查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
---|---|---|---|
Baidu | 20181207 | 1.0.0.2 | |
Alibaba | 20180921 | 0.1.0.2 | |
Tencent | 20181227 | 1.0.0.1 | |
Kingsoft | 20181227 | 2013.8.14.323 | |
McAfee | Artemis!DEB9813804A4 | 20181227 | 6.0.6.653 |
Avast | FileRepMetagen [Malware] | 20181227 | 18.4.3895.0 |
CrowdStrike | malicious_confidence_60% (D) | 20181022 | 1.0 |
section | .itext |
suspicious_features | HTTP version 1.0 used | suspicious_request | GET http://post.securestudies.com/packages/VR/PackageV.exe | ||||||
suspicious_features | HTTP version 1.0 used | suspicious_request | GET http://rkverify.securestudies.com/rk/rkverify.exe | ||||||
suspicious_features | POST method with no referer header | suspicious_request | POST https://update.googleapis.com/service/update2?cup2key=10:2633064249&cup2hreq=b5b55110068110e88447195f451b5202b02f70ffc91908e67333506186c4ae61 |
request | GET http://post.securestudies.com/packages/VR/PackageV.exe |
request | GET http://rkverify.securestudies.com/rk/rkverify.exe |
request | POST https://update.googleapis.com/service/update2?cup2key=10:2633064249&cup2hreq=b5b55110068110e88447195f451b5202b02f70ffc91908e67333506186c4ae61 |
request | POST https://update.googleapis.com/service/update2?cup2key=10:2633064249&cup2hreq=b5b55110068110e88447195f451b5202b02f70ffc91908e67333506186c4ae61 |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\is-IVFKN.tmp\itdownload.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\is-IVFKN.tmp\WJZVXzk.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\is-IVFKN.tmp\isxdl.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\is-NBQCD.tmp\deb9813804a451bd9bf8054981762f34.tmp |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\is-IVFKN.tmp\WJZVXzk.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\is-IVFKN.tmp\isxdl.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\is-IVFKN.tmp\itdownload.dll |
host | 172.217.24.14 |
dead_host | 172.217.27.142:443 |
MicroWorld-eScan | Application.RelevantKnowledge.Gen.2 |
CAT-QuickHeal | Trojan.CGeneric |
BitDefender | Application.RelevantKnowledge.Gen.2 |
K7GW | Adware ( 005216d41 ) |
K7AntiVirus | Adware ( 005216d41 ) |
NANO-Antivirus | Trojan.Win32.InstallCore.exwvzh |
Cyren | W32/Trojan.JHRA-4448 |
ClamAV | Win.Trojan.Agent-6638125-0 |
Kaspersky | not-a-virus:HEUR:Downloader.Win32.Funshion.gen |
Sophos | RuiQing Software Technology Beijing Inc (PUA) |
F-Secure | Application.RelevantKnowledge.Gen |
DrWeb | Trojan.InstallCore.3364 |
Invincea | heuristic |
McAfee-GW-Edition | BehavesLike.Win32.Extenbro.tc |
Emsisoft | Application.RelevantKnowledge.Gen.2 (B) |
Webroot | W32.Adware.Gen |
Endgame | malicious (high confidence) |
Arcabit | Application.RelevantKnowledge.Gen.2 |
ZoneAlarm | not-a-virus:HEUR:Downloader.Win32.Funshion.gen |
Microsoft | PUA:Win32/Tsingsoft |
McAfee | Artemis!DEB9813804A4 |
VBA32 | Trojan.InstallCore |
Malwarebytes | PUP.Optional.FusionCore |
Panda | PUP/MYPCTuneUp |
ESET-NOD32 | a variant of Win32/FusionCore.S potentially unwanted |
Rising | PUA.FusionCore!8.124 (CLOUD) |
GData | Application.RelevantKnowledge.Gen.2 |
AVG | FileRepMetagen [Malware] |
Cybereason | malicious.9652b4 |
Avast | FileRepMetagen [Malware] |
CrowdStrike | malicious_confidence_60% (D) |
Qihoo-360 | Win32/Application.80b |
No hosts contacted.
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 49175 | 165.193.78.234 post.securestudies.com | 80 |
192.168.56.101 | 49183 | 165.193.93.104 rkverify.securestudies.com | 80 |
192.168.56.101 | 49197 | 203.208.41.66 update.googleapis.com | 443 |
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 50002 | 114.114.114.114 | 53 |
192.168.56.101 | 50534 | 114.114.114.114 | 53 |
192.168.56.101 | 50568 | 114.114.114.114 | 53 |
192.168.56.101 | 51963 | 114.114.114.114 | 53 |
192.168.56.101 | 55368 | 114.114.114.114 | 53 |
192.168.56.101 | 60123 | 114.114.114.114 | 53 |
192.168.56.101 | 60221 | 114.114.114.114 | 53 |
192.168.56.101 | 61680 | 114.114.114.114 | 53 |
192.168.56.101 | 137 | 192.168.56.255 | 137 |
192.168.56.101 | 138 | 192.168.56.255 | 138 |
192.168.56.101 | 123 | 20.189.79.72 time.windows.com | 123 |
192.168.56.101 | 51378 | 224.0.0.252 | 5355 |
192.168.56.101 | 51808 | 224.0.0.252 | 5355 |
192.168.56.101 | 53237 | 224.0.0.252 | 5355 |
192.168.56.101 | 53380 | 224.0.0.252 | 5355 |
192.168.56.101 | 56804 | 224.0.0.252 | 5355 |
192.168.56.101 | 57236 | 224.0.0.252 | 5355 |
192.168.56.101 | 60384 | 224.0.0.252 | 5355 |
192.168.56.101 | 62191 | 224.0.0.252 | 5355 |
192.168.56.101 | 62318 | 224.0.0.252 | 5355 |
URI | Data |
---|---|
http://post.securestudies.com/packages/VR/PackageV.exe | GET /packages/VR/PackageV.exe HTTP/1.0 Host: post.securestudies.com User-Agent: InnoTools_Downloader |
http://rkverify.securestudies.com/rk/rkverify.exe | GET /rk/rkverify.exe HTTP/1.0 Host: rkverify.securestudies.com User-Agent: InnoTools_Downloader |
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts