查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
---|---|---|---|
Alibaba | 20190527 | 0.3.0.5 | |
Baidu | 20190318 | 1.0.0.2 | |
Avast | Win32:Evo-gen [Susp] | 20200706 | 18.4.3895.0 |
Kingsoft | 20200706 | 2013.8.14.323 | |
McAfee | Artemis!A293620072AB | 20200706 | 6.0.6.653 |
Tencent | 20200706 | 1.0.0.1 | |
CrowdStrike | 20190702 | 1.0 |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620831685.266626 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
section | .itext |
suspicious_features | POST method with no referer header | suspicious_request | POST https://update.googleapis.com/service/update2?cup2key=10:1542108029&cup2hreq=934d4332084d1164d2f2fc795646d0b6ba8e6c967844de7dd1333db156f9d31a |
request | GET http://stat.offerbox.io/download/1/{ED1184D0-4022-C999-201E-0EA6E9FA777D}/8EDA789A81BA9FA966CD2BB0A79D70ACEEBBB73238C63B414B/1/0 |
request | HEAD http://redirector.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe |
request | HEAD http://r1---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.100&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620802578&mv=m&mvi=1&pl=23&shardbypass=yes |
request | HEAD http://r3---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5ok7e&req_id=3f699ca5424f4ffb&cms_redirect=yes&ipbypass=yes&mip=59.50.85.19&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620802578&mv=m&mvi=3 |
request | GET http://r3---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5ok7e&req_id=3f699ca5424f4ffb&cms_redirect=yes&ipbypass=yes&mip=59.50.85.19&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620802578&mv=m&mvi=3 |
request | POST https://update.googleapis.com/service/update2?cup2key=10:1542108029&cup2hreq=934d4332084d1164d2f2fc795646d0b6ba8e6c967844de7dd1333db156f9d31a |
request | POST https://update.googleapis.com/service/update2?cup2key=10:1542108029&cup2hreq=934d4332084d1164d2f2fc795646d0b6ba8e6c967844de7dd1333db156f9d31a |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\is-JUJBE.tmp\botva2.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\is-JUJBE.tmp\NativeUID.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\is-KQ96J.tmp\a293620072abe07dcaacbfdf7a76a0a5.tmp |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\is-JUJBE.tmp\botva2.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\is-JUJBE.tmp\NativeUID.dll |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620831687.751626 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |
host | 172.217.24.14 | |||
host | 203.208.40.34 |