| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 | 
|---|---|---|---|
| McAfee | Artemis!D3B0EE7BB477 | 20201031 | 6.0.6.653 | 
| Baidu | 20190318 | 1.0.0.2 | |
| Avast | Win32:DropperX-gen [Drp] | 20201031 | 20.10.5736.0 | 
| Alibaba | TrojanDropper:Win32/Pwsteal.0a063b8d | 20190527 | 0.3.0.5 | 
| Kingsoft | 20201031 | 2013.8.14.323 | |
| Tencent | Win32.Trojan-dropper.Dapato.Wrpw | 20201031 | 1.0.0.1 | 
| CrowdStrike | win/malicious_confidence_100% (W) | 20190702 | 1.0 | 
| Time & API | Arguments | Status | Return | Repeated | 
|---|---|---|---|---|
| 
    1619924864.721835 GetComputerNameW  | 
    
        
            computer_name:
            
                
                    OSKAR-PC
                
            
            
             | 
success | 1 | 0 | 
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid | 
| pdb_path | D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb | 
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox | 
| section | .gfids | 
| resource name | PNG | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Login Data | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Login Data | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Web Data | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Opera\Opera Next\data\Login Data | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Opera\Opera Next\data\Default\Login Data | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Chromium\User Data\Default\Login Data | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Chromium\User Data\Default\Web Data | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Web Data | 
| file | C:\Users\Administrator.Oskar-PC\AppData\LocalMapleStudio\ChromePlus\Login Data | 
| file | C:\Users\Administrator.Oskar-PC\AppData\LocalMapleStudio\ChromePlus\Default\Login Data | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Login Data | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Nichrome\User Data\Default\Web Data | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Nichrome\User Data\Default\Login Data | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\RockMelt\User Data\Default\Web Data | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\RockMelt\User Data\Default\Login Data | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Yandex\YandexBrowser\User Data\Default\Login Data | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Yandex\YandexBrowser\User Data\Default\Web Data | 
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\SeaMonkey | 
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\Ardcwgg.exe | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\Ardcwgg.exe | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\Ardcwgg.exe | 
| cmdline | C:\Program Files (x86)\internet explorer\ieinstal.exe | 
| buffer | Buffer with sha1: 8b5b8b752d1739d0ea2628ff4d10073e1feb7252 | 
| host | 172.217.24.14 | |||
| file | C:\Program Files (x86)\FTPGetter\Profile\servers.xml | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\FTPGetter\servers.xml | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Estsoft\ALFTP\ESTdb2.dat | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\wcx_ftp.ini | 
| file | C:\Windows\wcx_ftp.ini | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\GHISLER\wcx_ftp.ini | 
| file | C:\Users\Administrator.Oskar-PC\wcx_ftp.ini | 
| file | C:\Windows\32BitFtp.ini | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\FileZilla\sitemanager.xml | 
| file | C:\Program Files (x86)\FileZilla\Filezilla.xml | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\FileZilla\filezilla.xml | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\FileZilla\recentservers.xml | 
| registry | HKEY_CURRENT_USER\Software\Ghisler\Total Commander | 
| registry | HKEY_CURRENT_USER\Software\VanDyke\SecureFX | 
| registry | HKEY_CURRENT_USER\Software\FlashPeak\BlazeFtp\Settings | 
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\.purple\accounts.xml |