Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Nov. 5, 2021, 10:41 a.m. | Nov. 5, 2021, 10:43 a.m. |
-
-
-
schtasks.exe /C /create /F /sc minute /mo 1 /tn "Telemetry Logging" /tr "C:\Users\test22\AppData\Roaming\Microsoft\TelemetryServices\fodhelper.exe"
2964
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | |
section | .debug |
section | .128xeq2 |
section | .boot |
section | {u'size_of_data': u'0x00011800', u'virtual_address': u'0x00001000', u'entropy': 7.995620202526813, u'name': u' ', u'virtual_size': u'0x00021f52'} | entropy | 7.99562020253 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00000800', u'virtual_address': u'0x00023000', u'entropy': 6.978689073245101, u'name': u' ', u'virtual_size': u'0x00000c36'} | entropy | 6.97868907325 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00006000', u'virtual_address': u'0x00024000', u'entropy': 7.989214626350801, u'name': u' ', u'virtual_size': u'0x0000ea26'} | entropy | 7.98921462635 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00000400', u'virtual_address': u'0x00033000', u'entropy': 7.314352897490997, u'name': u' ', u'virtual_size': u'0x00001cf8'} | entropy | 7.31435289749 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00002000', u'virtual_address': u'0x00035000', u'entropy': 7.940507612421558, u'name': u' ', u'virtual_size': u'0x00002e1d'} | entropy | 7.94050761242 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001600', u'virtual_address': u'0x00038000', u'entropy': 7.817443448705043, u'name': u' ', u'virtual_size': u'0x00001c58'} | entropy | 7.81744344871 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00165600', u'virtual_address': u'0x00361000', u'entropy': 7.9613768048927405, u'name': u'.boot', u'virtual_size': u'0x00165600'} | entropy | 7.96137680489 | description | A section with a high entropy has been found | |||||||||
entropy | 0.987812700449 | description | Overall entropy of this PE file is high |
description | task schedule | rule | schtasks_Zero | ||||||
description | [m] Generic Malware | rule | Generic_Malware_Zero_m | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
cmdline | /C /create /F /sc minute /mo 1 /tn "Telemetry Logging" /tr "C:\Users\test22\AppData\Roaming\Microsoft\TelemetryServices\fodhelper.exe" |
buffer | Buffer with sha1: 07698af75b7b7e143f431c1f48fce43864f2d654 |
registry | HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion |
registry | HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersion |