Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | July 15, 2022, 7:52 a.m. | July 15, 2022, 7:55 a.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,AjkRVrFNnyQmqXQdrComyaiwV
2776-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,AjkRVrFNnyQmqXQdrComyaiwV
2304
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,AkMhEGvNFpnSswjeCw
2888-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,AkMhEGvNFpnSswjeCw
2420
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,BMIWqtk
2984-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,BMIWqtk
2516
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,BpsBUyIiAmXYU
2064-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,BpsBUyIiAmXYU
2720
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,BxBybURSqJfOwVmXj
2132-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,BxBybURSqJfOwVmXj
2924
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,CCSLGUsdVtcCbfF
2252-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,CCSLGUsdVtcCbfF
3004
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,CWBdqFubMR
2448-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,CWBdqFubMR
3056
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,CbEceKaoQvfuhhIK
2792-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,CbEceKaoQvfuhhIK
1304
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,CcBDyidVYuvtjWfG
3068-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,CcBDyidVYuvtjWfG
2768
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,CeOVtVdkUnRPoUvswsvkEf
2416-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,CeOVtVdkUnRPoUvswsvkEf
1988
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,CvxIGiXAzAG
2860-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,CvxIGiXAzAG
2436
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,DPsWXvFrrwOLZwoq
2856-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,DPsWXvFrrwOLZwoq
2744
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,DllRegisterServer
2116-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,DllRegisterServer
2812-
regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\MxDzSVtwfSRlLv\dnfqUgyyGIrKnZE.dll"
3724
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,ENtihcf
2588-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,ENtihcf
2572
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,EVYoaysfyVmedMKzqOkd
2824-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,EVYoaysfyVmedMKzqOkd
2884
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,FSgLIbzCJsGhKrdTRUhBnjq
2756-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,FSgLIbzCJsGhKrdTRUhBnjq
2292
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,FXswjNvwqEmJHSzKXfB
152-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,FXswjNvwqEmJHSzKXfB
2964
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,FmRrLoGPniSXxeHYAaRXrsSIt
3108-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,FmRrLoGPniSXxeHYAaRXrsSIt
3236
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,FzYYWlRKDQMfKaJAUq
3228-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,FzYYWlRKDQMfKaJAUq
3480
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,GEQqgSeWrJkaNSdjOw
3368-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,GEQqgSeWrJkaNSdjOw
3512
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,GLvPFjzv
3472-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,GLvPFjzv
3656
-
-
explorer.exe C:\Windows\Explorer.EXE
1156 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,GTfYoyhXUmiOrfM
3648-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,GTfYoyhXUmiOrfM
3812
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,GlLOHKioWJZCQPS
3948-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,GlLOHKioWJZCQPS
3152
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,GVTerofsGHUASHLhWfIFX
3848-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,GVTerofsGHUASHLhWfIFX
2400
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,GpqOdmj
4036-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,GpqOdmj
3260
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,GtaEQGQNcgERZqWo
3104-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,GtaEQGQNcgERZqWo
2396
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,GzdHPyIXWoMGb
3248 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,HKgdkPfboZzjQODFfSu
3640 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,HmXZBMEhrWvTg
3824 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,HvFWvy
4020 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,ICrKqnEJHHrxYaH
3308 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,IDENrF
3552 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,ISuniIBoqjzfv
3484 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,IcEiBSQQHwaxZGs
4028 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,JCFScdjDVMLKVa
3324 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,JGwGKVHFHwfxsyCIp
556 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,JnkFkZthy
3680 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,LSRvMYckceDUkCMxwUAq
232 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,LhZoEaJRggyJr
1548 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,MknuTlXosJJdvczIkg
1872 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,MrhDZxAutnSSobTVt
3892 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,NRfTvw
3156 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,NZDMYgNWoHhCVPBFWyuTBSesQ
1820 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,NmBmwe
3508 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,NzYPpUvQ
2384 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,OThzaIZTEfYKTCCRQlcnW
2920 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,OWMilsbkgGVyJL
4140 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,OguxguFiYSHz
4244 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,PHzWjRI
4360 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,PNJeVrAcZDAW
4460 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,PSDYwIgmLiVzYESIaUYrbKg
4584 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,PiJSThSmMmzNNC
4684 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,PneIJqdSVVerltCm
4804 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,PpsLezsCiHiCVkHmZP
4920 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,PuoUVwFKYxjCqT
5036 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,PwNlKX
4120 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,QRkaVvgiLqTCjGKy
4316 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,RJAcdfSthTv
4480 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,RYkwsDq
4636 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,RZtKxjO
4792 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,RcnQoaySRBXJxsiZQIHxe
4964 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,RdnXeofUSzEDgzxXeW
3432 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,RfsPQSmuvBYXfIScfOT
4408 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,RkfakVk
4596 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,RmhqixPgftgQ
4528 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,SInCoGYrouPZGmYYJGKIR
5088 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,SRXSueHCT
4444 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,SVlQsYSAXEyhEvVkdWdX
4760 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,SnLgFTA
4864 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,SxfQZPkEOIcG
792 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,TJZCJgp
4788 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,TSNqZL
4292 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,TfpEQJjWUDp
5052 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,TvUVDsEcInyvKdGRA
4620 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,TvtXyQtNShHDYCMvH
4664 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,UGXSNpc
5136 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,ULOMXGiV
5240 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,UVzHIeChKCEwTMG
5372 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,UagSsmENTltTUKpktiEuRJfE
5484 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,UbjFSQJG
5604 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,UjDfVglhgynLAuMpwrtpXkH
5724 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,UrxprELRNWbXXBuOJlJ
5832 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,VXDuMBzruSCyfbAMzIrvV
5952 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,VcrtEzpxSRmZr
6096 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,VkRjra
5180 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,WMxfpgNLwoiQTZjkM
5208 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,WjtCBeYwDkRZvKLfJD
5468 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,XoMiJXhdBRBldnkLkgMM
5640 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,XsBeDFcmOsaqRihqMytJ
5828 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,YGPQhuvjFbQXSoJfVilOnVw
5992 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,YvzKAJK
6076 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,ZAppiYnp
5296 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,ZXZEfUeKC
5556 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,ZoyjBLvuBnIxXaWxFC
5816 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,aZwlVZLRtCIfDmaYbAXR
6044 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,bdnAzUNoMZJXxzHG
5264 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,btmsIKQVm
5292 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,cFminOM
5976 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,cKjOEfqQYYQ
5416 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,czIvuAZ
5620 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,dMEJcsHSUiODu
5696 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,dPYgmMRi
6128 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,dStUmppUwHfwVxtCgCewXt
5204 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,deMXieymThIxfyWzHCMb
6056 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,dgCMMkwNpUNZ
6200 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,eDtAbxMTINFwGjIRymBKxBFTe
6316 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,ePfrWQkHuKqOV
6416 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,eQnPJdIEwUrOjHyYKajVY
6536 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,eWqtOcNgKbDEwKynrCTAaqRd
6636 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,eiRJXgFAjkyObQxtC
6764 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,fLsjxmtTmthGKPw
6884 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,fqsAeZLb
7008 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,frkkGhhTKCPBzCLoveBHn
7104 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,fxmvSQNzSiXj
5744 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,gATjvjWkzNfdmAJbeFMKFtUmoI
6380 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,gCFmNdxvaAq
6492 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,gfeRIwKkCZUnQQ
6680 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,gjZENXkR
6744 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,gzzlrzxMlshrI
6992 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,hClTxV
6248 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,hDdSABujeGhBdM
6552 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,hJbRrovBnfzadHBLOAaX
6692 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,hLNWWET
6972 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,iIJmtODVuCFQPMFae
6184 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,iItzzFKWzIZojfOFqJG
6620 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,ibqesePIQXoUwnfgkLvfcuMFHK
6900 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,ieuLWaTjVeuBYegSaGXuly
5340 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,igFffrhNCQcHQStroQFS
6668 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,irtTnxRuuXAWDuDRGCivHz
6364 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,jVNpFjHcSQ
6728 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,jotleypmamgIHEUfZPLSmMtq
7100 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,jrkFXlWfdhOn
6740 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,kOcvjMhVkKI
7220 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,kPsHiOxOlxeVBpHYooACxIXHB
7320 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,kUHyuFSDHjRQgcFnZIHgvahta
7452 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,kXMermOELWqc
7580 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,kkWRnVCjitIbHTy
7676 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,kpoFTDgQJFpD
7800 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,kvCgXPvHuWWWdAHGy
7920 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,lFcjChjFWgKWuOuaAxn
8020 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,lKFTvqNg
8136 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,lcbnVGCdYXcKZTYevsVX
7236 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,lefIOOsVMhliLLj
7348 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,mKrNVAlauoRSIht
1200 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,nRVfeUAoalGiEviupjuyTviKt
7664 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,nWkMZMN
7832 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,naKLRCkO
8072 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,njUWLbQgRBGSd
7264 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,nlBfCJTJQhnnPxbkQkUAwWpmaA
7464 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,nmBYnmjGCq
1276 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,oIAdOUfQaetEfqMDSL
7888 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,osSAAvHx
8100 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,ovwgmHjsMpOQyjNpuqeLd
7360 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,ozpFyAlRWIHNYPuJbOLpoZosmO
7612 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,pAbWNQjHuawouRBUprBVrXw
7816 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,pCYRinZyYkFOxayPFyJDEDxKzO
7860 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,pQvYHQSqPMdqFOFub
7736 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,pbzbgZeZipMwitVYJJbYTdyYQ
8032 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,pnbxRJnSdfpDADRIEWZXepR
7764 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,qAirVWefWGdomxGs
7684 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,qbgUwwXPUNM
8176 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,rJVMJaiBojiOWxURyzmLWnxH
7716 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,rOlGGoosrOYjYnwqSX
8268 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,rSHUNkevMkknNwSlqR
8372 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,rmrMOmqIIM
8500 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,sBcaPzIWckINwkFTBxmdkiKID
8644 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,sJXDLm
8744 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,sNQjkxnpfL
8868 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,sPKnvGEKVGRHsXgbRRJFS
8984 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,snoSMpnSAlGCDUoadZDE
9108 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,tGDiqYCDbgMaBXHmxqrJv
7796 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,tGdwKquShaUWskzgERPqeG
8384 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,tXncljehbaR
8596 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,taNCAYWnFedga
8740 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,uFBMgXMRHfYmHKtd
8904 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,uQadijPTgYiRGTkxDpqTOeI
9068 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,vlEZdJoJilVuJxGaLFCzX
9212 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,vlPATCQWfWfv
8308 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,vnMwerzIvV
8488 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,wDtWqzCTVUWdqo
8948 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,weKcSTEtgvLwNKGEWr
9188 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,wyslQDXAh
8196 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,xRklmHvgNdkXc
8516 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,xbTTVacjLMTUBskAADEzpolBV
8852 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,xbcfQIhiMJswKveISUtGpEWTr
8636 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,ytgHNsgBKfkMoZjHI
9184 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,zLypEkbxfdampkTf
9016 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,ziTLFIzOnbzURBefGdA
8360 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\FnrTI.dll,
8612
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
Suricata Alerts
Suricata TLS
No Suricata TLS
cmdline | C:\Windows\system32\regsvr32.exe "C:\Windows\system32\MxDzSVtwfSRlLv\dnfqUgyyGIrKnZE.dll" |
section | {u'size_of_data': u'0x0002be00', u'virtual_address': u'0x0001b000', u'entropy': 7.848244115365133, u'name': u'.rsrc', u'virtual_size': u'0x0002bc80'} | entropy | 7.84824411537 | description | A section with a high entropy has been found | |||||||||
entropy | 0.654850746269 | description | Overall entropy of this PE file is high |
process | regsvr32.exe |
process | rundll32.exe |
host | 104.168.155.143 | |||
host | 144.202.108.116 | |||
host | 149.56.131.28 | |||
host | 164.90.222.65 | |||
host | 172.105.226.75 | |||
host | 196.218.30.83 | |||
host | 207.148.79.14 | |||
host | 213.239.212.5 |
service_name | dnfqUgyyGIrKnZE.dll | service_path | C:\Windows\System32\regsvr32.exe "C:\Windows\system32\MxDzSVtwfSRlLv\dnfqUgyyGIrKnZE.dll" |
file | C:\Windows\System32\MxDzSVtwfSRlLv\dnfqUgyyGIrKnZE.dll:Zone.Identifier |
Lionic | Trojan.Win64.Strab.4!c |
Elastic | malicious (moderate confidence) |
Cynet | Malicious (score: 99) |
FireEye | Generic.mg.745dac0fc6ed2014 |
CAT-QuickHeal | Trojan.Win64 |
McAfee | Emotet-FTY!745DAC0FC6ED |
Malwarebytes | Trojan.Emotet |
Sangfor | Trojan.Win64.Kryptik.DHR |
K7AntiVirus | Trojan ( 0059554a1 ) |
BitDefender | Trojan.GenericKD.50608750 |
K7GW | Trojan ( 0059554a1 ) |
CrowdStrike | win/malicious_confidence_100% (W) |
Arcabit | Trojan.Generic.D3043A6E |
Cyren | W64/S-ec2e480c!Eldorado |
Symantec | Trojan.Gen.MBT |
ESET-NOD32 | a variant of Win64/Kryptik.DHR |
Paloalto | generic.ml |
ClamAV | Win.Trojan.Emotet-9955402-0 |
Kaspersky | Trojan.Win64.Strab.n |
Alibaba | Trojan:Win64/Strab.7b781f12 |
ViRobot | Trojan.Win32.Z.Emotet.275456.KB |
MicroWorld-eScan | Trojan.GenericKD.50608750 |
Avast | Win64:BotX-gen [Trj] |
Tencent | Trojan.Win64.Kryptik.zr |
Ad-Aware | Trojan.GenericKD.50608750 |
Emsisoft | Trojan.GenericKD.50608750 (B) |
Comodo | Malware@#3au9qi7krnqm3 |
F-Secure | Trojan.TR/Kryptik.pwmhf |
DrWeb | Trojan.Emotet.1203 |
VIPRE | Trojan.GenericKD.50608750 |
TrendMicro | TrojanSpy.Win64.EMOTET.SMYXCFC |
McAfee-GW-Edition | Emotet-FTY!745DAC0FC6ED |
Sophos | Mal/Generic-S + Troj/Emotet-DCG |
Jiangmin | Trojan.Strab.bcj |
Webroot | W32.Trojan.Emotet |
Avira | TR/Kryptik.pwmhf |
Antiy-AVL | Trojan/Generic.ASMalwS.6C82 |
Kingsoft | Win32.Troj.Win64.n.(kcloud) |
Microsoft | Trojan:Win64/Emotet.BY!MTB |
GData | Trojan.GenericKD.50608750 |
AhnLab-V3 | Malware/Win.FTY.R503424 |
VBA32 | Trojan.Win64.Emotet |
ALYac | Trojan.Agent.Emotet |
MAX | malware (ai score=99) |
Cylance | Unsafe |
Rising | Trojan.Emotet/x64!1.DEEF (CLASSIC) |
Yandex | Trojan.Strab!V/4HjPjRRxs |
Ikarus | Trojan-Spy.Emotet |
MaxSecure | Trojan.Malware.185465870.susgen |
Fortinet | W64/Emotet.G!tr |
dead_host | 144.202.108.116:8080 |
dead_host | 207.148.79.14:8080 |
dead_host | 164.90.222.65:443 |
dead_host | 196.218.30.83:443 |
dead_host | 104.168.155.143:8080 |