Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | March 17, 2023, 7:56 a.m. | March 17, 2023, 7:56 a.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFAccessTagMethods
1932-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFAccessTagMethods
2468
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCIELabToXYZ
2236-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCIELabToXYZ
2520
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCIELabToRGBInit
2144-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCIELabToRGBInit
2604
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCheckTile
2324-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCheckTile
2648
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCheckpointDirectory
2424-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCheckpointDirectory
2776
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCleanup
2596-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCleanup
2916
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFClientOpen
2800-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFClientOpen
2092
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFClientdata
2952-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFClientdata
2464
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFComputeStrip
2268-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFComputeStrip
2760
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFClose
2072-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFClose
2908
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFComputeTile
2444-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFComputeTile
3040
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCreateCustomDirectory
2980-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCreateCustomDirectory
804
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCreateDirectory
2344-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCreateDirectory
1648
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCreateEXIFDirectory
2936-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCreateEXIFDirectory
1952
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCurrentDirOffset
2740-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCurrentDirOffset
2380
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCurrentDirectory
2824-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCurrentDirectory
3224
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCurrentRow
3132-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCurrentRow
3396
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCurrentStrip
3272-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCurrentStrip
3716
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCurrentTile
3380-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFCurrentTile
3780
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFDataWidth
3508-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFDataWidth
3928
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFDefaultStripSize
3604-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFDefaultStripSize
3868
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFDefaultTileSize
3692-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFDefaultTileSize
4004
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFError
3892-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFError
3252
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFErrorExt
2788-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFErrorExt
3408
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFdOpen
3376-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFdOpen
3808
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFieldDataType
3600-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFieldDataType
4000
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFieldName
3880-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFieldName
3524
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFieldPassCount
3724-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFieldPassCount
3836
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFieldReadCount
3392-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFieldReadCount
4076
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFieldTag
3768-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFieldTag
4036
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFieldWithName
3568-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFieldWithName
3076
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFieldWithTag
3344-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFieldWithTag
3800
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFieldWriteCount
3708-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFieldWriteCount
4104
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFileName
3744-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFileName
3528
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFileno
3324-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFileno
4316
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFindCODEC
4244-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFindCODEC
4460
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFindField
4408-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFindField
4668
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFlush
4580-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFlush
4700
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFlushData
4772-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFlushData
4924
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFreeDirectory
4868-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFFreeDirectory
4476
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetBitRevTable
4996-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetBitRevTable
4280
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetClientInfo
5096-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetClientInfo
3980
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetConfiguredCODECs
4108-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetConfiguredCODECs
4296
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetCloseProc
4240-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetCloseProc
5020
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetField
4716-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetField
4168
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetFieldDefaulted
4984-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetFieldDefaulted
4572
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetMapFileProc
4348-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetMapFileProc
4232
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetMode
4764-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetMode
4440
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetReadProc
5012-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetReadProc
4552
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetSizeProc
4320-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetSizeProc
4696
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetTagListCount
4516-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetTagListCount
4464
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetSeekProc
4560-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetSeekProc
5080
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetTagListEntry
4680-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetTagListEntry
4196
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetUnmapFileProc
2056-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetUnmapFileProc
5132
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetVersion
4756-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetVersion
5296
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFIsBigEndian
5208-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFIsBigEndian
5616
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetWriteProc
2060-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFGetWriteProc
5572
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFIsByteSwapped
5320-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFIsByteSwapped
5752
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFIsCODECConfigured
5448-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFIsCODECConfigured
5848
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFIsMSB2LSB
5536-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFIsMSB2LSB
5928
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFIsTiled
5724-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFIsTiled
5468
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFIsUpSampled
5896-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFIsUpSampled
5036
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFLastDirectory
6052-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFLastDirectory
1440
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFMergeFieldInfo
4928-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFMergeFieldInfo
5596
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFNumberOfDirectories
4288-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFNumberOfDirectories
5880
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFNumberOfTiles
5816 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFNumberOfStrips
5436-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFNumberOfStrips
4392
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFOpen
5968 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFOpenW
6140 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\loader_p1_dll_64_n1_x64_inf.dll35.dll,cIFFRGBAImageBegin
5872
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | E:\repo\ImageMagick\ImageMagick-6.9.3\vc14\x64\bin\CORE_RL_tiff_.pdb |
section | .gfids |
CrowdStrike | win/malicious_confidence_100% (W) |
Kaspersky | UDS:DangerousObject.Multi.Generic |
TrendMicro | TrojanSpy.Win64.ICEDID.SMYXDAVZ |
ZoneAlarm | UDS:DangerousObject.Multi.Generic |
Rising | Trojan.IcedID!8.102AF (CLOUD) |
section | {u'size_of_data': u'0x00006000', u'virtual_address': u'0x00069000', u'entropy': 6.888250429789257, u'name': u'.rsrc', u'virtual_size': u'0x0000573b'} | entropy | 6.88825042979 | description | A section with a high entropy has been found |