Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | May 20, 2022, 10:33 a.m. | May 20, 2022, 10:51 a.m. |
-
.svchost.exe "C:\Users\test22\AppData\Local\Temp\.svchost.exe"
2792 -
explorer.exe C:\Windows\Explorer.EXE
1156
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
103.176.113.85 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
file | C:\Users\test22\AppData\Local\Temp\clretwrc.dll |
file | C:\Users\test22\AppData\Local\Temp\CALCIFUGAL.lnk |
file | C:\Users\test22\AppData\Local\Temp\lang-1109.dll |
file | C:\Users\test22\AppData\Local\Temp\SharpDX.DXGI.dll |
file | C:\Users\test22\AppData\Local\Temp\nsaE2BF.tmp\System.dll |
file | C:\Users\test22\AppData\Local\Temp\lang-1026.dll |
file | C:\Users\test22\AppData\Local\Temp\Newtonsoft.Json.dll |
file | C:\Users\test22\AppData\Local\Temp\unmg.dll |
file | C:\Users\test22\AppData\Local\Temp\CALCIFUGAL.lnk |
file | C:\Users\test22\AppData\Local\Temp\Newtonsoft.Json.dll |
file | C:\Users\test22\AppData\Local\Temp\lang-1109.dll |
file | C:\Users\test22\AppData\Local\Temp\nsaE2BF.tmp\System.dll |
file | C:\Users\test22\AppData\Local\Temp\SharpDX.DXGI.dll |
file | C:\Users\test22\AppData\Local\Temp\unmg.dll |
file | C:\Users\test22\AppData\Local\Temp\lang-1026.dll |
host | 103.176.113.85 |
Bkav | W32.AIDetect.malware2 |
Lionic | Trojan.Win32.GuLoader.a!c |
MicroWorld-eScan | Trojan.GenericKD.50310877 |
FireEye | Trojan.GenericKD.50310877 |
ALYac | Trojan.GenericKD.50310877 |
Cylance | Unsafe |
Sangfor | Trojan.Win32.Save.a |
K7AntiVirus | Trojan ( 005903451 ) |
Alibaba | TrojanDownloader:Win32/GuLoader.cdb60e59 |
K7GW | Trojan ( 005903451 ) |
Cybereason | malicious.2817ab |
Cyren | W32/Trojan.HVNA-9307 |
Symantec | Trojan.Gen.2 |
Elastic | malicious (high confidence) |
ESET-NOD32 | NSIS/Injector.ASH |
APEX | Malicious |
Cynet | Malicious (score: 100) |
Kaspersky | HEUR:Trojan-Downloader.Win32.GuLoader.gen |
BitDefender | Trojan.GenericKD.50310877 |
Avast | FileRepMalware [Misc] |
Tencent | Win32.Trojan-downloader.Guloader.Lnxz |
Ad-Aware | Trojan.GenericKD.50310877 |
Emsisoft | Trojan.GenericKD.50310877 (B) |
McAfee-GW-Edition | BehavesLike.Win32.Dropper.jc |
Sophos | Mal/Generic-S |
Jiangmin | Trojan.Fsysna.niv |
Webroot | W32.Trojan.Gen |
Kingsoft | Win32.Troj.Undef.(kcloud) |
Microsoft | Trojan:Script/Phonzy.C!ml |
GData | Trojan.GenericKD.50310877 |
AhnLab-V3 | Trojan/Win.Wacatac.C5133102 |
McAfee | Artemis!AC5B584F655F |
MAX | malware (ai score=85) |
TrendMicro-HouseCall | TROJ_GEN.R002H0DEJ22 |
Ikarus | Trojan.MSIL.Inject |
AVG | FileRepMalware [Misc] |