Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | Aug. 28, 2021, 5:43 p.m. | Aug. 28, 2021, 5:47 p.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\44.dll,CvvuibpxxnejxroDsqhgxyzcujno
2504-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\44.dll,CvvuibpxxnejxroDsqhgxyzcujno
932
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\44.dll,JfvrwqpngZxcdineOxnuutznn
896-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\44.dll,JfvrwqpngZxcdineOxnuutznn
2176-
cmd.exe cmd /c ping 127.0.0.1 -n 8 & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\44.dll", StartW mscp ahis & exit
2480-
PING.EXE ping 127.0.0.1 -n 8
572 -
rundll32.exe "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\44.dll", StartW mscp ahis
2316
-
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\44.dll,MzqvvwcgmfEvubknxjygklx
2880-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\44.dll,MzqvvwcgmfEvubknxjygklx
2808
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\44.dll,StartW
2332-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\44.dll,StartW
2664
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\44.dll,fgrererere
2400-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\44.dll,fgrererere
2488
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\44.dll,qwwwwww
2948-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\44.dll,qwwwwww
360
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\44.dll,
1768
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
description | rundll32.exe tried to sleep 495 seconds, actually delayed analysis time by 495 seconds |
cmdline | ping 127.0.0.1 -n 8 |
cmdline | cmd /c ping 127.0.0.1 -n 8 & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\44.dll", StartW mscp ahis & exit |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Gen:Variant.Razy.913977 |
Cylance | Unsafe |
ESET-NOD32 | a variant of Win64/BazarLoader.AZ |
APEX | Malicious |
Kaspersky | UDS:DangerousObject.Multi.Generic |
BitDefender | Gen:Variant.Razy.913977 |
Avast | FileRepMalware |
Ad-Aware | Gen:Variant.Razy.913977 |
Emsisoft | Gen:Variant.Razy.913977 (B) |
FireEye | Generic.mg.6a124d95c5c5038d |
MAX | malware (ai score=81) |
Arcabit | Trojan.Razy.DDF239 |
GData | Gen:Variant.Razy.913977 |
Cynet | Malicious (score: 100) |
AhnLab-V3 | Trojan/Win.IcedID.C4608701 |
ALYac | Gen:Variant.Razy.913977 |
Fortinet | W64/BazarLoader.AZ!tr |
AVG | FileRepMalware |