Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | Sept. 6, 2021, 8:14 a.m. | Sept. 6, 2021, 8:16 a.m. |
-
-
cmd.exe "C:\Windows\System32\cmd.exe" /c schtasks /create /tn \03BD451ED4621855818353 /tr "C:\Users\test22\AppData\Roaming\Microsoft\Windows\03BD451ED4621855818353\03BD451ED4621855818353.exe" /st 00:00 /du 9999:59 /sc once /ri 1 /f
2236-
schtasks.exe schtasks /create /tn \03BD451ED4621855818353 /tr "C:\Users\test22\AppData\Roaming\Microsoft\Windows\03BD451ED4621855818353\03BD451ED4621855818353.exe" /st 00:00 /du 9999:59 /sc once /ri 1 /f
2524
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
cmdline | schtasks /create /tn \03BD451ED4621855818353 /tr "C:\Users\test22\AppData\Roaming\Microsoft\Windows\03BD451ED4621855818353\03BD451ED4621855818353.exe" /st 00:00 /du 9999:59 /sc once /ri 1 /f |
cmdline | "C:\Windows\System32\cmd.exe" /c schtasks /create /tn \03BD451ED4621855818353 /tr "C:\Users\test22\AppData\Roaming\Microsoft\Windows\03BD451ED4621855818353\03BD451ED4621855818353.exe" /st 00:00 /du 9999:59 /sc once /ri 1 /f |
cmdline | cmd.exe /c schtasks /create /tn \03BD451ED4621855818353 /tr "C:\Users\test22\AppData\Roaming\Microsoft\Windows\03BD451ED4621855818353\03BD451ED4621855818353.exe" /st 00:00 /du 9999:59 /sc once /ri 1 /f |
cmdline | schtasks /create /tn \03BD451ED4621855818353 /tr "C:\Users\test22\AppData\Roaming\Microsoft\Windows\03BD451ED4621855818353\03BD451ED4621855818353.exe" /st 00:00 /du 9999:59 /sc once /ri 1 /f |
cmdline | "C:\Windows\System32\cmd.exe" /c schtasks /create /tn \03BD451ED4621855818353 /tr "C:\Users\test22\AppData\Roaming\Microsoft\Windows\03BD451ED4621855818353\03BD451ED4621855818353.exe" /st 00:00 /du 9999:59 /sc once /ri 1 /f |
cmdline | cmd.exe /c schtasks /create /tn \03BD451ED4621855818353 /tr "C:\Users\test22\AppData\Roaming\Microsoft\Windows\03BD451ED4621855818353\03BD451ED4621855818353.exe" /st 00:00 /du 9999:59 /sc once /ri 1 /f |
cmdline | schtasks /create /tn \03BD451ED4621855818353 /tr "C:\Users\test22\AppData\Roaming\Microsoft\Windows\03BD451ED4621855818353\03BD451ED4621855818353.exe" /st 00:00 /du 9999:59 /sc once /ri 1 /f |
cmdline | "C:\Windows\System32\cmd.exe" /c schtasks /create /tn \03BD451ED4621855818353 /tr "C:\Users\test22\AppData\Roaming\Microsoft\Windows\03BD451ED4621855818353\03BD451ED4621855818353.exe" /st 00:00 /du 9999:59 /sc once /ri 1 /f |
cmdline | cmd.exe /c schtasks /create /tn \03BD451ED4621855818353 /tr "C:\Users\test22\AppData\Roaming\Microsoft\Windows\03BD451ED4621855818353\03BD451ED4621855818353.exe" /st 00:00 /du 9999:59 /sc once /ri 1 /f |
Lionic | Trojan.Win32.Tasker.4!c |
Elastic | malicious (high confidence) |
FireEye | Generic.mg.0f41234ce843d72a |
McAfee | RDN/Generic.grp |
Cylance | Unsafe |
Cybereason | malicious.ce843d |
BitDefenderTheta | Gen:NN.ZexaF.34126.eu0@ayYnWumi |
ESET-NOD32 | a variant of Win32/GenKryptik.EOYQ |
APEX | Malicious |
Kaspersky | UDS:Trojan.Win32.Tasker.gen |
Avast | FileRepMalware |
eGambit | Unsafe.AI_Score_99% |
Microsoft | Trojan:Script/Phonzy.B!ml |
Rising | Trojan.Generic@ML.90 (RDML:zU+8TvJojuf4mIrkuCXfPA) |
AVG | FileRepMalware |
CrowdStrike | win/malicious_confidence_100% (W) |
cmdline | schtasks /create /tn \03BD451ED4621855818353 /tr "C:\Users\test22\AppData\Roaming\Microsoft\Windows\03BD451ED4621855818353\03BD451ED4621855818353.exe" /st 00:00 /du 9999:59 /sc once /ri 1 /f |
cmdline | "C:\Windows\System32\cmd.exe" /c schtasks /create /tn \03BD451ED4621855818353 /tr "C:\Users\test22\AppData\Roaming\Microsoft\Windows\03BD451ED4621855818353\03BD451ED4621855818353.exe" /st 00:00 /du 9999:59 /sc once /ri 1 /f |
cmdline | cmd.exe /c schtasks /create /tn \03BD451ED4621855818353 /tr "C:\Users\test22\AppData\Roaming\Microsoft\Windows\03BD451ED4621855818353\03BD451ED4621855818353.exe" /st 00:00 /du 9999:59 /sc once /ri 1 /f |