Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | March 17, 2023, 7:51 a.m. | March 17, 2023, 7:52 a.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,ANJHrtqPyoZlLN
2560-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,ANJHrtqPyoZlLN
908
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,AdDIJNyjoaSeKitBSSfvfV
2644-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,AdDIJNyjoaSeKitBSSfvfV
2088
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,AiQuYKFP
2736-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,AiQuYKFP
196
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,AjCvWu
2824-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,AjCvWu
2216
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,AveAkeMGsAwFFAhoKdNXhIMFQ
2916-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,AveAkeMGsAwFFAhoKdNXhIMFQ
2628
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,BFNfItOdrItDPYj
3012-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,BFNfItOdrItDPYj
2676
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,BOhuBWDUsCWLiC
940-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,BOhuBWDUsCWLiC
2776
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,BTMFzdgTuyWjiIBHnce
2460-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,BTMFzdgTuyWjiIBHnce
1152
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,CXLyPNN
2612-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,CXLyPNN
1728
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,CoPzTghLuoRCKv
3000-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,CoPzTghLuoRCKv
2444
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,CzSCLOcblUEHZbXguBeBKvOsFr
2516-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,CzSCLOcblUEHZbXguBeBKvOsFr
3004
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,DGWnzoUQDuJFITIs
2860-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,DGWnzoUQDuJFITIs
2556
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,DXFnrcWUukvqM
2168-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,DXFnrcWUukvqM
1120
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,DllRegisterServer
2920-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,DllRegisterServer
3044-
regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\OAgjhKSULIBzUOCv\qeRLOgWoVARWAki.dll"
3560
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,DtuklXMCytMEOfG
2748-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,DtuklXMCytMEOfG
3016
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,DvvFQBN
2924-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,DvvFQBN
2520
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,EEFTMFWzodeDNgkOokBFbPUM
2864-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,EEFTMFWzodeDNgkOokBFbPUM
2852
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,EZkpQfdxRULajOkDrGLHdLD
2784-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,EZkpQfdxRULajOkDrGLHdLD
2112
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,EnFJoeQtlzsJDJiJBmbXoBTpwv
2828-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,EnFJoeQtlzsJDJiJBmbXoBTpwv
2100
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,EsKEcLa
3112-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,EsKEcLa
3240
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,EtgJryXb
3232-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,EtgJryXb
3472
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,EwUPpnOBjfPxH
3364-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,EwUPpnOBjfPxH
3532
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,EztRXmoFVqjMSateN
3464-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,EztRXmoFVqjMSateN
3692
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,FASZSnNRTIVAAaGcgawnKQZyy
3636-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,FASZSnNRTIVAAaGcgawnKQZyy
3848
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,FGFyHfFIUhGbYBAZSYZbyICNUd
3776-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,FGFyHfFIUhGbYBAZSYZbyICNUd
3964
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,FRjkVJXkyiheeOfN
3916-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,FRjkVJXkyiheeOfN
4064
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,FYgbRxuhThTqi
4056-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,FYgbRxuhThTqi
3148
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,FkEiXaMMKAdEpLTECJzhaViXI
3204-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,FkEiXaMMKAdEpLTECJzhaViXI
3356
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,GFnuqsATNhcsPXZHiVOxZST
3432-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,GFnuqsATNhcsPXZHiVOxZST
3676
-
-
explorer.exe C:\Windows\Explorer.EXE
1452 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,GQJmrAwSczpjroAXcGhyqBUdB
3604-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,GQJmrAwSczpjroAXcGhyqBUdB
3792
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,GUBjDl
3804-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,GUBjDl
3640
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,GVoDrZwwflq
3468-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,GVoDrZwwflq
3284
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,GWOPbRQrBekZviftyaAUwXmnh
2716-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,GWOPbRQrBekZviftyaAUwXmnh
3168
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,HIQgMO
2120-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,HIQgMO
3720
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,HUraWDowXZUfxDa
3448-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,HUraWDowXZUfxDa
3948
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,Hjkwbzu
2224 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,IVoyuTGXNLCke
3156 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,IfyOjidHbwvD
3620 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,IxFJaPJQRQSzqlajawLBTzlwKo
3668 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,JOLlxrVluAyNHIhUuvAYwypV
3780 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,JXiDoHIIyrJjEYKuRb
3188 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,JilnPOgZrXMjkwk
3852 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,JqWanxhQqUNu
3836 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,KCYGkqzzvPgjOGshmaWLW
3608 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,KEMrlPvHxelUlZ
2456 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,KMaMkjqMkYYPMAAJPKLOehoPyY
4040 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,KVtfEbpbmPAlXPj
4192 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,KpXiawubnkzsXkEtjJO
4304 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,KydgpVnbUe
4416 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,LZWxaAtECxaSGoAz
4516 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,LxlPnmCsAgDIkxMugK
4636 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,LyTteGzhZhP
4756 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,MEXTEnCNvZXJLhRKiTCyNPih
4860 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,MRJugro
4980 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,MdqrgqIfjHmjoZkNi
5100 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,MgYMlGlGPQTRsI
4172 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,MopbjpmEaxOdYcIcIYZme
4372 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,NFxEbaQrvHYBkgyyc
4540 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,NItPsPAfBOUuIBno
4752 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,NyTYpQnIzVVNhlVibsSjFCZouP
4928 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,OaAXUXHduoOFLxnDhBJwzh
5064 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,OeHfob
3748 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,OsrEfsOyNaoWldUmRfDeFahCz
4376 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,OtMYeClSBjKXnqKKcwvkpdT
4708 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,PTjntzhnCrFsOVRuqb
4848 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,PVEOpmicZObotzmowwdn
5048 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,PYGtAnBuWCkXSFbfJoxh
4360 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,PcZbHHwxtObWwsAZucWAfp
4728 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,PovPoPHy
5008 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\My5PdKnB.dll,QQDxzrvZSfjOUIRPNLzseI
4784
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | _RDATA |
resource name | BPEFHH |
cmdline | C:\Windows\system32\regsvr32.exe "C:\Windows\system32\OAgjhKSULIBzUOCv\qeRLOgWoVARWAki.dll" |
Elastic | malicious (high confidence) |
McAfee | Artemis!6F262E779FC2 |
K7AntiVirus | Trojan ( 0059b58d1 ) |
K7GW | Trojan ( 0059b58d1 ) |
CrowdStrike | win/malicious_confidence_100% (D) |
Symantec | ML.Attribute.HighConfidence |
Cynet | Malicious (score: 100) |
McAfee-GW-Edition | BehavesLike.Win64.Generic.jc |
section | {u'size_of_data': u'0x0002b000', u'virtual_address': u'0x0007a000', u'entropy': 7.83165138668879, u'name': u'.rsrc', u'virtual_size': u'0x0002aee8'} | entropy | 7.83165138669 | description | A section with a high entropy has been found | |||||||||
entropy | 0.266873545384 | description | Overall entropy of this PE file is high |
process | regsvr32.exe |
process | rundll32.exe |
file | C:\Windows\System32\OAgjhKSULIBzUOCv\qeRLOgWoVARWAki.dll:Zone.Identifier |