| 查杀引擎 | 查杀结果 | 查杀时间 | 查杀版本 |
|---|---|---|---|
| McAfee | Artemis!C96D3B8CC1F4 | 20200902 | 6.0.6.653 |
| Alibaba | 20190527 | 0.3.0.5 | |
| CrowdStrike | 20190702 | 1.0 | |
| Baidu | 20190318 | 1.0.0.2 | |
| Avast | 20200901 | 18.4.3895.0 | |
| Kingsoft | 20200902 | 2013.8.14.323 | |
| Tencent | 20200902 | 1.0.0.1 |
| section | .ndata |
| suspicious_features | HTTP version 1.0 used | suspicious_request | GET http://logs.bytefence.com/event?Eventname=NsisInstaller&status=Start&Product=ByteFence&i_data=&ruserid=&tag=2.0.50727&OSVersion=6.1.0.0&version=5.4.1.13&tag2={00000000-0000-0000-0000-000000000000} | ||||||
| suspicious_features | HTTP version 1.0 used | suspicious_request | GET http://logs.bytefence.com/event?Eventname=NsisInstaller&status=Finish&Product=ByteFence&i_data=&ruserid=&tag=2.0.50727&OSVersion=6.1.0.0&version=5.4.1.13&tag2={00000000-0000-0000-0000-000000000000} | ||||||
| request | GET http://logs.bytefence.com/event?Eventname=NsisInstaller&status=Start&Product=ByteFence&i_data=&ruserid=&tag=2.0.50727&OSVersion=6.1.0.0&version=5.4.1.13&tag2={00000000-0000-0000-0000-000000000000} |
| request | GET http://logs.bytefence.com/event?Eventname=NsisInstaller&status=Finish&Product=ByteFence&i_data=&ruserid=&tag=2.0.50727&OSVersion=6.1.0.0&version=5.4.1.13&tag2={00000000-0000-0000-0000-000000000000} |
| file | C:\Program Files\ByteFence\rsEngineHelper.exe |
| file | C:\Program Files\ByteFence\x64\rsEngineFW_x64.dll |
| file | C:\Program Files\ByteFence\websocket-sharp.dll |
| file | C:\Program Files\ByteFence\x86\ext_x86.dll |
| file | C:\Program Files\ByteFence\x86\msdia140.dll |
| file | C:\Program Files\ByteFence\x86\lz4_x86.dll |
| file | C:\Program Files\ByteFence\amd64\KernelTraceControl.dll |
| file | C:\Program Files\ByteFence\x64\rsEnginePM_x64.dll |
| file | C:\Program Files\ByteFence\ByteFence.exe |
| file | C:\Program Files\ByteFence\ByteFenceGUI.dll |
| file | C:\Program Files\ByteFence\x64\rsLggrServer_x64.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nso83F1.tmp\nsDialogs.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nso83F1.tmp\nsisdl.dll |
| file | C:\Program Files\ByteFence\amd64\msdia140.dll |
| file | C:\Program Files\ByteFence\x64\ext_x64.dll |
| file | C:\Program Files\ByteFence\x86\rsLggrServer_x86.dll |
| file | C:\Program Files\ByteFence\ByteFenceService.exe |
| file | C:\Program Files\ByteFence\Uninstall.exe |
| file | C:\Program Files\ByteFence\x86\rsEngineFW_x86.dll |
| file | C:\Program Files\ByteFence\x86\7z86.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nso83F1.tmp\nsExec.dll |
| file | C:\Program Files\ByteFence\Microsoft.Diagnostics.Tracing.TraceEvent.dll |
| file | C:\Program Files\ByteFence\rsEngine.dll |
| file | C:\Program Files\ByteFence\x64\7z64.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\InstallTools.exe |
| file | C:\Program Files\ByteFence\x64\System.Data.SQLite.dll |
| file | C:\Program Files\ByteFence\x64\lz4_x64.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\bytefence-installer-5.4.1.13.exe |
| file | C:\Program Files\ByteFence\Microsoft.Win32.TaskScheduler.dll |
| file | C:\Program Files\ByteFence\rsUtils.dll |
| file | C:\Program Files\ByteFence\ByteFenceScan.exe |
| file | C:\Program Files\ByteFence\x86\KernelTraceControl.dll |
| file | C:\Program Files\ByteFence\rsMessages.dll |
| file | C:\Program Files\ByteFence\x86\rsEnginePM_x86.dll |
| file | C:\Program Files\ByteFence\x86\System.Data.SQLite.dll |
| file | C:\Program Files\ByteFence\protobuf-net.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nso83F1.tmp\System.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nso83F1.tmp\nsisdl.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\InstallTools.exe |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nso83F1.tmp\nsDialogs.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nso83F1.tmp\nsExec.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nso83F1.tmp\System.dll |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\bytefence-installer-5.4.1.13.exe |
| wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "ByteFenceService.exe") |
| wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "rsLggr.exe") |
| wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "rsEngineHelper.exe") |
| wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "ByteFence.exe") |
| wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "ByteFenceScan.exe") |
| cmdline | taskkill /f /im ByteFenceScan.exe |
| cmdline | taskkill /f /im rsLggr.exe |
| cmdline | taskkill /f /im ByteFenceService.exe |
| cmdline | taskkill /f /im rsEngineHelper.exe |
| cmdline | taskkill /f /im ByteFence.exe |
| host | 172.217.24.14 | |||
| McAfee | Artemis!C96D3B8CC1F4 |
| K7AntiVirus | Trojan ( 00555f5d1 ) |
| K7GW | Riskware ( dec003101 ) |
| Cyren | W32/Trojan.RFDL-4325 |
| ClamAV | Win.Dropper.Wanna-6651539-0 |
| DrWeb | Program.Unwanted.4920 |
| Sophos | ByteFence Anti-Malware (PUA) |
| Microsoft | Misleading:Win32/Fybents |
| Malwarebytes | PUP.Optional.ByteFence |
| ESET-NOD32 | MSIL/ByteFence.C potentially unwanted |
No hosts contacted.
| Source | Source Port | Destination | Destination Port |
|---|---|---|---|
| 192.168.56.101 | 49186 | 18.235.150.249 logs.bytefence.com | 80 |
| 192.168.56.101 | 49216 | 18.235.150.249 logs.bytefence.com | 80 |
| Source | Source Port | Destination | Destination Port |
|---|---|---|---|
| 192.168.56.101 | 49713 | 114.114.114.114 | 53 |
| 192.168.56.101 | 50002 | 114.114.114.114 | 53 |
| 192.168.56.101 | 50568 | 114.114.114.114 | 53 |
| 192.168.56.101 | 53237 | 114.114.114.114 | 53 |
| 192.168.56.101 | 53380 | 114.114.114.114 | 53 |
| 192.168.56.101 | 53657 | 114.114.114.114 | 53 |
| 192.168.56.101 | 60384 | 114.114.114.114 | 53 |
| 192.168.56.101 | 137 | 192.168.56.255 | 137 |
| 192.168.56.101 | 138 | 192.168.56.255 | 138 |
| 192.168.56.101 | 123 | 20.189.79.72 time.windows.com | 123 |
| 192.168.56.101 | 49235 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 50534 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 51808 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 51963 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 56804 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 57874 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 62191 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 62318 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 62912 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 63429 | 224.0.0.252 | 5355 |
| URI | Data |
|---|---|
| http://logs.bytefence.com/event?Eventname=NsisInstaller&status=Start&Product=ByteFence&i_data=&ruserid=&tag=2.0.50727&OSVersion=6.1.0.0&version=5.4.1.13&tag2={00000000-0000-0000-0000-000000000000} | GET /event?Eventname=NsisInstaller&status=Start&Product=ByteFence&i_data=&ruserid=&tag=2.0.50727&OSVersion=6.1.0.0&version=5.4.1.13&tag2={00000000-0000-0000-0000-000000000000} HTTP/1.0
Host: logs.bytefence.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*
|
| http://logs.bytefence.com/event?Eventname=NsisInstaller&status=Finish&Product=ByteFence&i_data=&ruserid=&tag=2.0.50727&OSVersion=6.1.0.0&version=5.4.1.13&tag2={00000000-0000-0000-0000-000000000000} | GET /event?Eventname=NsisInstaller&status=Finish&Product=ByteFence&i_data=&ruserid=&tag=2.0.50727&OSVersion=6.1.0.0&version=5.4.1.13&tag2={00000000-0000-0000-0000-000000000000} HTTP/1.0
Host: logs.bytefence.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*
|
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts