| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| CrowdStrike | win/malicious_confidence_70% (W) | 20190702 | 1.0 |
| Alibaba | Trojan:Win32/runner.ali1000123 | 20190527 | 0.3.0.5 |
| Avast | Win32:Trojan-gen | 20201210 | 21.1.5827.0 |
| Baidu | 20190318 | 1.0.0.2 | |
| Kingsoft | 20201211 | 2017.9.26.565 | |
| McAfee | RDN/Generic.grp | 20201211 | 6.0.6.653 |
| Tencent | 20201211 | 1.0.0.1 |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1619786023.16 IsDebuggerPresent |
failed | 0 | 0 | |
|
1619786023.16 IsDebuggerPresent |
failed | 0 | 0 | |
|
1619786031.863375 IsDebuggerPresent |
failed | 0 | 0 |
| pdb_path | D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb |
| section | .gfids |
| resource name | PNG |
| file | C:\Users\Administrator.Oskar-PC\56444627\wqvet.docx |
| file | C:\Users\Administrator.Oskar-PC\56444627\qlvi.pdf |
| file | C:\Users\Administrator.Oskar-PC\56444627\thiaw.ppt |
| file | C:\Users\Administrator.Oskar-PC\56444627\iuxn.pdf |
| file | C:\Users\Administrator.Oskar-PC\56444627\endg.docx |
| file | C:\Users\Administrator.Oskar-PC\56444627\hcdw.pif |
| file | C:\Users\Administrator.Oskar-PC\56444627\awjphstea.vbs |
| file | C:\Users\Administrator.Oskar-PC\56444627\nftijsllrb.dll |
| file | C:\Users\Administrator.Oskar-PC\56444627\urkahq.cpl |
| file | C:\Users\Administrator.Oskar-PC\56444627\hrvusamwsp.dll |
| file | C:\Users\Administrator.Oskar-PC\56444627\hcdw.pif |
| process | regsvcs.exe |
| buffer | Buffer with sha1: f36e025a5bb6e391e14ae81a570d09483241dd4c |
| buffer | Buffer with sha1: 86c4889d43f14293a8c89cf928b487641304697c |
| host | 154.16.93.179 | |||
| host | 172.217.24.14 | |||
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\WindowsUpdate | reg_value | 0\56444627\hcdw.pif 0\56444627\khsn.ndx | ||||||