| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| McAfee | Artemis!AF0DCC7BE12B | 20201023 | 6.0.6.653 |
| Alibaba | Trojan:Win32/runner.ali1000123 | 20190527 | 0.3.0.5 |
| Baidu | 20190318 | 1.0.0.2 | |
| Avast | Win32:Trojan-gen | 20201023 | 18.4.3895.0 |
| Tencent | Win32.Trojan.Crypt.Lnej | 20201023 | 1.0.0.1 |
| Kingsoft | 20201023 | 2013.8.14.323 | |
| CrowdStrike | win/malicious_confidence_70% (W) | 20190702 | 1.0 |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1619846547.066 IsDebuggerPresent |
failed | 0 | 0 | |
|
1619846547.082 IsDebuggerPresent |
failed | 0 | 0 |
| pdb_path | D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb |
| section | .gfids |
| resource name | PNG |
| domain | alhabib4rec.ddns.net |
| description | RegSvcs.exe tried to sleep 206 seconds, actually delayed analysis time by 206 seconds | |||
| file | C:\99168878\rvwldwxv.ppt |
| file | C:\99168878\obkrdsv.xls |
| file | C:\Users\Administrator.Oskar-PC\temp\hhddb.docx |
| file | C:\99168878\lmngdras.docx |
| file | C:\99168878\sgww.xls |
| file | C:\99168878\antinbtvn.xls |
| file | C:\99168878\igjxxvtch.docx |
| file | C:\99168878\gbuenbv.docx |
| file | C:\99168878\xsvsnhsd.ppt |
| file | C:\99168878\nnxrk.pdf |
| file | C:\99168878\hhddb.docx |
| file | C:\99168878\ghehlgrsm.xls |
| file | C:\99168878\wtbtpcvopt.cpl |
| file | C:\99168878\rvnudbluvd.dll |
| file | C:\99168878\qjigvekmf.dll |
| file | C:\99168878\avhlvofkk.dll |
| file | C:\99168878\xoam.dll |
| file | C:\99168878\lixuxtvq.dll |
| file | C:\99168878\efmtxu.pif |
| file | C:\99168878\xvkqgfwviw.exe |
| file | C:\99168878\efmtxu.pif |
| process | regsvcs.exe |
| buffer | Buffer with sha1: 28960a3b556c267bb1aab14eb18259acf765349e |
| buffer | Buffer with sha1: 2ed1a153b27e22b8f70f97beec38fe99253901de |
| host | 172.217.24.14 | |||
| reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\WindowsUpdate | reg_value | c:\99168878\efmtxu.pif c:\99168878\dbahroos.tin | ||||||