Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | June 23, 2023, 9:17 a.m. | June 23, 2023, 9:19 a.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rcrypto_generichash_blake2b_pick_best_implementation
2096-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rcrypto_generichash_blake2b_pick_best_implementation
2300
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rcrypto_onetimeauth_poly1305_pick_best_implementation
2180-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rcrypto_onetimeauth_poly1305_pick_best_implementation
2500
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rBKDF2_SHA256
1208-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rBKDF2_SHA256
2372
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rcrypto_pwhash_argon2_pick_best_implementation
2332-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rcrypto_pwhash_argon2_pick_best_implementation
2624
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rcrypto_scalarmult_curve25519_pick_best_implementation
2480-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rcrypto_scalarmult_curve25519_pick_best_implementation
2736
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rcrypto_sign_ed25519_detached
2612-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rcrypto_sign_ed25519_detached
2796
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rcrypto_sign_ed25519_ref10_hinit
2820-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rcrypto_sign_ed25519_ref10_hinit
2976
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rcrypto_sign_ed25519_verify_detached
2944-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rcrypto_sign_ed25519_verify_detached
2164
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rcrypto_stream_chacha20_pick_best_implementation
2080-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rcrypto_stream_chacha20_pick_best_implementation
2572
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rcrypto_stream_salsa20_pick_best_implementation
2440-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rcrypto_stream_salsa20_pick_best_implementation
2828
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rsodium_alloc_init
2816-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rsodium_alloc_init
2084
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rsodium_crit_init
2860-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rsodium_crit_init
2676
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rsodium_runtime_get_cpu_features
2216-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rsodium_runtime_get_cpu_features
2880
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rlloc_region
2512-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rlloc_region
3032
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2_ctx
2552-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2_ctx
2980
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2_hash
2496-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2_hash
2304
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2_pick_best_implementation
2152-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2_pick_best_implementation
2184
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2_verify
2560-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2_verify
2128
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2i_hash_encoded
2144-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2i_hash_encoded
3164
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2i_hash_raw
3156-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2i_hash_raw
3364
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2i_verify
3316-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2i_verify
3504
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2id_hash_encoded
3452-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2id_hash_encoded
3616
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2id_hash_raw
3640-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2id_hash_raw
3800
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2id_verify
3752-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrgon2id_verify
4012
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rlake2b_compress_avx2
3892-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rlake2b_compress_avx2
2716
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rlake2b_compress_ref
4020-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rlake2b_compress_ref
3196
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rlake2b_compress_sse41
3188-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rlake2b_compress_sse41
3528
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rlake2b_compress_ssse3
3448-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rlake2b_compress_ssse3
3696
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rlake2b_long
3544-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rlake2b_long
4088
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_abytes
3976-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_abytes
3276
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_beforenm
3216-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_beforenm
3684
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_decrypt
3348-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_decrypt
3200
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_decrypt_afternm
4072-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_decrypt_afternm
3968
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_decrypt_detached
3356-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_decrypt_detached
3660
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_decrypt_detached_afternm
3224-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_decrypt_detached_afternm
3588
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_encrypt
3928-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_encrypt
4224
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_encrypt_afternm
4100-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_encrypt_afternm
4392
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_encrypt_detached
4256-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_encrypt_detached
4480
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_encrypt_detached_afternm
4384-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_encrypt_detached_afternm
4576
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_is_available
4636-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_is_available
4968
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_keybytes
4784-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_keybytes
5044
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_keygen
4920-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_keygen
4192
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_messagebytes_max
4124-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_messagebytes_max
4492
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_npubbytes
4360-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_npubbytes
4740
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_nsecbytes
4528-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_nsecbytes
5064
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_statebytes
5012-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_aes256gcm_statebytes
4928
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_abytes
4188-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_abytes
4476
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_decrypt
4408-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_decrypt
4332
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_decrypt_detached
5080-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_decrypt_detached
4152
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_encrypt
4888-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_encrypt
4664
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_encrypt_detached
4728-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_encrypt_detached
5040
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_abytes
4984-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_abytes
5184
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_decrypt
5128-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_decrypt
5300
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_decrypt_detached
5364-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_decrypt_detached
5600
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_encrypt
5544-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_encrypt
5844
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_encrypt_detached
5700-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_encrypt_detached
5988
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_keybytes
5836-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_keybytes
6096
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_keygen
5972-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_keygen
5268
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_messagebytes_max
5168-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_messagebytes_max
5668
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_npubbytes
5620-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_npubbytes
4172
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_nsecbytes
5884-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_ietf_nsecbytes
5320
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_keybytes
6044-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_keybytes
5748
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_keygen
5632-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_keygen
5612
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_messagebytes_max
5976-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_messagebytes_max
5332
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_npubbytes
5928-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_npubbytes
5932
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_nsecbytes
5920-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_chacha20poly1305_nsecbytes
5820
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_xchacha20poly1305_ietf_abytes
6128-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_xchacha20poly1305_ietf_abytes
5584
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_xchacha20poly1305_ietf_decrypt
4932-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_xchacha20poly1305_ietf_decrypt
6192
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_xchacha20poly1305_ietf_decrypt_detached
6060 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_xchacha20poly1305_ietf_encrypt
5948 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\lim.php.dll,rrypto_aead_xchacha20poly1305_ietf_encrypt_detached
6292
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | {u'size_of_data': u'0x0000a400', u'virtual_address': u'0x00039000', u'entropy': 7.002053932465696, u'name': u'.rdata', u'virtual_size': u'0x0000a2a0'} | entropy | 7.00205393247 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00005000', u'virtual_address': u'0x00052000', u'entropy': 7.607727850907664, u'name': u'.reloc', u'virtual_size': u'0x0000493b'} | entropy | 7.60772785091 | description | A section with a high entropy has been found |