Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Oct. 29, 2021, 10 a.m. | Oct. 29, 2021, 10:02 a.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,cxzasada
2564-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,cxzasada
2816-
cmd.exe cmd /c ping 192.0.2.82 -n 6 -w 1000 > NUL & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", cxzasada wdtbkqfe koorgsfd & exit
2228-
PING.EXE ping 192.0.2.82 -n 6 -w 1000
2312 -
rundll32.exe "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", cxzasada wdtbkqfe koorgsfd
1128
-
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,ddsdfwe
2712-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,ddsdfwe
2532-
cmd.exe cmd /c ping 127.0.0.1 -n 6 > NUL & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", ddsdfwe wdtbkqfe koorgsfd & exit
2184-
PING.EXE ping 127.0.0.1 -n 6
2548 -
rundll32.exe "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", ddsdfwe wdtbkqfe koorgsfd
2672
-
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,htrhrr
2356-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,htrhrr
2516
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,nvqqws
3000-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,nvqqws
2728-
cmd.exe cmd /c ping 127.0.0.1 -n 6 -4 > NUL & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", nvqqws wdtbkqfe koorgsfd & exit
2668-
PING.EXE ping 127.0.0.1 -n 6 -4
1892 -
rundll32.exe "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", nvqqws wdtbkqfe koorgsfd
2804
-
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,ClearNode
2464-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,ClearNode
2160-
cmd.exe cmd /c timeout /t 8 /nobreak & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", ClearNode wdtbkqfe koorgsfd & exit
1700-
timeout.exe timeout /t 8 /nobreak
1728 -
rundll32.exe "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", ClearNode wdtbkqfe koorgsfd
3044
-
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,pogfhgf
2824-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,pogfhgf
2180
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,
2684
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
description | rundll32.exe tried to sleep 401 seconds, actually delayed analysis time by 401 seconds |
section | {u'size_of_data': u'0x0001ba00', u'virtual_address': u'0x00006000', u'entropy': 7.728152878306273, u'name': u'.rdata', u'virtual_size': u'0x0001b91c'} | entropy | 7.72815287831 | description | A section with a high entropy has been found | |||||||||
entropy | 0.833962264151 | description | Overall entropy of this PE file is high |
cmdline | cmd /c ping 127.0.0.1 -n 6 -4 > NUL & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", nvqqws wdtbkqfe koorgsfd & exit |
cmdline | cmd /c ping 192.0.2.82 -n 6 -w 1000 > NUL & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", cxzasada wdtbkqfe koorgsfd & exit |
cmdline | cmd /c ping 127.0.0.1 -n 6 > NUL & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", ddsdfwe wdtbkqfe koorgsfd & exit |
cmdline | ping 192.0.2.82 -n 6 -w 1000 |
cmdline | ping 127.0.0.1 -n 6 -4 |
cmdline | ping 127.0.0.1 -n 6 |
Cynet | Malicious (score: 100) |
McAfee | Artemis!CD3E23CDDEB9 |
Sangfor | Suspicious.Win32.Save.a |
CrowdStrike | win/malicious_confidence_60% (D) |
Avast | Win64:MalwareX-gen [Trj] |
McAfee-GW-Edition | BehavesLike.Win64.BadFile.cc |
FireEye | Generic.mg.cd3e23cddeb92b73 |
Sophos | Generic ML PUA (PUA) |
MaxSecure | Trojan.Malware.300983.susgen |
Microsoft | Trojan:Win64/BazarLoader.MZK!MTB |
Fortinet | W64/Kryptik.CQV!tr |
AVG | Win64:MalwareX-gen [Trj] |