Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 29, 2021, 3:01 p.m. | Oct. 29, 2021, 3:03 p.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,ClearNode
2648-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,ClearNode
1760
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,cxzasada
2076-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,cxzasada
2944-
cmd.exe cmd /c timeout 9 /nobreak & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", cxzasada wdtbkqfe koorgsfd & exit
2004-
timeout.exe timeout 9 /nobreak
1912 -
rundll32.exe "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", cxzasada wdtbkqfe koorgsfd
1344
-
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,ddsdfwe
2276-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,ddsdfwe
620-
cmd.exe cmd /c choice /c y /d y /t 7 & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", ddsdfwe wdtbkqfe koorgsfd & exit
204-
choice.exe choice /c y /d y /t 7
2356 -
rundll32.exe "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", ddsdfwe wdtbkqfe koorgsfd
932
-
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,htrhrr
1812-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,htrhrr
2072-
cmd.exe cmd /c ping 192.0.2.136 -n 5 -w 1000 & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", htrhrr wdtbkqfe koorgsfd & exit
2796-
PING.EXE ping 192.0.2.136 -n 5 -w 1000
2320 -
rundll32.exe "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", htrhrr wdtbkqfe koorgsfd
1748
-
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,nvqqws
2832-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,nvqqws
1304
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,pogfhgf
1116-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,pogfhgf
1460-
cmd.exe cmd /c ping 192.0.2.123 -n 9 -4 -w 1000 & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", pogfhgf wdtbkqfe koorgsfd & exit
2364-
PING.EXE ping 192.0.2.123 -n 9 -4 -w 1000
1632 -
rundll32.exe "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", pogfhgf wdtbkqfe koorgsfd
1364
-
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\temp.dll,
1808
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
description | rundll32.exe tried to sleep 403 seconds, actually delayed analysis time by 403 seconds |
section | {u'size_of_data': u'0x0001ba00', u'virtual_address': u'0x00006000', u'entropy': 7.728152878306273, u'name': u'.rdata', u'virtual_size': u'0x0001b91c'} | entropy | 7.72815287831 | description | A section with a high entropy has been found | |||||||||
entropy | 0.833962264151 | description | Overall entropy of this PE file is high |
cmdline | cmd /c ping 192.0.2.123 -n 9 -4 -w 1000 & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", pogfhgf wdtbkqfe koorgsfd & exit |
cmdline | ping 192.0.2.123 -n 9 -4 -w 1000 |
cmdline | cmd /c ping 192.0.2.136 -n 5 -w 1000 & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\temp.dll", htrhrr wdtbkqfe koorgsfd & exit |
cmdline | ping 192.0.2.136 -n 5 -w 1000 |
Cynet | Malicious (score: 100) |
McAfee | Artemis!CD3E23CDDEB9 |
Sangfor | Suspicious.Win32.Save.a |
CrowdStrike | win/malicious_confidence_70% (W) |
Symantec | Trojan.Gen.2 |
Sophos | Generic ML PUA (PUA) |
TrendMicro | TrojanSpy.Win64.BAZARLOADER.YXBJ3Z |
McAfee-GW-Edition | BehavesLike.Win64.BadFile.cc |
FireEye | Generic.mg.cd3e23cddeb92b73 |
Microsoft | Trojan:Win64/BazarLoader.MZK!MTB |
Fortinet | W64/Kryptik.CQV!tr |
AVG | Win64:MalwareX-gen [Trj] |
Avast | Win64:MalwareX-gen [Trj] |
MaxSecure | Trojan.Malware.300983.susgen |