Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | July 8, 2022, 7 p.m. | July 8, 2022, 7:07 p.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,AjkRVrFNnyQmqXQdrComyaiwV
2780-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,AjkRVrFNnyQmqXQdrComyaiwV
2296
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,AkMhEGvNFpnSswjeCw
2864-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,AkMhEGvNFpnSswjeCw
2832
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,BMIWqtk
2956-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,BMIWqtk
2444
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,BpsBUyIiAmXYU
3044-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,BpsBUyIiAmXYU
2728
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,BxBybURSqJfOwVmXj
2116-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,BxBybURSqJfOwVmXj
2924
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,CCSLGUsdVtcCbfF
2184-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,CCSLGUsdVtcCbfF
3032
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,CWBdqFubMR
2388-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,CWBdqFubMR
2056
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,CbEceKaoQvfuhhIK
2644-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,CbEceKaoQvfuhhIK
2140
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,CcBDyidVYuvtjWfG
2952-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,CcBDyidVYuvtjWfG
2440
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,CeOVtVdkUnRPoUvswsvkEf
2416-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,CeOVtVdkUnRPoUvswsvkEf
2800
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,CvxIGiXAzAG
3056-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,CvxIGiXAzAG
2280
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,DPsWXvFrrwOLZwoq
2772-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,DPsWXvFrrwOLZwoq
2572
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,DllRegisterServer
3028-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,DllRegisterServer
1112-
regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\UeQorVovcGq\MvskxRUPOiGbutI.dll"
3800
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,ENtihcf
2196-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,ENtihcf
2072
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,EVYoaysfyVmedMKzqOkd
3012-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,EVYoaysfyVmedMKzqOkd
2856
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,FSgLIbzCJsGhKrdTRUhBnjq
2336-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,FSgLIbzCJsGhKrdTRUhBnjq
2560
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,FXswjNvwqEmJHSzKXfB
2236-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,FXswjNvwqEmJHSzKXfB
1992
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,FmRrLoGPniSXxeHYAaRXrsSIt
2664-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,FmRrLoGPniSXxeHYAaRXrsSIt
3124
-
-
explorer.exe C:\Windows\Explorer.EXE
1156 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,FzYYWlRKDQMfKaJAUq
3200-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,FzYYWlRKDQMfKaJAUq
3316
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,GEQqgSeWrJkaNSdjOw
3352-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,GEQqgSeWrJkaNSdjOw
3568
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,GLvPFjzv
3456-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,GLvPFjzv
3636
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,GTfYoyhXUmiOrfM
3560 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,GVTerofsGHUASHLhWfIFX
3732 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,GlLOHKioWJZCQPS
3904 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,GpqOdmj
4056 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,GtaEQGQNcgERZqWo
3108 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,GzdHPyIXWoMGb
3248 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,HKgdkPfboZzjQODFfSu
3420 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,HmXZBMEhrWvTg
3656 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,HvFWvy
3824 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,ICrKqnEJHHrxYaH
3960 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,IDENrF
2124 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,ISuniIBoqjzfv
2636 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,IcEiBSQQHwaxZGs
3584 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,JCFScdjDVMLKVa
3796 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,JGwGKVHFHwfxsyCIp
3964 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,JnkFkZthy
2064 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,LSRvMYckceDUkCMxwUAq
3652 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,LhZoEaJRggyJr
3300 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,MknuTlXosJJdvczIkg
3336 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,MrhDZxAutnSSobTVt
3536 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,NRfTvw
2344 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,NZDMYgNWoHhCVPBFWyuTBSesQ
3380 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,NmBmwe
3272 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,NzYPpUvQ
3880 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,OThzaIZTEfYKTCCRQlcnW
4124 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,OWMilsbkgGVyJL
4256 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,OguxguFiYSHz
4388 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,PHzWjRI
4504 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,PNJeVrAcZDAW
4620 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,PSDYwIgmLiVzYESIaUYrbKg
4720 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,PiJSThSmMmzNNC
4880 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,PneIJqdSVVerltCm
5004 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,PpsLezsCiHiCVkHmZP
5108 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,PuoUVwFKYxjCqT
4184 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,PwNlKX
4244 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,QRkaVvgiLqTCjGKy
4524 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,RJAcdfSthTv
4660 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,RYkwsDq
4812 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,RZtKxjO
5024 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,RcnQoaySRBXJxsiZQIHxe
4152 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,RdnXeofUSzEDgzxXeW
4360 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,RfsPQSmuvBYXfIScfOT
4632 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,RkfakVk
4704 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,RmhqixPgftgQ
5068 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,SInCoGYrouPZGmYYJGKIR
4364 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,SRXSueHCT
4564 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,SVlQsYSAXEyhEvVkdWdX
548 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,SnLgFTA
4920 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,SxfQZPkEOIcG
4464 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,TJZCJgp
1588 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,TSNqZL
1164 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,TfpEQJjWUDp
4776 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,TvUVDsEcInyvKdGRA
4580 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,TvtXyQtNShHDYCMvH
3520 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,UGXSNpc
4744 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,ULOMXGiV
4896 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,UVzHIeChKCEwTMG
5240 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,UagSsmENTltTUKpktiEuRJfE
5340 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,UbjFSQJG
5456 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,UjDfVglhgynLAuMpwrtpXkH
5580 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,UrxprELRNWbXXBuOJlJ
5704 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,VXDuMBzruSCyfbAMzIrvV
5824 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,VcrtEzpxSRmZr
5944 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,VkRjra
6044 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,WMxfpgNLwoiQTZjkM
5156 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,WjtCBeYwDkRZvKLfJD
5324 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,XoMiJXhdBRBldnkLkgMM
5520 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,XsBeDFcmOsaqRihqMytJ
5672 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,YGPQhuvjFbQXSoJfVilOnVw
5896 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,YvzKAJK
6088 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,ZAppiYnp
5164 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,ZXZEfUeKC
5432 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,ZoyjBLvuBnIxXaWxFC
5756 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,aZwlVZLRtCIfDmaYbAXR
5968 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,bdnAzUNoMZJXxzHG
5368 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,btmsIKQVm
5388 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,cFminOM
5860 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,cKjOEfqQYYQ
5132 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,czIvuAZ
5524 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,dMEJcsHSUiODu
5272 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,dPYgmMRi
2352 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,dStUmppUwHfwVxtCgCewXt
5412 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,deMXieymThIxfyWzHCMb
6136 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,dgCMMkwNpUNZ
5740 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,eDtAbxMTINFwGjIRymBKxBFTe
5360 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,ePfrWQkHuKqOV
6248 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,eQnPJdIEwUrOjHyYKajVY
6360 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,eWqtOcNgKbDEwKynrCTAaqRd
6472 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,eiRJXgFAjkyObQxtC
6592 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,fLsjxmtTmthGKPw
6716 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,fqsAeZLb
6832 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,frkkGhhTKCPBzCLoveBHn
6960 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,fxmvSQNzSiXj
7052 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,gATjvjWkzNfdmAJbeFMKFtUmoI
5264 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,gCFmNdxvaAq
6260 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,gfeRIwKkCZUnQQ
6424 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,gjZENXkR
6568 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,gzzlrzxMlshrI
6760 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,hClTxV
6916 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,hDdSABujeGhBdM
7068 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,hJbRrovBnfzadHBLOAaX
6216 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,hLNWWET
6344 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,iIJmtODVuCFQPMFae
6712 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,iItzzFKWzIZojfOFqJG
6980 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,ibqesePIQXoUwnfgkLvfcuMFHK
6156 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,ieuLWaTjVeuBYegSaGXuly
6548 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,igFffrhNCQcHQStroQFS
6880 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,irtTnxRuuXAWDuDRGCivHz
7040 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,jVNpFjHcSQ
6676 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,jotleypmamgIHEUfZPLSmMtq
6840 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,jrkFXlWfdhOn
6704 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,kOcvjMhVkKI
6160 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,kPsHiOxOlxeVBpHYooACxIXHB
6488 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,kUHyuFSDHjRQgcFnZIHgvahta
6944 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,kXMermOELWqc
7292 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,kkWRnVCjitIbHTy
7416 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,kpoFTDgQJFpD
7532 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,kvCgXPvHuWWWdAHGy
7632 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,lFcjChjFWgKWuOuaAxn
7732 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,lKFTvqNg
7848 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,lcbnVGCdYXcKZTYevsVX
7972 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,lefIOOsVMhliLLj
8084 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,mKrNVAlauoRSIht
6240 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,nRVfeUAoalGiEviupjuyTviKt
7268 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,nWkMZMN
7452 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,naKLRCkO
7628 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,njUWLbQgRBGSd
7756 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,nlBfCJTJQhnnPxbkQkUAwWpmaA
7952 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,nmBYnmjGCq
8160 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,oIAdOUfQaetEfqMDSL
7320 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,osSAAvHx
7572 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,ovwgmHjsMpOQyjNpuqeLd
7768 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,ozpFyAlRWIHNYPuJbOLpoZosmO
7992 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,pAbWNQjHuawouRBUprBVrXw
7328 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,pCYRinZyYkFOxayPFyJDEDxKzO
7748 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,pQvYHQSqPMdqFOFub
8164 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,pbzbgZeZipMwitVYJJbYTdyYQ
7288 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,pnbxRJnSdfpDADRIEWZXepR
8008 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,qAirVWefWGdomxGs
7332 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,qbgUwwXPUNM
8188 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,rJVMJaiBojiOWxURyzmLWnxH
8040 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,rOlGGoosrOYjYnwqSX
8060 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,rSHUNkevMkknNwSlqR
7568 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,rmrMOmqIIM
8308 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,sBcaPzIWckINwkFTBxmdkiKID
8404 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,sJXDLm
8528 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,sNQjkxnpfL
8644 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,sPKnvGEKVGRHsXgbRRJFS
8776 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,snoSMpnSAlGCDUoadZDE
8892 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,tGDiqYCDbgMaBXHmxqrJv
9016 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,tGdwKquShaUWskzgERPqeG
9140 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,tXncljehbaR
8268 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,taNCAYWnFedga
8432 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,uFBMgXMRHfYmHKtd
8612 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,uQadijPTgYiRGTkxDpqTOeI
8708 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,vlEZdJoJilVuJxGaLFCzX
8904 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,vlPATCQWfWfv
9092 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,vnMwerzIvV
7876 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,wDtWqzCTVUWdqo
8452 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,weKcSTEtgvLwNKGEWr
8588 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,wyslQDXAh
8800 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,xRklmHvgNdkXc
9060 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,xbTTVacjLMTUBskAADEzpolBV
8284 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,xbcfQIhiMJswKveISUtGpEWTr
8740 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,ytgHNsgBKfkMoZjHI
8916 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,zLypEkbxfdampkTf
8396 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,ziTLFIzOnbzURBefGdA
8988 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\9dwcb1g2Vqh3Owz.dll,
7812
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
103.126.216.86 | Active | Moloch |
103.224.241.74 | Active | Moloch |
103.41.204.169 | Active | Moloch |
103.71.99.57 | Active | Moloch |
103.85.95.4 | Active | Moloch |
104.248.225.227 | Active | Moloch |
128.199.217.206 | Active | Moloch |
139.196.72.155 | Active | Moloch |
139.59.80.108 | Active | Moloch |
165.232.185.110 | Active | Moloch |
174.138.33.49 | Active | Moloch |
175.126.176.79 | Active | Moloch |
178.238.225.252 | Active | Moloch |
178.62.112.199 | Active | Moloch |
188.165.79.151 | Active | Moloch |
188.225.32.231 | Active | Moloch |
190.145.8.4 | Active | Moloch |
196.44.98.190 | Active | Moloch |
198.199.70.22 | Active | Moloch |
202.134.4.210 | Active | Moloch |
5.253.30.17 | Active | Moloch |
54.37.106.167 | Active | Moloch |
54.37.228.122 | Active | Moloch |
62.171.178.147 | Active | Moloch |
87.106.97.83 | Active | Moloch |
Suricata Alerts
Suricata TLS
No Suricata TLS
ip | 103.224.241.74 |
ip | 104.248.225.227 |
ip | 139.196.72.155 |
ip | 178.62.112.199 |
ip | 188.225.32.231 |
ip | 196.44.98.190 |
ip | 198.199.70.22 |
ip | 5.253.30.17 |
ip | 54.37.106.167 |
cmdline | C:\Windows\system32\regsvr32.exe "C:\Windows\system32\UeQorVovcGq\MvskxRUPOiGbutI.dll" |
Elastic | malicious (high confidence) |
FireEye | Generic.mg.0abd7dda188ea78f |
CrowdStrike | win/malicious_confidence_100% (W) |
TrendMicro | TrojanSpy.Win64.EMOTET.SMYXCFC |
McAfee-GW-Edition | Emotet-FTY!0ABD7DDA188E |
Microsoft | Trojan:Win32/Wacatac.B!ml |
McAfee | Emotet-FTY!0ABD7DDA188E |
section | {u'size_of_data': u'0x0002e600', u'virtual_address': u'0x0001a000', u'entropy': 7.832588443776013, u'name': u'.rsrc', u'virtual_size': u'0x0002e480'} | entropy | 7.83258844378 | description | A section with a high entropy has been found | |||||||||
entropy | 0.669675090253 | description | Overall entropy of this PE file is high |
process | regsvr32.exe |
process | rundll32.exe |
host | 103.126.216.86 | |||
host | 103.224.241.74 | |||
host | 103.41.204.169 | |||
host | 103.71.99.57 | |||
host | 103.85.95.4 | |||
host | 104.248.225.227 | |||
host | 128.199.217.206 | |||
host | 139.196.72.155 | |||
host | 139.59.80.108 | |||
host | 165.232.185.110 | |||
host | 174.138.33.49 | |||
host | 175.126.176.79 | |||
host | 178.238.225.252 | |||
host | 178.62.112.199 | |||
host | 188.165.79.151 | |||
host | 188.225.32.231 | |||
host | 190.145.8.4 | |||
host | 196.44.98.190 | |||
host | 198.199.70.22 | |||
host | 202.134.4.210 | |||
host | 5.253.30.17 | |||
host | 54.37.106.167 | |||
host | 54.37.228.122 | |||
host | 62.171.178.147 | |||
host | 87.106.97.83 |
service_name | MvskxRUPOiGbutI.dll | service_path | C:\Windows\System32\regsvr32.exe "C:\Windows\system32\UeQorVovcGq\MvskxRUPOiGbutI.dll" |
file | C:\Windows\System32\UeQorVovcGq\MvskxRUPOiGbutI.dll:Zone.Identifier |
dead_host | 87.106.97.83:7080 |
dead_host | 192.168.56.101:49404 |
dead_host | 190.145.8.4:443 |
dead_host | 192.168.56.101:49448 |
dead_host | 103.85.95.4:8080 |
dead_host | 192.168.56.101:49452 |
dead_host | 192.168.56.101:49436 |
dead_host | 165.232.185.110:8080 |
dead_host | 192.168.56.101:49424 |
dead_host | 103.71.99.57:8080 |
dead_host | 103.41.204.169:8080 |
dead_host | 192.168.56.101:49406 |
dead_host | 128.199.217.206:443 |
dead_host | 192.168.56.101:49468 |
dead_host | 174.138.33.49:7080 |
dead_host | 54.37.228.122:443 |
dead_host | 175.126.176.79:8080 |
dead_host | 62.171.178.147:8080 |
dead_host | 178.238.225.252:8080 |
dead_host | 192.168.56.101:49402 |
dead_host | 139.59.80.108:8080 |
dead_host | 192.168.56.101:49420 |
dead_host | 192.168.56.101:49443 |
dead_host | 192.168.56.101:49400 |
dead_host | 202.134.4.210:7080 |
dead_host | 192.168.56.101:49439 |