Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | March 15, 2023, 9:01 a.m. | March 15, 2023, 9:03 a.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_attr_list_insert
2636-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_attr_list_insert
2420
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_attr_letter_spacing_new
2552-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_attr_letter_spacing_new
940
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_attr_list_new
2728-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_attr_list_new
2108
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_attr_list_unref
2816-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_attr_list_unref
2204
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_attr_strikethrough_new
2908-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_attr_strikethrough_new
2588
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_attr_underline_new
3000-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_attr_underline_new
2616
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_context_set_font_options
2056-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_context_set_font_options
2708
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_context_set_resolution
2228-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_context_set_resolution
812
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_font_map_create_context
2592-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_font_map_create_context
1216
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_font_map_get_default
2920-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_font_map_get_default
2180
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_font_map_get_type
1264-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_font_map_get_type
3040
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_font_map_new
2544-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_font_map_new
2188
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_font_map_set_resolution
2448-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_font_map_set_resolution
3308
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_layout_path
3228-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_layout_path
3440
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_show_layout
3384-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_show_layout
3712
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_update_context
3620-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_cairo_update_context
3876
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_context_get_font_description
3768-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_context_get_font_description
3892
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_context_get_gravity
3936-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_context_get_gravity
2428
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_context_set_base_dir
4076-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_context_set_base_dir
3368
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_context_set_base_gravity
3276-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_context_set_base_gravity
2536
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_context_set_gravity_hint
3588-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_context_set_gravity_hint
4004
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_context_set_language
3904-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_context_set_language
2520
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_copy
3180-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_copy
3680
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_free
3896-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_free
4072
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_from_string
3848-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_from_string
3668
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_new
3336-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_new
3216
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_set_family_static
3088-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_set_family_static
3992
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_set_size
3748-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_set_size
4244
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_set_stretch
4212-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_set_stretch
4400
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_set_style
4388-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_set_style
4576
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_set_variant
4536-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_set_variant
4764
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_set_weight
4652-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_description_set_weight
4900
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_map_create_context
4800-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_font_map_create_context
5084
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_gravity_to_rotation
4932-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_gravity_to_rotation
4132
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_language_from_string
5076-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_language_from_string
4264
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_context_changed
4420-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_context_changed
4632
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_get_context
4560-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_get_context
4844
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_get_extents
4776-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_get_extents
4492
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_get_iter
5068-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_get_iter
4596
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_get_size
4308-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_get_size
4852
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_iter_free
4484-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_iter_free
5056
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_iter_get_baseline
4828-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_iter_get_baseline
4820
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_new
4380-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_new
3432
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_alignment
4792-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_alignment
4184
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_attributes
4112-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_attributes
5192
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_auto_dir
5216-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_auto_dir
5416
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_ellipsize
5360-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_ellipsize
5616
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_font_description
5492-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_font_description
5808
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_height
5592-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_height
5912
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_indent
5744-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_indent
5980
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_justify
5876-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_justify
5288
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_markup
6048-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_markup
5272
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_single_paragraph_mode
5204-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_single_paragraph_mode
5576
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_text
5468-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_text
5856
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_width
5764-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_width
6008
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_wrap
5972-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_wrap
5560
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,init
5276-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,init
5784
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,
5476
Name | Response | Post-Analysis Lookup |
---|---|---|
skanfordiporka.com | 68.183.10.71 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49290 -> 68.183.10.71:80 | 2032086 | ET MALWARE Win32/IcedID Request Cookie | A Network Trojan was detected |
TCP 192.168.56.101:49283 -> 68.183.10.71:80 | 2032086 | ET MALWARE Win32/IcedID Request Cookie | A Network Trojan was detected |
Suricata TLS
No Suricata TLS
pdb_path | E:\repo\ImageMagick\ImageMagick-6.9.3\vc14\x64\bin\CORE_RL_pango_.pdb |
section | .gfids |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://skanfordiporka.com/ |
request | GET http://skanfordiporka.com/ |
description | rundll32.exe tried to sleep 178 seconds, actually delayed analysis time by 178 seconds |
TrendMicro | TrojanSpy.Win64.ICEDID.SMYXDAVZ |
section | {u'size_of_data': u'0x00006000', u'virtual_address': u'0x0005c000', u'entropy': 6.823978273936543, u'name': u'.rsrc', u'virtual_size': u'0x0000568a'} | entropy | 6.82397827394 | description | A section with a high entropy has been found |
cmdline | "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll77.dll,cango_layout_set_attributes |