Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Nov. 7, 2021, 10:16 a.m. | Nov. 7, 2021, 10:23 a.m. |
-
-
cmd.exe C:\Windows\system32\cmd.exe /c icacls "C:\Users\test22\AppData\Roaming\x86_microsoft-windows-csrsrv.resources_31bf3856ad364e35_6.1.7601.17514_ru-ru_c920b87044297248" /inheritance:e /deny "*S-1-1-0:(R,REA,RA,RD)" & icacls "C:\Users\test22\AppData\Roaming\x86_microsoft-windows-csrsrv.resources_31bf3856ad364e35_6.1.7601.17514_ru-ru_c920b87044297248" /inheritance:e /deny "*S-1-5-7:(R,REA,RA,RD)" & icacls "C:\Users\test22\AppData\Roaming\x86_microsoft-windows-csrsrv.resources_31bf3856ad364e35_6.1.7601.17514_ru-ru_c920b87044297248" /inheritance:e /deny "test22:(R,REA,RA,RD)"
2896-
icacls.exe icacls "C:\Users\test22\AppData\Roaming\x86_microsoft-windows-csrsrv.resources_31bf3856ad364e35_6.1.7601.17514_ru-ru_c920b87044297248" /inheritance:e /deny "*S-1-1-0:(R,REA,RA,RD)"
3012 -
icacls.exe icacls "C:\Users\test22\AppData\Roaming\x86_microsoft-windows-csrsrv.resources_31bf3856ad364e35_6.1.7601.17514_ru-ru_c920b87044297248" /inheritance:e /deny "*S-1-5-7:(R,REA,RA,RD)"
2076 -
icacls.exe icacls "C:\Users\test22\AppData\Roaming\x86_microsoft-windows-csrsrv.resources_31bf3856ad364e35_6.1.7601.17514_ru-ru_c920b87044297248" /inheritance:e /deny "test22:(R,REA,RA,RD)"
788
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | |
section | .imports |
section | .themida |
section | .loadcon |
section | .boot |
section | .taggant |
cmdline | C:\Windows\system32\cmd.exe /c icacls "C:\Users\test22\AppData\Roaming\x86_microsoft-windows-csrsrv.resources_31bf3856ad364e35_6.1.7601.17514_ru-ru_c920b87044297248" /inheritance:e /deny "*S-1-1-0:(R,REA,RA,RD)" & icacls "C:\Users\test22\AppData\Roaming\x86_microsoft-windows-csrsrv.resources_31bf3856ad364e35_6.1.7601.17514_ru-ru_c920b87044297248" /inheritance:e /deny "*S-1-5-7:(R,REA,RA,RD)" & icacls "C:\Users\test22\AppData\Roaming\x86_microsoft-windows-csrsrv.resources_31bf3856ad364e35_6.1.7601.17514_ru-ru_c920b87044297248" /inheritance:e /deny "test22:(R,REA,RA,RD)" |
section | {u'size_of_data': u'0x0004ecdb', u'virtual_address': u'0x00001000', u'entropy': 7.983359871411453, u'name': u' ', u'virtual_size': u'0x0008dfdd'} | entropy | 7.98335987141 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x0000e622', u'virtual_address': u'0x0008f000', u'entropy': 7.959989070013559, u'name': u' ', u'virtual_size': u'0x0002fd8e'} | entropy | 7.95998907001 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x000007eb', u'virtual_address': u'0x000bf000', u'entropy': 7.847001716618583, u'name': u' ', u'virtual_size': u'0x00008f74'} | entropy | 7.84700171662 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00025200', u'virtual_address': u'0x000c8000', u'entropy': 7.948768444610188, u'name': u' ', u'virtual_size': u'0x000251d7'} | entropy | 7.94876844461 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00005d7d', u'virtual_address': u'0x000ee000', u'entropy': 7.954872938134222, u'name': u' ', u'virtual_size': u'0x00007134'} | entropy | 7.95487293813 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x001e3000', u'virtual_address': u'0x003e7000', u'entropy': 7.941164160185236, u'name': u'.boot', u'virtual_size': u'0x001e3000'} | entropy | 7.94116416019 | description | A section with a high entropy has been found | |||||||||
entropy | 0.995174077093 | description | Overall entropy of this PE file is high |
registry | HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion |
registry | HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersion |
cmdline | icacls "C:\Users\test22\AppData\Roaming\x86_microsoft-windows-csrsrv.resources_31bf3856ad364e35_6.1.7601.17514_ru-ru_c920b87044297248" /inheritance:e /deny "test22:(R,REA,RA,RD)" |
cmdline | icacls "C:\Users\test22\AppData\Roaming\x86_microsoft-windows-csrsrv.resources_31bf3856ad364e35_6.1.7601.17514_ru-ru_c920b87044297248" /inheritance:e /deny "*S-1-5-7:(R,REA,RA,RD)" |
cmdline | icacls "C:\Users\test22\AppData\Roaming\x86_microsoft-windows-csrsrv.resources_31bf3856ad364e35_6.1.7601.17514_ru-ru_c920b87044297248" /inheritance:e /deny "*S-1-1-0:(R,REA,RA,RD)" |
cmdline | C:\Windows\system32\cmd.exe /c icacls "C:\Users\test22\AppData\Roaming\x86_microsoft-windows-csrsrv.resources_31bf3856ad364e35_6.1.7601.17514_ru-ru_c920b87044297248" /inheritance:e /deny "*S-1-1-0:(R,REA,RA,RD)" & icacls "C:\Users\test22\AppData\Roaming\x86_microsoft-windows-csrsrv.resources_31bf3856ad364e35_6.1.7601.17514_ru-ru_c920b87044297248" /inheritance:e /deny "*S-1-5-7:(R,REA,RA,RD)" & icacls "C:\Users\test22\AppData\Roaming\x86_microsoft-windows-csrsrv.resources_31bf3856ad364e35_6.1.7601.17514_ru-ru_c920b87044297248" /inheritance:e /deny "test22:(R,REA,RA,RD)" |
registry | HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__ |
Elastic | malicious (high confidence) |
McAfee | Artemis!5805AEC9385D |
Cylance | Unsafe |
Symantec | ML.Attribute.HighConfidence |
ESET-NOD32 | a variant of Win32/Packed.Themida.HJQ |
APEX | Malicious |
Avast | FileRepMalware |
Kaspersky | UDS:Trojan.Win32.Bingoml |
NANO-Antivirus | Virus.Win32.Gen-Crypt.ccnc |
McAfee-GW-Edition | Artemis!Trojan |
FireEye | Generic.mg.5805aec9385d2fac |
Sophos | ML/PE-A |
SentinelOne | Static AI - Malicious PE |
eGambit | PE.Heur.InvalidSig |
Gridinsoft | Trojan.Heur!.01212031 |
Microsoft | Trojan:Win32/Sabsik.FL.B!ml |
Cynet | Malicious (score: 100) |
Acronis | suspicious |
BitDefenderTheta | Gen:NN.ZexaF.34266.CYY@aey!3pei |
VBA32 | BScope.TrojanBanker.Banbra |
Yandex | Trojan.GenAsa!IIuaU2lPQB8 |
MaxSecure | Trojan.Malware.300983.susgen |
AVG | FileRepMalware |
Cybereason | malicious.100ad3 |
Paloalto | generic.ml |