Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Nov. 1, 2021, 10:27 a.m. | Nov. 1, 2021, 10:36 a.m. |
-
174.exe "C:\Users\test22\AppData\Local\Temp\174.exe"
1616
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
resource name | AVI |
section | {u'size_of_data': u'0x00129200', u'virtual_address': u'0x0000c000', u'entropy': 7.975277632923118, u'name': u'.rsrc', u'virtual_size': u'0x00129036'} | entropy | 7.97527763292 | description | A section with a high entropy has been found | |||||||||
entropy | 0.971790678659 | description | Overall entropy of this PE file is high |
cmdline | at.exe |
reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\wextract_cleanup0 | reg_value | rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\test22\AppData\Local\Temp\IXP000.TMP\" |
Lionic | Trojan.Multi.Generic.4!c |
MicroWorld-eScan | Trojan.GenericKD.47293550 |
FireEye | Trojan.GenericKD.47293550 |
McAfee | Artemis!497287B2C027 |
Cylance | Unsafe |
Sangfor | Backdoor.Win32.Agent.myuerz |
K7AntiVirus | Riskware ( 0040eff71 ) |
Alibaba | Backdoor:Win32/AVEvader.01e5429c |
K7GW | Riskware ( 0040eff71 ) |
Symantec | ML.Attribute.HighConfidence |
TrendMicro-HouseCall | TROJ_FRS.VSNTJV21 |
Paloalto | generic.ml |
Kaspersky | Backdoor.Win32.Agent.myuerz |
BitDefender | Trojan.GenericKD.47293550 |
Avast | Win32:Malware-gen |
Ad-Aware | Trojan.GenericKD.47293550 |
Emsisoft | Trojan.GenericKD.47293550 (B) |
DrWeb | Trojan.MulDrop18.46357 |
TrendMicro | TROJ_FRS.VSNTJV21 |
McAfee-GW-Edition | BehavesLike.Win32.Dropper.tc |
Sophos | Mal/Generic-S |
MAX | malware (ai score=100) |
Microsoft | Trojan:Win32/Sabsik.FL.B!ml |
GData | Trojan.GenericKD.47293550 |
VBA32 | Backdoor.Agent |
ALYac | Trojan.GenericKD.47293550 |
eGambit | Unsafe.AI_Score_92% |
Fortinet | Malicious_Behavior.SB |
AVG | Win32:Malware-gen |