS14tALDViBvqCf47YkiQRtKz1BAQUpc436uuwdQ6UZ4i0RfrZJBCHlh8CEAPcYwoSMi%2FL8DFvBZHrSfY%3D HTTP/1.1 Connection: Keep-Alive Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: ocsp.digicert.com |
| http://1223.dragonparking.com/?site=os.bestupdatemeta.com | GET /?site=os.bestupdatemeta.com HTTP/1.1 Accept: */* Connection: Keep-Alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2 Cache-Control: no-cache Host: 1223.dragonparking.com |
| http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D | GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEFIA5aolVvwahu2WydRLM8c%3D HTTP/1.1 Cache-Control: no-cache Connection: Keep-Alive Pragma: no-cache Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: ocsp.verisign.com |
| http://rp.bestupdatemeta.com/ | POST / HTTP/1.1 Accept: */* Host: rp.bestupdatemeta.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2 Content-Length: 1536 Cache-Control: no-cache |
| http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D | GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D HTTP/1.1 Connection: Keep-Alive Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: ocsp.digicert.com |
| http://sf.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEE1ZQDhNmtKTlI4sQBPCBNA%3D | GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTSqZMG5M8TA9rdzkbCnNwuMAd5VgQUz5mp6nsm9EvJjo%2FX8AUm7%2BPSp50CEE1ZQDhNmtKTlI4sQBPCBNA%3D HTTP/1.1 Connection: Keep-Alive Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: sf.symcd.com |
| http://os2.bestupdatemeta.com/FusionOSToto_New/ | POST /FusionOSToto_New/ HTTP/1.1 Accept: */* Host: os2.bestupdatemeta.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2 Content-Length: 2688 Cache-Control: no-cache |
| http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1 Cache-Control: max-age = 900 Connection: Keep-Alive Accept: */* If-Modified-Since: Mon, 19 Apr 2021 20:17:25 GMT If-None-Match: "80f8835935d71:0" User-Agent: Microsoft-CryptoAPI/6.1 Host: www.download.windowsupdate.com |
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts