Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | June 22, 2023, 10:05 a.m. | June 22, 2023, 10:10 a.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,??0OrbitSession@orbitdll@mg@@QEAA@XZ
2548-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,??0OrbitSession@orbitdll@mg@@QEAA@XZ
2936
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,??1OrbitSession@orbitdll@mg@@QEAA@XZ
2632-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,??1OrbitSession@orbitdll@mg@@QEAA@XZ
2972
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?CheckUpdate@OrbitSession@orbitdll@mg@@QEAAHXZ
2724-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?CheckUpdate@OrbitSession@orbitdll@mg@@QEAAHXZ
812
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?Close@SavegameReader@orbitdll@mg@@QEAAXXZ
2816-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?Close@SavegameReader@orbitdll@mg@@QEAAXXZ
2068
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?Close@SavegameWriter@orbitdll@mg@@QEAAX_N@Z
2908-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?Close@SavegameWriter@orbitdll@mg@@QEAAX_N@Z
2204
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetLocText@OrbitSession@orbitdll@mg@@QEAAPEBGPEBGPEBD@Z
1120-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetLocText@OrbitSession@orbitdll@mg@@QEAAPEBGPEBGPEBD@Z
2244
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetLoginDetails@OrbitSession@orbitdll@mg@@QEAAXIPEAVIGetLoginDetailsListener@23@@Z
2184-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetLoginDetails@OrbitSession@orbitdll@mg@@QEAAXIPEAVIGetLoginDetailsListener@23@@Z
2664
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetName@SavegameInfo@orbitdll@mg@@QEAAPEBGXZ
2596-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetName@SavegameInfo@orbitdll@mg@@QEAAPEBGXZ
2780
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetNetworkTraffic@OrbitSession@orbitdll@mg@@QEAAXIPEAVIGetNetworkTrafficListener@23@@Z
2892-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetNetworkTraffic@OrbitSession@orbitdll@mg@@QEAAXIPEAVIGetNetworkTrafficListener@23@@Z
196
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetOrbitServer@OrbitSession@orbitdll@mg@@QEAAXIPEAVIGetOrbitServerListener@23@II@Z
2408-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetOrbitServer@OrbitSession@orbitdll@mg@@QEAAXIPEAVIGetOrbitServerListener@23@II@Z
940
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetRequestUniqueId@OrbitSession@orbitdll@mg@@QEAAIXZ
744-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetRequestUniqueId@OrbitSession@orbitdll@mg@@QEAAIXZ
2588
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetSavegameId@SavegameInfo@orbitdll@mg@@QEAAIXZ
884-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetSavegameId@SavegameInfo@orbitdll@mg@@QEAAIXZ
2380
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetSavegameList@OrbitSession@orbitdll@mg@@QEAAXIPEAVIGetSavegameListListener@23@I@Z
1952-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetSavegameList@OrbitSession@orbitdll@mg@@QEAAXIPEAVIGetSavegameListListener@23@I@Z
2872
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetSavegameReader@OrbitSession@orbitdll@mg@@QEAAXIPEAVIGetSavegameReaderListener@23@II@Z
2128-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetSavegameReader@OrbitSession@orbitdll@mg@@QEAAXIPEAVIGetSavegameReaderListener@23@II@Z
3216
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetSavegameWriter@OrbitSession@orbitdll@mg@@QEAAXIPEAVIGetSavegameWriterListener@23@II_N@Z
3456-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetSavegameWriter@OrbitSession@orbitdll@mg@@QEAAXIPEAVIGetSavegameWriterListener@23@II_N@Z
3556
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetSize@SavegameInfo@orbitdll@mg@@QEAAIXZ
3660-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetSize@SavegameInfo@orbitdll@mg@@QEAAIXZ
3808
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetUplayId@SavegameInfo@orbitdll@mg@@QEAAIXZ
3864-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?GetUplayId@SavegameInfo@orbitdll@mg@@QEAAIXZ
3992
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?Read@SavegameReader@orbitdll@mg@@QEAAXIPEAVISavegameReadListener@23@IPEAXI@Z
4052-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?Read@SavegameReader@orbitdll@mg@@QEAAXIPEAVISavegameReadListener@23@IPEAXI@Z
1016
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?RemoveSavegame@OrbitSession@orbitdll@mg@@QEAAXIPEAVIRemoveSavegameListener@23@II@Z
772-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?RemoveSavegame@OrbitSession@orbitdll@mg@@QEAAXIPEAVIRemoveSavegameListener@23@II@Z
3296
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?SetName@SavegameWriter@orbitdll@mg@@QEAA_NPEAG@Z
3412-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?SetName@SavegameWriter@orbitdll@mg@@QEAA_NPEAG@Z
2756
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\3052c15a0e5926da6706d7bc1440d1ad.movpkg.dll,?StartLauncher@OrbitSession@orbitdll@mg@@QEAA_NIIPEBD0@Z
3684
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | D:\JenkinsWorkspace\workspace\client_build_installer\client\build\working_directory\RelWithDebInfo\ubiorbitapi_r264.pdb |
Symantec | Trojan Horse |
McAfee-GW-Edition | Artemis!Trojan |
GData | Trojan.GenericKD.67671411 |
Webroot | W32.Malware.Gen |
Microsoft | Trojan:Win32/Casdet!rfn |
McAfee | Artemis!67B3201085B9 |
Rising | Trojan.Agent!8.B1E (CLOUD) |