Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Aug. 4, 2023, 8:55 a.m. | Aug. 4, 2023, 8:57 a.m. |
-
-
cmd.exe "C:\Windows\system32\cmd" /c "C:\Users\test22\AppData\Local\Temp\F00D.tmp\F01D.tmp\F01E.bat C:\Users\test22\AppData\Local\Temp\utilsx.exe"
2624
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | .code |
file | C:\Users\test22\AppData\Local\Temp\utilsxupdater.exe |
file | C:\Users\test22\AppData\Local\Temp\F00D.tmp\F01D.tmp\F01E.bat |
section | {u'size_of_data': u'0x00000e00', u'virtual_address': u'0x00022000', u'entropy': 7.154669031660471, u'name': u'.rsrc', u'virtual_size': u'0x00000c0c'} | entropy | 7.15466903166 | description | A section with a high entropy has been found |
cmdline | "C:\Windows\system32\cmd" /c "C:\Users\test22\AppData\Local\Temp\F00D.tmp\F01D.tmp\F01E.bat C:\Users\test22\AppData\Local\Temp\utilsx.exe" |
file | C:\Users\test22\AppData\Local\Temp\F00D.tmp |
file | C:\Users\test22\AppData\Local\Temp\F00D.tmp\F01D.tmp |
Bkav | W32.Common.FFE247B3 |
tehtris | Generic.Malware |
MicroWorld-eScan | Trojan.GenericKD.68501123 |
FireEye | Generic.mg.413157ad1210bff4 |
Cylance | unsafe |
Sangfor | Trojan.Win32.Save.a |
Cybereason | malicious.dd1f9c |
Arcabit | Trojan.Generic.D4153E83 |
Cyren | W64/Boxter.A.gen!Eldorado |
Elastic | malicious (high confidence) |
Cynet | Malicious (score: 100) |
APEX | Malicious |
BitDefender | Trojan.GenericKD.68501123 |
TACHYON | Trojan/W64.Agent.126976.B |
Emsisoft | Trojan.GenericKD.68501123 (B) |
McAfee-GW-Edition | BehavesLike.Win64.RealProtect.ch |
Trapmine | suspicious.low.ml.score |
Sophos | Mal/Generic-S |
SentinelOne | Static AI - Suspicious PE |
Webroot | Pua.Gen |
Microsoft | Trojan:Win32/Casdet!rfn |
GData | Trojan.GenericKD.68501123 |
Detected | |
McAfee | Artemis!413157AD1210 |
MAX | malware (ai score=84) |
Malwarebytes | Generic.Malware.AI.DDS |
MaxSecure | Trojan.Malware.300983.susgen |
Fortinet | W32/PossibleThreat |
DeepInstinct | MALICIOUS |