Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | July 8, 2023, 1:59 p.m. | July 8, 2023, 2:12 p.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\new64x.dll,rundll
2548-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\new64x.dll,rundll
2688
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\new64x.dll,
2632
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | .KaR |
section | .56K |
section | .rn} |
resource name | AVI |
resource name | FILE |
resource name | PNG |
resource name | SHADER |
CrowdStrike | win/malicious_confidence_100% (W) |
Elastic | malicious (high confidence) |
ESET-NOD32 | a variant of Win64/Coroxy.C.gen |
Cynet | Malicious (score: 100) |
DeepInstinct | MALICIOUS |
section | {u'size_of_data': u'0x0036a800', u'virtual_address': u'0x00179000', u'entropy': 7.794869650281678, u'name': u'.rn}', u'virtual_size': u'0x0036a6b8'} | entropy | 7.79486965028 | description | A section with a high entropy has been found | |||||||||
entropy | 0.998572652013 | description | Overall entropy of this PE file is high |
host | 172.67.75.172 | |||
host | 5.42.65.67 |