Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Jan. 19, 2023, 12:35 p.m. | Jan. 19, 2023, 12:48 p.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?CallShowStatus@JKDefragLib@@QEAAXPEAUDefragDataStruct@@HH@Z
2628-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?CallShowStatus@JKDefragLib@@QEAAXPEAUDefragDataStruct@@HH@Z
3056
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?AddArrayString@JKDefragLib@@QEAAPEAPEA_WPEAPEA_WPEA_W@Z
2544-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?AddArrayString@JKDefragLib@@QEAAPEAPEA_WPEAPEA_WPEA_W@Z
2508
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?ColorizeItem@JKDefragLib@@QEAAXPEAUDefragDataStruct@@PEAUItemStruct@@_K2H@Z
2720-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?ColorizeItem@JKDefragLib@@QEAAXPEAUDefragDataStruct@@PEAUItemStruct@@_K2H@Z
1356
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?DeleteItemTree@JKDefragLib@@QEAAXPEAUItemStruct@@@Z
2808-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?DeleteItemTree@JKDefragLib@@QEAAXPEAUItemStruct@@@Z
2308
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?FragmentCount@JKDefragLib@@QEAAHPEAUItemStruct@@@Z
2900-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?FragmentCount@JKDefragLib@@QEAAHPEAUItemStruct@@@Z
2584
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?GetItemLcn@JKDefragLib@@QEAA_KPEAUItemStruct@@@Z
2992-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?GetItemLcn@JKDefragLib@@QEAA_KPEAUItemStruct@@@Z
2684
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?GetLongPath@JKDefragLib@@QEAAPEA_WPEAUDefragDataStruct@@PEAUItemStruct@@@Z
2072-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?GetLongPath@JKDefragLib@@QEAAPEA_WPEAUDefragDataStruct@@PEAUItemStruct@@@Z
2752
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?GetShortPath@JKDefragLib@@QEAAPEA_WPEAUDefragDataStruct@@PEAUItemStruct@@@Z
2192-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?GetShortPath@JKDefragLib@@QEAAPEA_WPEAUDefragDataStruct@@PEAUItemStruct@@@Z
3024
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?IsFragmented@JKDefragLib@@QEAAHPEAUItemStruct@@_K1@Z
2532-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?IsFragmented@JKDefragLib@@QEAAHPEAUItemStruct@@_K1@Z
604
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?MatchMask@JKDefragLib@@QEAAHPEA_W0@Z
2880-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?MatchMask@JKDefragLib@@QEAAHPEA_W0@Z
2052
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?RunJkDefrag@JKDefragLib@@QEAAXPEA_WHHNPEAPEA_W1PEAH1@Z
2100-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?RunJkDefrag@JKDefragLib@@QEAAXPEA_WHHNPEAPEA_W1PEAH1@Z
2488
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?ShowHex@JKDefragLib@@QEAAXPEAUDefragDataStruct@@PEAE_K@Z
2800-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?ShowHex@JKDefragLib@@QEAAXPEAUDefragDataStruct@@PEAE_K@Z
2116
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?SlowDown@JKDefragLib@@QEAAXPEAUDefragDataStruct@@@Z
2080-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?SlowDown@JKDefragLib@@QEAAXPEAUDefragDataStruct@@@Z
2788
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?StopJkDefrag@JKDefragLib@@QEAAXPEAHH@Z
2760-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?StopJkDefrag@JKDefragLib@@QEAAXPEAHH@Z
3196
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?SystemErrorStr@JKDefragLib@@QEAAXKPEA_W_K@Z
2664-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?SystemErrorStr@JKDefragLib@@QEAAXKPEA_W_K@Z
3352
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?TreeBiggest@JKDefragLib@@QEAAPEAUItemStruct@@PEAU2@@Z
3220-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?TreeBiggest@JKDefragLib@@QEAAPEAUItemStruct@@PEAU2@@Z
3424
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?TreeDetach@JKDefragLib@@QEAAXPEAUDefragDataStruct@@PEAUItemStruct@@@Z
3340-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?TreeDetach@JKDefragLib@@QEAAXPEAUDefragDataStruct@@PEAUItemStruct@@@Z
3596
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?TreeFirst@JKDefragLib@@QEAAPEAUItemStruct@@PEAU2@H@Z
3588-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?TreeFirst@JKDefragLib@@QEAAPEAUItemStruct@@PEAU2@H@Z
3756
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?TreeInsert@JKDefragLib@@QEAAXPEAUDefragDataStruct@@PEAUItemStruct@@@Z
3732-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?TreeInsert@JKDefragLib@@QEAAXPEAUDefragDataStruct@@PEAUItemStruct@@@Z
3952
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?TreeNext@JKDefragLib@@QEAAPEAUItemStruct@@PEAU2@@Z
3872-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?TreeNext@JKDefragLib@@QEAAPEAUItemStruct@@PEAU2@@Z
3280
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?TreeNextPrev@JKDefragLib@@QEAAPEAUItemStruct@@PEAU2@H@Z
4024-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?TreeNextPrev@JKDefragLib@@QEAAPEAUItemStruct@@PEAU2@H@Z
3544
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?TreePrev@JKDefragLib@@QEAAPEAUItemStruct@@PEAU2@@Z
3136-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?TreePrev@JKDefragLib@@QEAAPEAUItemStruct@@PEAU2@@Z
3628
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?TreeSmallest@JKDefragLib@@QEAAPEAUItemStruct@@PEAU2@@Z
3320-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?TreeSmallest@JKDefragLib@@QEAAPEAUItemStruct@@PEAU2@@Z
3708
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?stristr@JKDefragLib@@QEAAPEADPEAD0@Z
3552-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?stristr@JKDefragLib@@QEAAPEADPEAD0@Z
4020
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?stristrW@JKDefragLib@@QEAAPEA_WPEA_W0@Z
3900-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,?stristrW@JKDefragLib@@QEAAPEA_WPEA_W0@Z
3112
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,DllRegisterServer
3188-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,DllRegisterServer
3712-
regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\SqgVvKHZbUCIyvj\VomzcJxJr.dll"
3896
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\dKRRwATC1r1pz.dll,
3508 -
explorer.exe C:\Windows\Explorer.EXE
1452
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 149.28.143.92:443 -> 192.168.56.101:49227 | 2029340 | ET INFO TLS Handshake Failure | Potentially Bad Traffic |
TCP 192.168.56.101:49231 -> 187.63.160.88:80 | 2404307 | ET CNC Feodo Tracker Reported CnC Server group 8 | A Network Trojan was detected |
TCP 192.168.56.101:49223 -> 182.162.143.56:443 | 2404306 | ET CNC Feodo Tracker Reported CnC Server group 7 | A Network Trojan was detected |
TCP 182.162.143.56:443 -> 192.168.56.101:49224 | 2029340 | ET INFO TLS Handshake Failure | Potentially Bad Traffic |
TCP 187.63.160.88:80 -> 192.168.56.101:49232 | 2029340 | ET INFO TLS Handshake Failure | Potentially Bad Traffic |
Suricata TLS
No Suricata TLS
section | _RDATA |
cmdline | C:\Windows\system32\regsvr32.exe "C:\Windows\system32\SqgVvKHZbUCIyvj\VomzcJxJr.dll" |
process | regsvr32.exe |
process | rundll32.exe |
host | 110.232.117.186 | |||
host | 149.28.143.92 | |||
host | 169.60.181.70 | |||
host | 182.162.143.56 | |||
host | 187.63.160.88 | |||
host | 91.187.140.35 | |||
host | 94.23.45.86 | |||
host | 95.217.221.146 |
file | C:\Windows\System32\SqgVvKHZbUCIyvj\VomzcJxJr.dll:Zone.Identifier |
Lionic | Trojan.Win32.Emotet.L!c |
Elastic | malicious (high confidence) |
DrWeb | Trojan.Siggen19.2733 |
MicroWorld-eScan | Trojan.GenericKDZ.93259 |
ClamAV | Win.Malware.Gbix-9976817-0 |
ALYac | Trojan.Agent.Emotet |
Malwarebytes | Trojan.Emotet |
Zillya | Trojan.Injuke.Win32.26507 |
K7AntiVirus | Trojan ( 0059a90c1 ) |
Alibaba | Trojan:Win64/Injuke.507353de |
K7GW | Trojan ( 0059a90c1 ) |
CrowdStrike | win/malicious_confidence_100% (W) |
VirIT | Trojan.Win64.Genus.BQP |
Cyren | W64/S-8b4c5040!Eldorado |
Symantec | ML.Attribute.HighConfidence |
ESET-NOD32 | a variant of Win64/Kryptik.DOE |
Cynet | Malicious (score: 100) |
Kaspersky | Trojan.Win32.Injuke.fzpp |
BitDefender | Trojan.GenericKDZ.93259 |
Avast | Win64:BotX-gen [Trj] |
Tencent | Trojan.Win64.Kryptik.yw |
Emsisoft | Trojan.GenericKDZ.93259 (B) |
F-Secure | Trojan.TR/AD.Nekark.qwxzh |
VIPRE | Trojan.GenericKDZ.93259 |
TrendMicro | TrojanSpy.Win64.EMOTET.YXDARZ |
McAfee-GW-Edition | BehavesLike.Win64.Emotet.ch |
FireEye | Trojan.GenericKDZ.93259 |
Sophos | Mal/Generic-S + Troj/Emotet-DCP |
Jiangmin | Trojan.Injuke.qnq |
Webroot | W32.Trojan.Emotet |
Avira | TR/AD.Nekark.qwxzh |
Antiy-AVL | Trojan/Win32.Injuke |
Microsoft | Trojan:Win64/Emotet.EM!MTB |
Gridinsoft | Malware.Win64.Emotet.bot |
Arcabit | Trojan.Generic.D16C4B |
ZoneAlarm | Trojan.Win32.Injuke.fzpp |
GData | Trojan.GenericKDZ.93259 |
Detected | |
AhnLab-V3 | Trojan/Win.BotX-gen.R533097 |
McAfee | Artemis!2A4865151E02 |
MAX | malware (ai score=84) |
VBA32 | Trojan.Win64.Emotet |
Cylance | Unsafe |
TrendMicro-HouseCall | TrojanSpy.Win64.EMOTET.YXDARZ |
Rising | Trojan.Cobalt!8.C4EF (TFE:6:eR2NJLMzZWQ) |
Yandex | Trojan.Kryptik!p6jUxrGd0ww |
Ikarus | Trojan.Win64.Crypt |
MaxSecure | Trojan.Malware.192387666.susgen |
Fortinet | W32/Emotet.PACA!tr |
AVG | Win64:BotX-gen [Trj] |
dead_host | 94.23.45.86:4143 |
dead_host | 95.217.221.146:8080 |
dead_host | 169.60.181.70:8080 |
dead_host | 192.168.56.101:49234 |
dead_host | 91.187.140.35:8080 |