Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | Jan. 20, 2022, 10:04 a.m. | Jan. 20, 2022, 10:07 a.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\image.png.dll,EproyAklW
2248-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\image.png.dll,EproyAklW
1088
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\image.png.dll,K766MrG4
2372-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\image.png.dll,K766MrG4
2528-
cmd.exe cmd /c choice /c y /d y /t 6 & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\image.png.dll", K766MrG4 wD6bUqfE kO5rG7fD & exit
2036-
choice.exe choice /c y /d y /t 6
2788 -
rundll32.exe "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\image.png.dll", K766MrG4 wD6bUqfE kO5rG7fD
2288
-
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\image.png.dll,CarefullyAbout
2192-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\image.png.dll,CarefullyAbout
2908-
cmd.exe cmd /c ping 127.0.0.1 -n 10 -i 44 > NUL & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\image.png.dll", CarefullyAbout wD6bUqfE kO5rG7fD & exit
968-
PING.EXE ping 127.0.0.1 -n 10 -i 44
1692 -
rundll32.exe "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\image.png.dll", CarefullyAbout wD6bUqfE kO5rG7fD
2244
-
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\image.png.dll,OlPy2
2508-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\image.png.dll,OlPy2
2808
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\image.png.dll,PeopleAcross
2572-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\image.png.dll,PeopleAcross
2260-
cmd.exe cmd /c ping 192.0.2.47 -n 6 -i 53 -w 1000 > NUL & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\image.png.dll", PeopleAcross wD6bUqfE kO5rG7fD & exit
2024-
PING.EXE ping 192.0.2.47 -n 6 -i 53 -w 1000
2624 -
rundll32.exe "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\image.png.dll", PeopleAcross wD6bUqfE kO5rG7fD
1308
-
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\image.png.dll,ProgrammeSome
2972-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\image.png.dll,ProgrammeSome
2232-
cmd.exe cmd /c ping 192.0.2.35 -n 10 -w 1000 > NUL & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\image.png.dll", ProgrammeSome wD6bUqfE kO5rG7fD & exit
2500-
PING.EXE ping 192.0.2.35 -n 10 -w 1000
1732 -
rundll32.exe "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\image.png.dll", ProgrammeSome wD6bUqfE kO5rG7fD
2492
-
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\image.png.dll,Yn6xc
2240-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\image.png.dll,Yn6xc
2652
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\image.png.dll,n2E5g
2712-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\image.png.dll,n2E5g
2420-
cmd.exe cmd /c ping 192.0.2.28 -n 10 -4 -w 1000 & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\image.png.dll", n2E5g wD6bUqfE kO5rG7fD & exit
2032-
PING.EXE ping 192.0.2.28 -n 10 -4 -w 1000
2740 -
rundll32.exe "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\image.png.dll", n2E5g wD6bUqfE kO5rG7fD
1600
-
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\image.png.dll,
612
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
resource name | None |
description | rundll32.exe tried to sleep 644 seconds, actually delayed analysis time by 644 seconds |
Elastic | malicious (high confidence) |
Webroot | W32.Trojan.Trickbot |
section | {u'size_of_data': u'0x00020000', u'virtual_address': u'0x00092000', u'entropy': 7.800114792958684, u'name': u'.data', u'virtual_size': u'0x000260f0'} | entropy | 7.80011479296 | description | A section with a high entropy has been found |
cmdline | cmd /c ping 192.0.2.35 -n 10 -w 1000 > NUL & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\image.png.dll", ProgrammeSome wD6bUqfE kO5rG7fD & exit |
cmdline | cmd /c ping 192.0.2.28 -n 10 -4 -w 1000 & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\image.png.dll", n2E5g wD6bUqfE kO5rG7fD & exit |
cmdline | cmd /c ping 127.0.0.1 -n 10 -i 44 > NUL & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\image.png.dll", CarefullyAbout wD6bUqfE kO5rG7fD & exit |
cmdline | ping 127.0.0.1 -n 10 -i 44 |
cmdline | ping 192.0.2.35 -n 10 -w 1000 |
cmdline | cmd /c ping 192.0.2.47 -n 6 -i 53 -w 1000 > NUL & "C:\Windows\system32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\image.png.dll", PeopleAcross wD6bUqfE kO5rG7fD & exit |
cmdline | ping 192.0.2.47 -n 6 -i 53 -w 1000 |
cmdline | ping 192.0.2.28 -n 10 -4 -w 1000 |