查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
---|---|---|---|
Alibaba | Trojan:Win32/Injector.706c2c51 | 20190527 | 0.3.0.5 |
Avast | AutoIt:Injector-JF [Trj] | 20191116 | 18.4.3895.0 |
Tencent | 20191116 | 1.0.0.1 | |
Baidu | 20190318 | 1.0.0.2 | |
Kingsoft | 20191116 | 2013.8.14.323 | |
McAfee | Artemis!A967ABD30F28 | 20191113 | 6.0.6.653 |
CrowdStrike | win/malicious_confidence_100% (W) | 20190702 | 1.0 |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620990359.322125 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
1620990359.337125 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
cmdline | C:\Windows\System32\cmd.exe /k ping 127.0.0.1 -t 0 & del C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\a967abd30f28f86cc275c0f3232944c3.exe & exit |
cmdline | "C:\Windows\system32\cmd.exe" /k ping 127.0.0.1 -t 0 & del C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\a967abd30f28f86cc275c0f3232944c3.exe & exit |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\a967abd30f28f86cc275c0f3232944c3.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\a967abd30f28f86cc275c0f3232944c3.exe |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620990360.384125 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |
cmdline | C:\Windows\System32\cmd.exe /k ping 127.0.0.1 -t 0 & del C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\a967abd30f28f86cc275c0f3232944c3.exe & exit |
cmdline | ping 127.0.0.1 -t 0 |
cmdline | "C:\Windows\system32\cmd.exe" /k ping 127.0.0.1 -t 0 & del C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\a967abd30f28f86cc275c0f3232944c3.exe & exit |
buffer | Buffer with sha1: c75033f755a48ebb3e7ccfc73365fd003c1bd3aa |
buffer | Buffer with sha1: 8a602ab8f95f2ca7f1fa4346e7527e1c27f78981 |
host | 172.217.24.14 |