| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| McAfee | Artemis!DF8463491F17 | 20201211 | 6.0.6.653 |
| Alibaba | VirTool:Win32/AutInject.0dcf1e5e | 20190527 | 0.3.0.5 |
| Baidu | 20190318 | 1.0.0.2 | |
| Avast | Win32:PWSX-gen [Trj] | 20201210 | 21.1.5827.0 |
| Tencent | Malware.Win32.Gencirc.10b0d056 | 20201211 | 1.0.0.1 |
| Kingsoft | 20201211 | 2017.9.26.565 | |
| CrowdStrike | win/malicious_confidence_100% (W) | 20190702 | 1.0 |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1619977227.996626 WriteConsoleW |
buffer:
成功: 成功创建计划任务 "RtkAudioService64"。
console_handle: 0x00000007 |
success | 1 | 0 |
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
| suspicious_features | POST method with no referer header | suspicious_request | POST http://0x21.in:8000/_az/ | ||||||
| request | POST http://0x21.in:8000/_az/ |
| request | POST http://0x21.in:8000/_az/ |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\vnc.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\windef.exe |
| file | C:\Users\Administrator.Oskar-PC\btpanui\SystemPropertiesPerformance.exe |
| cmdline | schtasks /create /tn RtkAudioService64 /tr "C:\Users\Administrator.Oskar-PC\btpanui\SystemPropertiesPerformance.exe" /sc minute /mo 1 /F |
| cmdline | "C:\Windows\SysWOW64\schtasks.exe" /create /tn RtkAudioService64 /tr "C:\Users\Administrator.Oskar-PC\btpanui\SystemPropertiesPerformance.exe" /sc minute /mo 1 /F |
| cmdline | C:\Windows\system32\svchost.exe -k |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1619977224.981249 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |
| cmdline | schtasks /create /tn RtkAudioService64 /tr "C:\Users\Administrator.Oskar-PC\btpanui\SystemPropertiesPerformance.exe" /sc minute /mo 1 /F |
| cmdline | "C:\Windows\SysWOW64\schtasks.exe" /create /tn RtkAudioService64 /tr "C:\Users\Administrator.Oskar-PC\btpanui\SystemPropertiesPerformance.exe" /sc minute /mo 1 /F |
| buffer | Buffer with sha1: 8e9e84bd726fd9042fb99139b8c7dd00fccdc0a2 |
| buffer | Buffer with sha1: ba875be81fcc6e3caab657bc4e56c5f904281c75 |
| host | 172.217.24.14 | |||
| host | 58.63.233.69 | |||
| cmdline | schtasks /create /tn RtkAudioService64 /tr "C:\Users\Administrator.Oskar-PC\btpanui\SystemPropertiesPerformance.exe" /sc minute /mo 1 /F |
| cmdline | "C:\Windows\SysWOW64\schtasks.exe" /create /tn RtkAudioService64 /tr "C:\Users\Administrator.Oskar-PC\btpanui\SystemPropertiesPerformance.exe" /sc minute /mo 1 /F |