Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | May 11, 2021, 6:05 p.m. | May 11, 2021, 6:07 p.m. |
-
12_CNB_Programas_de_Becas-70212-em.txt "C:\Users\test22\AppData\Local\Temp\12_CNB_Programas_de_Becas-70212-em.txt"
4208-
chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --single-argument C:\Users\test22\AppData\Roaming\12_CNB_Programas_de_Becas.pdf
3172-
chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef2cb6e00,0x7fef2cb6e10,0x7fef2cb6e20
6116
-
-
-
-
reg.exe REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /v Windows /t REG_SZ /d "C:\Users\test22\AppData\Roaming\System.exe" ///
8168 -
reg.exe REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /v Windows /t REG_SZ /d "C:\Users\test22\AppData\Roaming\System.exe"
4884
-
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
172.217.25.14 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
pdb_path | D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb |
file | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\chrome.exe\PATH |
section | .gfids |
resource name | PNG |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics-spare.pma |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Last Version |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics-active.pma |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\reports\aedd0046-ffc5-4770-b7fe-38b467588e14.dmp |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics-spare.pma |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\First Run |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\reports |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\index |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-609AC2C1-C64.pma |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\metadata |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_0 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_2 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_3 |
file | C:\Users\test22\AppData\Roaming\12_CNB_Programas_de_Becas.pdf |
file | C:\Users\test22\AppData\Roaming\cfx.bat |
file | C:\Users\test22\AppData\Roaming\win.vbe |
file | C:\Users\test22\AppData\Roaming\System.exe |
file | C:\Users\test22\AppData\Roaming\12_CNB_Programas_de_Becas.pdf |
file | C:\Users\test22\AppData\Roaming\win.vbe |
file | C:\Users\test22\AppData\Roaming\cfx.bat |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
cmdline | REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /v Windows /t REG_SZ /d "C:\Users\test22\AppData\Roaming\System.exe" /// |
cmdline | REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /v Windows /t REG_SZ /d "C:\Users\test22\AppData\Roaming\System.exe" |
host | 172.217.25.14 |
reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Windows | reg_value | C:\Users\test22\AppData\Roaming\System.exe |
parent_process | chrome.exe | martian_process | "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1020,2244711460136607760,4775864505368540397,131072 --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --use-gl=swiftshader-webgl --mojo-platform-channel-handle=552 /prefetch:2 | ||||||
parent_process | chrome.exe | martian_process | "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef2cb6e00,0x7fef2cb6e10,0x7fef2cb6e20 | ||||||
parent_process | wscript.exe | martian_process | "C:\Users\test22\AppData\Roaming\cfx.bat" | ||||||
parent_process | wscript.exe | martian_process | C:\Users\test22\AppData\Roaming\cfx.bat |
file | C:\Windows\SysWOW64\wscript.exe |
Bkav | W32.AIDetect.malware1 |
MicroWorld-eScan | Gen:Variant.Graftor.713003 |
McAfee | Artemis!DAF77956A7CB |
Sangfor | Trojan.Win32.Save.a |
CrowdStrike | win/malicious_confidence_80% (W) |
Arcabit | Trojan.Graftor.DAE12B |
Symantec | Ransom.Wannacry |
APEX | Malicious |
Kaspersky | UDS:DangerousObject.Multi.Generic |
BitDefender | Gen:Variant.Graftor.713003 |
Paloalto | generic.ml |
Ad-Aware | Gen:Variant.Graftor.713003 |
DrWeb | Trojan.BtcMine.308 |
McAfee-GW-Edition | BehavesLike.Win32.Generic.rc |
FireEye | Generic.mg.daf77956a7cbbdb2 |
Emsisoft | Gen:Variant.Graftor.713003 (B) |
Ikarus | Win32.Outbreak |
Avira | TR/CoinMiner.rqgqb |
MAX | malware (ai score=80) |
Antiy-AVL | Trojan/Generic.ASMalwS.3113434 |
Gridinsoft | Trojan.Win32.Injector.ad!i |
Microsoft | Trojan:Win32/Wacatac.B!ml |
ViRobot | Trojan.Win32.Z.Graftor.8742467 |
ZoneAlarm | UDS:DangerousObject.Multi.Generic |
GData | Gen:Variant.Graftor.713003 |
Cynet | Malicious (score: 100) |
AhnLab-V3 | Trojan/Win32.Kryptik.R353672 |
ALYac | Gen:Variant.Graftor.713003 |
TrendMicro-HouseCall | TROJ_GEN.R002H0CEA21 |
Fortinet | W32/PossibleThreat |
Cybereason | malicious.6a7cbb |
Panda | Trj/Genetic.gen |