Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | March 28, 2023, 8:32 a.m. | March 28, 2023, 8:34 a.m. |
-
-
-
WMIC.exe wmic csproduct get uuid
2756
-
-
WMIC.exe wmic os get Caption
2864 -
-
WMIC.exe wmic path win32_VideoController get name
3012
-
-
-
WMIC.exe wmic cpu get name
1404
-
-
-
systeminfo.exe systeminfo
2228
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
212.87.204.93 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | .symtab |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Chrome.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Firefox.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Office\Recent\Templates.LNK |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Chrome.lnk |
cmdline | cmd.exe /c "wmic csproduct get uuid" |
cmdline | cmd /C "wmic cpu get name" |
cmdline | wmic os get Caption |
cmdline | wmic csproduct get uuid |
cmdline | wmic path win32_VideoController get name |
cmdline | cmd /C "wmic path win32_VideoController get name" |
cmdline | wmic cpu get name |
wmi | SELECT UUID FROM Win32_ComputerSystemProduct |
wmi | SELECT Name FROM win32_VideoController |
wmi | SELECT Caption FROM Win32_OperatingSystem |
wmi | SELECT Name FROM WIN32_PROCESSOR |
cmdline | cmd.exe /c "wmic csproduct get uuid" |
cmdline | cmd /C "wmic cpu get name" |
cmdline | cmd "/c " systeminfo |
cmdline | systeminfo |
cmdline | wmic os get Caption |
cmdline | wmic csproduct get uuid |
cmdline | wmic path win32_VideoController get name |
cmdline | cmd /C "wmic path win32_VideoController get name" |
cmdline | wmic cpu get name |
wmi | SELECT Name FROM WIN32_PROCESSOR |
wmi | SELECT UUID FROM Win32_ComputerSystemProduct |
host | 212.87.204.93 |
cmdline | cmd "/c " systeminfo |
Lionic | Trojan.Win32.Convagent.4!c |
MicroWorld-eScan | Gen:Variant.Jaik.127758 |
FireEye | Generic.mg.027a60b4337dd084 |
ALYac | Gen:Variant.Jaik.127758 |
Malwarebytes | Malware.AI.497866992 |
Sangfor | Infostealer.Win32.Agent.Vnzc |
Alibaba | Trojan:JS/TitanStealer.81afce46 |
CrowdStrike | win/malicious_confidence_100% (W) |
Arcabit | Trojan.Jaik.D1F30E |
BitDefenderTheta | AI:Packer.C209DA8B1F |
Cyren | W32/ABRisk.FLVX-7117 |
Symantec | ML.Attribute.HighConfidence |
Elastic | malicious (high confidence) |
ESET-NOD32 | a variant of WinGo/Agent.JS |
Cynet | Malicious (score: 100) |
APEX | Malicious |
Paloalto | generic.ml |
ClamAV | Win.Infostealer.Aurora-9980073-1 |
Kaspersky | Trojan-PSW.Win32.Coins.affj |
BitDefender | Gen:Variant.Jaik.127758 |
ViRobot | Trojan.Win.Z.Jaik.3226890 |
Avast | Win32:Evo-gen [Trj] |
Rising | Stealer.Aurora!1.E1B6 (CLASSIC) |
Emsisoft | Gen:Variant.Jaik.127758 (B) |
VIPRE | Gen:Variant.Jaik.127758 |
TrendMicro | TrojanSpy.Win32.AURORASTEALER.YXDC1Z |
McAfee-GW-Edition | BehavesLike.Win32.Trojan.wh |
Sophos | Troj/Aurora-A |
SentinelOne | Static AI - Suspicious PE |
Webroot | W32.Trojan.Gen |
Avira | TR/Crypt.XPACK.Gen |
MAX | malware (ai score=81) |
Gridinsoft | Malware.Win32.Aurora.bot |
Microsoft | Trojan:Win32/Casdet!rfn |
GData | Gen:Variant.Jaik.127758 |
Detected | |
AhnLab-V3 | Trojan/Win.Generic.C5400367 |
McAfee | Artemis!027A60B4337D |
VBA32 | BScope.Trojan.Nacra |
TrendMicro-HouseCall | TrojanSpy.Win32.AURORASTEALER.YXDC1Z |
Tencent | Win32.Trojan.Crypt.Qgil |
Ikarus | Trojan-Spy.TitanStealer |
MaxSecure | Trojan.Malware.300983.susgen |
Fortinet | W32/GoAgent.IE!tr |
AVG | Win32:Evo-gen [Trj] |
Panda | Trj/Chgt.AD |