Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Feb. 9, 2023, 10:44 a.m. | Feb. 9, 2023, 10:45 a.m. |
-
f6ad5fe2-5c5e-4386-bdad-f48d7d797960.exe "C:\Users\test22\AppData\Local\Temp\f6ad5fe2-5c5e-4386-bdad-f48d7d797960.exe"
2560
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | mi_exe_stub.pdb |
section | .didat |
resource name | B |
resource name | GOOGLEUPDATE |
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_ARABIC_SYRIA | offset | 0x00183838 | size | 0x0000017a |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_mr.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_pt-PT.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_ro.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_ar.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_ca.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_sr-Cyrl-RS.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_lt.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_quz.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdate.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_cs.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_sk.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_ta.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_mi.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_fr-CA.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_sq.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_as.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_gd.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_km.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_kn.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_pl.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_ko.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\psuser_64.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\MicrosoftEdgeUpdate.exe |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_sr.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_fr.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_nb.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_cy.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_ur.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_ug.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\MicrosoftEdgeUpdateOnDemand.exe |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_hr.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_de.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_am.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_gu.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_en.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_id.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_nl.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\psuser_arm64.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_ru.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_lb.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_bn-IN.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_uk.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_af.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_lv.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\MicrosoftEdgeUpdateBroker.exe |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_it.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_pa.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_tr.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_zh-CN.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_tt.dll |
section | {u'size_of_data': u'0x0015c400', u'virtual_address': u'0x00028000', u'entropy': 7.983751722010894, u'name': u'.rsrc', u'virtual_size': u'0x0015c284'} | entropy | 7.98375172201 | description | A section with a high entropy has been found | |||||||||
entropy | 0.903079416532 | description | Overall entropy of this PE file is high |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_mr.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_pt-PT.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_zh-TW.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_ar.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_ca.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_sr-Cyrl-RS.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_lt.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_quz.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdate.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_cs.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_sk.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_ta.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_mi.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_fr-CA.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_sq.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_as.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_gd.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_km.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_kn.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_cy.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_ko.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\MicrosoftEdgeUpdateSetup.exe |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\psuser_64.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\MicrosoftEdgeUpdate.exe |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_sr.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_fr.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_nb.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_pl.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_ur.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_ug.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\NOTICE.TXT |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\MicrosoftEdgeUpdateOnDemand.exe |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_ro.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_hr.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_de.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_am.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_gu.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_en.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_id.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_nl.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\psuser_arm64.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_ru.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_lb.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_bn-IN.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_uk.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_af.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_lv.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\MicrosoftEdgeUpdateBroker.exe |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_it.dll |
file | C:\Program Files (x86)\Microsoft\Temp\EUEEB5.tmp\msedgeupdateres_pa.dll |