Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | June 7, 2023, 10:25 a.m. | June 7, 2023, 10:26 a.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,l_cmsComputeInterpParams@24
3020 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,l_cmsFreeInterpParams@4
1184 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,l_cmsGetFormatter@16
2384 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,l_cmsFloat2Half@4
612 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,l_cmsHalf2Float@4
1192 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,l_cmsQuantizeVal@12
1704 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,l_cmsReadDevicelinkLUT@8
2556 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,l_cmsReadInputLUT@8
2496 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,l_cmsReadOutputLUT@8
2916 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,l_cmsStageAllocIdentityCLut@8
2204 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,l_cmsStageAllocIdentityCurves@8
2220 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,l_cmsStageAllocLab2XYZ@4
1604 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,l_cmsStageAllocLabV2ToV4@4
2684 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,l_cmsStageAllocLabV4ToV2@4
2116 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,l_cmsStageAllocNamedColor@8
2376 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,l_cmsStageAllocXYZ2Lab@4
2388 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcms15Fixed16toDouble
2724 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcms8Fixed8toDouble
2380 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsAdjustEndianess16
904 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsAdjustEndianess32
1884 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsAdjustEndianess64
2768 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsCalloc
2368 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsCreateMutex
2172 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsDecodeDateTimeNumber
2408 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsDefaultICCintents
3036 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsDestroyMutex
3084 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsDoTransformLineStride@36
3192 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsDoubleTo15Fixed16
3304 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsDoubleTo8Fixed8
3452 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsDupMem
3548 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsEncodeDateTimeNumber
3640 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsFree
3732 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsGetTransformFormatters16
3840 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsGetTransformFormattersFloat
3940 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsGetTransformUserData
4056 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsICCcolorSpace
3204 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsIOPrintf
3424 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsLCMScolorSpace
3576 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsLockMutex
3692 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsMAT3eval
3644 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsMAT3identity
4076 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsMAT3inverse
3296 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsMAT3isIdentity
3536 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsMAT3per
3824 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsMAT3solve
3116 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsMalloc
3528 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsMallocZero
3784 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsOpenProfileFromIOhandler2THR@12
3464 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsPipelineSetOptimizationParameters
3208 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsRead15Fixed16Number
3816 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsReadAlignment
3260 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsReadFloat32Number
4100 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsReadTypeBase
4216 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsReadUInt16Array
4628 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsReadUInt16Number
4748 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsReadUInt32Number
4844 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsReadUInt64Number
4944 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsReadUInt8Number
5096 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsReadXYZNumber
4240 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsRealloc
4668 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsSetTransformUserData
4828 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsStageAllocPlaceholder
5012 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsUnlockMutex
4260 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsVEC3cross
4832 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsVEC3distance
4472 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsVEC3dot
3044 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsVEC3init
3684 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsVEC3length
4176 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsVEC3minus
4864 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsWrite15Fixed16Number
4592 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\batteryacid.dat.dll,lcmsWriteAlignment
5188
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | c:\Documents and Settings\Andrew\Desktop\lcms\lcms2-2.9\bin\lcms2.pdb |
section | {u'size_of_data': u'0x0001b000', u'virtual_address': u'0x0005d000', u'entropy': 7.904860604753047, u'name': u'.rsrc', u'virtual_size': u'0x0001a53f'} | entropy | 7.90486060475 | description | A section with a high entropy has been found | |||||||||
entropy | 0.227848101266 | description | Overall entropy of this PE file is high |
Elastic | malicious (high confidence) |
CrowdStrike | win/malicious_confidence_70% (D) |
Symantec | W32.Qakbot!g51 |
Kaspersky | HEUR:Trojan-Banker.Win32.Qbot.gen |
TrendMicro | TrojanSpy.Win32.QAKBOT.YXDFGZ |
McAfee-GW-Edition | BehavesLike.Win32.Trojan.gc |
Sophos | Mal/Generic-S |
Gridinsoft | Trojan.Win32.Qakbot.bot |
McAfee | Artemis!179D4849F8D0 |
Rising | Trojan.Qbot!8.8A3 (CLOUD) |