Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | April 10, 2023, 9:44 p.m. | April 10, 2023, 9:47 p.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\fcon.dll,DllGetActivationFactory
2732-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\fcon.dll,DllGetActivationFactory
2968
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\fcon.dll,DllGetClassObject
2820-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\fcon.dll,DllGetClassObject
3040
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\fcon.dll,DllCanUnloadNow
2636-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\fcon.dll,DllCanUnloadNow
1336
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\fcon.dll,GetCtacPropertyAlloc
2916-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\fcon.dll,GetCtacPropertyAlloc
2404
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\fcon.dll,ModifyStagingControlVariants
1216-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\fcon.dll,ModifyStagingControlVariants
2476
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\fcon.dll,ModifyStagingControls
1400-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\fcon.dll,ModifyStagingControls
2716
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\fcon.dll,SubscribeFeatureReporting
2420-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\fcon.dll,SubscribeFeatureReporting
2936
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\fcon.dll,UnsubscribeFeatureReporting
2676-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\fcon.dll,UnsubscribeFeatureReporting
2416
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\fcon.dll,
2880
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | fcon.pdb |
section | .didat |
resource name | MUI |
resource name | WEVT_TEMPLATE |