查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
---|---|---|---|
McAfee | 20200710 | 6.0.6.653 | |
Alibaba | 20190527 | 0.3.0.5 | |
Avast | 20200710 | 18.4.3895.0 | |
Baidu | 20190318 | 1.0.0.2 | |
Kingsoft | 20200710 | 2013.8.14.323 | |
Tencent | 20200710 | 1.0.0.1 | |
CrowdStrike | 20190702 | 1.0 |
pdb_path | E:\pcgame\GameDownloader\Release\GameDownloader.pdb |
resource name | INI |
resource name | ZIP |
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://180.163.54.67:80/ | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://47.97.7.140:80/ | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://180.163.202.66:80/ | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://140.206.225.136:80/ |
request | GET http://r.yx-s.net/b/duan/s/ginstall/?user_from=414100000225&user_channel=622110021&user_subsite=221121&mid=2d5bac7481e6a281dd071007abc25283&status=7&gkey=gjol&ver=1.0.0.1001&first_time= |
request | GET http://gametool.down.yx-g.com/gametool/lyyx/gjol/622110021/DL.ini |
request | GET http://gametool.down.360-g.net/gametool/lyyx/gjol/622110021/DL.ini |
request | GET http://gametool.down.yx-g.com/gametool/lyyx/gjol/default/DL.ini |
request | POST http://180.163.54.67:80/ |
request | POST http://47.97.7.140:80/ |
request | POST http://180.163.202.66:80/ |
request | POST http://140.206.225.136:80/ |
request | POST http://180.163.54.67:80/ |
request | POST http://47.97.7.140:80/ |
request | POST http://180.163.202.66:80/ |
request | POST http://140.206.225.136:80/ |
ip | 123.161.62.172 |
ip | 180.163.202.93 |
ip | 182.140.250.18 |
ip | 39.98.93.220 |
ip | 47.92.99.221 |
regkey | .*360Safe |
name | RT_VERSION | language | LANG_CHINESE | offset | 0x0044d168 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x000002e8 | ||||||||||||||||||
name | RT_VERSION | language | LANG_CHINESE | offset | 0x0044d168 | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x000002e8 |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\7za.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\atl71.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\DlMgr.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\dl_peer_id.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\xldl.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\msvcr71.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\MiniThunderPlatform.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\minizip.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\XLBugHandler.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\XLBugReport.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\msvcp71.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\zlib1.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\download_engine.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\7za.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\msvcr71.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\dl_peer_id.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\atl71.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\XLBugReport.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\XLBugHandler.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\MiniThunderPlatform.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\xldl.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\DlMgr.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\download_engine.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\zlib1.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\msvcp71.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\download\minizip.dll |
Paloalto | generic.ml |
Ikarus | Trojan.Agent |
Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1620985513.238755 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |
entropy | 7.99551579620857 | section | {'size_of_data': '0x00283800', 'virtual_address': '0x001ca000', 'entropy': 7.99551579620857, 'name': '.rsrc', 'virtual_size': '0x002836dc'} | description | A section with a high entropy has been found | |||||||||
entropy | 0.578167115902965 | description | Overall entropy of this PE file is high |
host | 123.161.62.172 | |||
host | 172.217.24.14 | |||
host | 39.98.93.220 |