CAT-QuickHeal: Trojan.Wacatac
McAfee: Artemis!77BDE3A6392E
Cylance: Unsafe
K7AntiVirus: Adware ( 005070c51 )
K7GW: Adware ( 005070c51 )
Cybereason: malicious.e956bd
Invincea: heuristic
BitDefenderTheta: Gen:NN.ZexaF.33558.YpKfaCxIy2ob
F-Prot: W32/Trojan.CLL.gen!Eldorado
Symantec: Trojan Horse
ESET-NOD32: a variant of Win32/Packed.BlackMoon.A potentially unwanted
Paloalto: generic.ml
Avast: Win32:Malware-gen
Sophos: Generic PUA HE (PUA)
Comodo: Malware@#1iyufsdw0rmbv
McAfee-GW-Edition: BehavesLike.Win32.Flyagent.wc
Ikarus: Trojan-PSW.QQpass
Cyren: W32/Trojan.CLL.gen!Eldorado
Fortinet: W32/Agent.65CA!tr
Antiy-AVL: GrayWare/Win32.FlyStudio.a
Endgame: malicious (moderate confidence)
Microsoft: Trojan:Win32/Tiggre!rfn
VBA32: BScope.Trojan.Tiggre
Rising: Trojan.Kryptik!1.B3E8 (TFE:5:fpZJMZROweE)
SentinelOne: DFI - Malicious PE
AVG: Win32:Malware-gen
CrowdStrike: win/malicious_confidence_70% (W)
行为分析
互斥量(Mutexes)
- Local\MSCTF.Asm.MutexDefault1
- RasPbFile
执行的命令
- C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
- C:\Windows\system32\sppsvc.exe
创建的服务
无信息
进程
Finder.exe PID: 2680, 上一级进程 PID: 2320
services.exe PID: 424, 上一级进程 PID: 328
mscorsvw.exe PID: 2508, 上一级进程 PID: 424
mscorsvw.exe PID: 1412, 上一级进程 PID: 424
读取的文件
- C:\Windows\Globalization\Sorting\sortdefault.nls
- C:\Users\test\AppData\Local\GDIPFONTCACHEV1.DAT
- C:\Windows\Fonts\simsun.ttc
- C:\Windows\Fonts\micross.ttf
- C:\Windows\Fonts\segoeui.ttf
- C:\Windows\Fonts\msyh.ttf
- C:\Windows\Fonts\malgun.ttf
- C:\Windows\Fonts\msjh.ttf
- C:\Windows\Fonts\tahoma.ttf
- C:\Users\test\AppData\Local\Temp\FinderVC.dll
- C:\Users\test\AppData\Local\Temp\Finder_OpenCV.dll
- C:\Users\test\AppData\Local\Temp\sfui.ttf
- C:\Users\test\AppData\Local\Temp\trayico.exe
- C:\Windows\System32\wlanapi.dll
- C:\Windows\System32\wlanutil.dll
- C:\Windows\System32\rasapi32.dll
- C:\Windows\System32\rasman.dll
- C:\Windows\System32\d2d1.dll
- C:\Windows\System32\DWrite.dll
- C:\Windows\Fonts\staticcache.dat
- C:\Users\test\AppData\Local\Temp\setting.ini
- C:\Users\test\AppData\Local\Temp\Finder.exe
- C:\Windows\Fonts\segoeuib.ttf
- C:\Users\test\AppData\Local\Temp\language\chinese.ini
- C:\Users\test\AppData\Local\Temp\ico\logo1.png
- C:\Users\test\AppData\Local\Temp\ico\logo2.png
- C:\Windows\Fonts\raavi.ttf
- C:\Windows\Fonts\arial.ttf
- C:\Windows\Fonts\meiryo.ttc
- C:\Windows\System32\tzres.dll
- C:\Users\test\AppData\Local\Temp\keyboard.ini
- C:\Windows\Fonts\ARIALUNI.TTF
- C:\Users\test\AppData\Local\Temp\ico\cortana.png
- C:\Windows\SysWOW64\stdole2.tlb
- C:\Program Files (x86)\Common Files\System\ado\msado15.dll
- C:\Users\test\AppData\Local\Temp\ico\win.png
- C:\Windows\sysnative\LogFiles\Scm\da41de71-8431-42fb-9db0-eb64a961dead
修改的文件
- C:\Users\test\AppData\Local\GDIPFONTCACHEV1.DAT
- C:\Users\test\AppData\Local\Temp\FinderVC.dll
- C:\Users\test\AppData\Local\Temp\Finder_OpenCV.dll
- C:\Users\test\AppData\Local\Temp\sfui.ttf
- C:\Users\test\AppData\Local\Temp\trayico.exe
- C:\Users\test\AppData\Local\Temp\language\chinese.ini
- C:\Users\test\AppData\Local\Temp\setting.ini
- C:\Users\test\AppData\Local\Temp\ico\logo1.png
- C:\Users\test\AppData\Local\Temp\ico\logo2.png
- C:\Users\test\AppData\Local\Temp\keyboard.ini
- C:\Users\test\AppData\Local\Temp\ico\cortana.png
- C:\Users\test\AppData\Local\Temp\ico\win.png
- C:\Windows\sysnative\LogFiles\Scm\9435f817-fed2-454e-88cd-7f78fda62c48
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngenservicelock.dat
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngenrootstorelock.dat
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngenservicelock.dat
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngenrootstorelock.dat
删除的文件
无信息
修改的注册表键
- HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\LanguageList
删除的注册表键
无信息