Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | April 28, 2023, 5:07 p.m. | April 28, 2023, 5:09 p.m. |
-
-
-
WMIC.exe wmic csproduct get uuid
2744
-
-
WMIC.exe wmic os get Caption
2852 -
-
WMIC.exe wmic path win32_VideoController get name
3012
-
-
-
WMIC.exe wmic cpu get name
800
-
-
-
systeminfo.exe systeminfo
2212
-
-
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Roaming\Microsoft\Windows\Cookies\" \"C:\Users\test22\AppData\Local\Temp\XVlBzgbaiC\""
2608 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cookies\" \"C:\Users\test22\AppData\Local\Temp\MRAjWwhTHc\""
2796 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\tcuAxhxKQFDaFpL\""
2912 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\History\" \"C:\Users\test22\AppData\Local\Temp\SjFbcXoEFf\""
1152 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\RsWxPLDnJObCsNV\""
1400 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data\" \"C:\Users\test22\AppData\Local\Temp\lgTeMaPEZQ\""
2328 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\leQYhYzRyWJjPjz\""
1560 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Web Data\" \"C:\Users\test22\AppData\Local\Temp\pfRFEgmota\""
2848 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\FetHsbZRjxAwnwe\""
2924 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\krBEmfdzdc\""
2856 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\EkXBAkjQZLCtTMt\""
1264 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Microsoft\Windows\History\" \"C:\Users\test22\AppData\Local\Temp\TCoaNatyyi\""
300
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
94.142.138.215 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | .MPRESS1 |
section | .MPRESS2 |
resource name | AFX_DIALOG_LAYOUT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlSoceng.store |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0\_locales\pt_PT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\nl\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.5_0\_locales |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\_locales\is |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\1256\_platform_specific\all\sths\a4b90990b418581487bb13a2cc67700a3c359804f91bdfb8e377cd0ec80ddc10.sth |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\_locales\is\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\_locales\iw |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\_locales\it |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_0\_locales\fil |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.3_0\_locales\de |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\_locales\id |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\_locales\fil |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\_locales\mr\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\topbar_floating_button_close.png |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0\_locales\tr\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0\_locales\id\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\_locales\fr |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0\_locales\fr\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\fil\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\1256\_platform_specific\all\sths\c652a0ec48ceb3fcab170992c43a87413309e80065a26252401ba3362a17c565.sth |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\_locales\ru |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\_locales\fi\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\pnacl\0.57.44.2492\_platform_specific\x86_64\pnacl_public_pnacl_json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\_locales\ro |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.ldb |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\zh_TW |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\ms |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.5_0\_locales\es_419\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\1256\_platform_specific\all\sths |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\_locales\ko |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\_locales\kn |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\_locales\km |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.3_0\_locales\el\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOCK |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.3_0\_locales\ja |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0\_locales\ar |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\_locales\ka |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\_locales\tr\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOCK |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.3_0\_locales\fil |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\no |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\_locales\it\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\_locales\ro\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.5_0\_locales\ca |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.5_0\_locales\tr\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.5_0\_locales\cs |
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00814f64 | size | 0x00000002 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00816a7c | size | 0x00000134 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081c9d0 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081c9d0 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081c9d0 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081c9d0 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081c9d0 | size | 0x00000144 | ||||||||||||||||||
name | RT_MENU | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081cb14 | size | 0x00000042 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081d0e8 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081d0e8 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081d0e8 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081d0e8 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081d0e8 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081d0e8 | size | 0x00000034 | ||||||||||||||||||
name | RT_STRING | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081e048 | size | 0x00000294 | ||||||||||||||||||
name | RT_STRING | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081e048 | size | 0x00000294 | ||||||||||||||||||
name | RT_STRING | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081e048 | size | 0x00000294 | ||||||||||||||||||
name | RT_STRING | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081e048 | size | 0x00000294 | ||||||||||||||||||
name | RT_STRING | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081e048 | size | 0x00000294 | ||||||||||||||||||
name | RT_STRING | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081e048 | size | 0x00000294 | ||||||||||||||||||
name | RT_STRING | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081e048 | size | 0x00000294 | ||||||||||||||||||
name | RT_STRING | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081e048 | size | 0x00000294 | ||||||||||||||||||
name | RT_STRING | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081e048 | size | 0x00000294 | ||||||||||||||||||
name | RT_STRING | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081e048 | size | 0x00000294 | ||||||||||||||||||
name | RT_STRING | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0081e048 | size | 0x00000294 |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\open1.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\agent.pyw.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\office_2007.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Office\Recent\Templates.LNK |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\open.PNG.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\SendTo\EditPlus.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\테스트.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click.py.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox Guest Additions\Website.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\sn.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\util.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\Settings.ini.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\agent.pyw - 바로 가기.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Chrome.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\한글2010(정품).lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\Office.2010.Toolkit.and.EZ-Activator.v2.1.5.Final.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\agent.py.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk |
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\readme.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\시리얼넘버.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\age.pyw.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click.pyw.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\Python27.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\한글2010(정품) (2).lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\시작프로그램.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\다운로드.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\1234.zip.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\exit.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Firefox.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Chrome.lnk |
cmdline | cmd.exe /c "wmic csproduct get uuid" |
cmdline | cmd /C "wmic cpu get name" |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\FetHsbZRjxAwnwe\"" |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data\" \"C:\Users\test22\AppData\Local\Temp\lgTeMaPEZQ\"" |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Roaming\Microsoft\Windows\Cookies\" \"C:\Users\test22\AppData\Local\Temp\XVlBzgbaiC\"" |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Microsoft\Windows\History\" \"C:\Users\test22\AppData\Local\Temp\TCoaNatyyi\"" |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\History\" \"C:\Users\test22\AppData\Local\Temp\SjFbcXoEFf\"" |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\RsWxPLDnJObCsNV\"" |
cmdline | wmic os get Caption |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Web Data\" \"C:\Users\test22\AppData\Local\Temp\pfRFEgmota\"" |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\tcuAxhxKQFDaFpL\"" |
cmdline | wmic csproduct get uuid |
cmdline | wmic path win32_VideoController get name |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cookies\" \"C:\Users\test22\AppData\Local\Temp\MRAjWwhTHc\"" |
cmdline | cmd /C "wmic path win32_VideoController get name" |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\krBEmfdzdc\"" |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\leQYhYzRyWJjPjz\"" |
cmdline | wmic cpu get name |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\EkXBAkjQZLCtTMt\"" |
wmi | SELECT UUID FROM Win32_ComputerSystemProduct |
wmi | SELECT Name FROM win32_VideoController |
wmi | SELECT Caption FROM Win32_OperatingSystem |
wmi | SELECT Name FROM WIN32_PROCESSOR |
section | {u'size_of_data': u'0x00302a00', u'virtual_address': u'0x00001000', u'entropy': 7.999944478445648, u'name': u'.MPRESS1', u'virtual_size': u'0x0081e000'} | entropy | 7.99994447845 | description | A section with a high entropy has been found | |||||||||
entropy | 0.99725008088 | description | Overall entropy of this PE file is high |
process | system |
cmdline | cmd.exe /c "wmic csproduct get uuid" |
cmdline | cmd /C "wmic cpu get name" |
cmdline | cmd "/c " systeminfo |
cmdline | wmic os get Caption |
cmdline | systeminfo |
cmdline | wmic csproduct get uuid |
cmdline | wmic path win32_VideoController get name |
cmdline | cmd /C "wmic path win32_VideoController get name" |
cmdline | wmic cpu get name |
wmi | SELECT Name FROM WIN32_PROCESSOR |
wmi | SELECT UUID FROM Win32_ComputerSystemProduct |
host | 94.142.138.215 |
file | C:\Users\test22\AppData\Local\Temp\SandboxieInstall.exe |
registry | HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion |
registry | HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\VideoBiosVersion |
file | C:\Users\test22\AppData\Roaming\Electrum\wallets |
count | 1779 | name | heapspray | process | powershell.exe | total_mb | 111 | length | 65536 | protection | PAGE_READWRITE |
file | C:\Users\test22\AppData\Roaming\Exodus\exodus.wallet |
file | C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\parent.lock |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |
cmdline | cmd "/c " systeminfo |
Lionic | Trojan.Win32.Generic.4!c |
tehtris | Generic.Malware |
MicroWorld-eScan | Trojan.GenericKD.66661667 |
FireEye | Generic.mg.4b32941cd92e048e |
McAfee | Artemis!4B32941CD92E |
Cylance | unsafe |
Sangfor | Infostealer.Win32.Coins.Vmii |
K7AntiVirus | Trojan ( 00593ee01 ) |
Alibaba | TrojanPSW:Win32/Coins.6cac7513 |
K7GW | Trojan ( 00593ee01 ) |
CrowdStrike | win/malicious_confidence_60% (W) |
Cyren | W32/ABRisk.RUMD-4075 |
Symantec | ML.Attribute.HighConfidence |
Elastic | malicious (moderate confidence) |
ESET-NOD32 | a variant of Win32/Packed.Themida.IDS |
Cynet | Malicious (score: 99) |
APEX | Malicious |
Paloalto | generic.ml |
Kaspersky | Trojan-PSW.Win32.Coins.afke |
BitDefender | Trojan.GenericKD.66661667 |
Avast | Win32:Evo-gen [Trj] |
Rising | Stealer.Coins!8.133E9 (CLOUD) |
Sophos | Mal/Generic-S |
F-Secure | Trojan.TR/PSW.Coins.zbqnj |
VIPRE | Trojan.GenericKD.66661667 |
TrendMicro | TrojanSpy.Win32.AURORASTEALER.YXDDZZ |
McAfee-GW-Edition | Artemis!Trojan |
Trapmine | malicious.high.ml.score |
Emsisoft | Trojan.GenericKD.66661667 (B) |
Avira | TR/PSW.Coins.zbqnj |
Antiy-AVL | Trojan[Packed]/Win32.Themida |
Microsoft | Trojan:Win32/Sabsik.FL.B!ml |
Gridinsoft | Malware.Win32.Aurora.bot |
Arcabit | Trojan.Generic.D3F92D23 |
ZoneAlarm | Trojan-PSW.Win32.Coins.afke |
GData | Trojan.GenericKD.66661667 |
Detected | |
BitDefenderTheta | Gen:NN.ZexaF.36164.cpwaauQAXYgO |
ALYac | Trojan.GenericKD.66661667 |
MAX | malware (ai score=83) |
Malwarebytes | Trojan.Packed.MPRESS |
Panda | Trj/Chgt.AD |
Zoner | Trojan.Win32.133812 |
TrendMicro-HouseCall | TrojanSpy.Win32.AURORASTEALER.YXDDZZ |
Tencent | Win32.Trojan-QQPass.QQRob.Dflw |
SentinelOne | Static AI - Suspicious PE |
MaxSecure | Trojan.Malware.300983.susgen |
Fortinet | W32/PossibleThreat |
AVG | Win32:Evo-gen [Trj] |
DeepInstinct | MALICIOUS |