| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| McAfee | PUP-FXK | 20190809 | 6.0.6.653 |
| Alibaba | 20190527 | 0.3.0.5 | |
| Baidu | 20190318 | 1.0.0.2 | |
| Tencent | 20190809 | 1.0.0.1 | |
| Kingsoft | 20190809 | 2013.8.14.323 | |
| CrowdStrike | win/malicious_confidence_100% (D) | 20190212 | 1.0 |
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
| suspicious_features | POST method with no referer header | suspicious_request | POST http://dlg-configs.buzzrin.de/config-from-production | ||||||
| suspicious_features | POST method with no referer header | suspicious_request | POST http://dlg-messages.buzzrin.de/1/dg/3 | ||||||
| request | HEAD http://dlg-configs.buzzrin.de/ |
| request | POST http://dlg-configs.buzzrin.de/config-from-production |
| request | GET http://az687722.vo.msecnd.net/public-source/downloadguide/computerbild/1.0/default/campaigns/product+website/ui/base.zip |
| request | GET http://az687722.vo.msecnd.net/public-source/downloadguide/computerbild/1.0/default/campaigns/product+website/ui/computerbild-flow-5-text-en-us.zip |
| request | POST http://dlg-messages.buzzrin.de/1/dg/3 |
| request | GET http://az687722.vo.msecnd.net/public-source/downloadguide/computerbild/1.0/default/campaigns/product+website/ui/last.zip |
| request | POST http://dlg-configs.buzzrin.de/config-from-production |
| request | POST http://dlg-messages.buzzrin.de/1/dg/3 |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\DLG\ui\common\base\js\jquery-1.10.2.min.js |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1620814374.932375 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |
| entropy | 7.29363915702178 | section | {'size_of_data': '0x00021c00', 'virtual_address': '0x0005a000', 'entropy': 7.29363915702178, 'name': '.rdata', 'virtual_size': '0x00021a50'} | description | A section with a high entropy has been found | |||||||||
| entropy | 0.2504638218923933 | description | Overall entropy of this PE file is high | |||||||||||
| host | 172.217.24.14 | |||