Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Sept. 4, 2023, 7:41 a.m. | Sept. 4, 2023, 7:44 a.m. |
-
-
-
regsvr32.exe regsvr32 /s C:\infolive\vfpres.dll
3056 -
regsvr32.exe regsvr32 /s C:\infolive\MSCOMM32.ocx
1152 -
regsvr32.exe regsvr32 /s C:\infolive\msvcr71.dll
1728 -
regsvr32.exe regsvr32 /s C:\infolive\vfp9r.dll
2136 -
regsvr32.exe regsvr32 /s C:\infolive\VFP9RENU.DLL
2184 -
regsvr32.exe regsvr32 /s C:\infolive\vfpcom.dll
2260 -
regsvr32.exe C:\Windows\Syswow64\regsvr32 /s C:\infolive\vfpres.dll
2440 -
regsvr32.exe C:\Windows\Syswow64\regsvr32 /s C:\infolive\MSCOMM32.ocx
2464 -
regsvr32.exe C:\Windows\Syswow64\regsvr32 /s C:\infolive\msvcr71.dll
2636 -
regsvr32.exe C:\Windows\Syswow64\regsvr32 /s C:\infolive\vfp9r.dll
2420 -
regsvr32.exe C:\Windows\Syswow64\regsvr32 /s C:\infolive\VFP9RENU.DLL
2740 -
regsvr32.exe C:\Windows\Syswow64\regsvr32 /s C:\infolive\vfpcom.dll
284 -
regedit.exe regedit.exe /S C:\infolive\patch.reg
2844 -
regedit.exe regedit.exe /S C:\infolive\odbc.reg
2888
-
-
-
explorer.exe C:\Windows\Explorer.EXE
1452
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb |
section | .gfids |
resource name | PNG |
file | C:\infolive\_bms.dll |
file | C:\infolive\Cpuinf32.dll |
file | C:\infolive\vfpres.dll |
file | C:\infolive\updater.bat |
file | C:\infolive\setup.exe |
file | C:\infolive\infolive.exe |
file | C:\infolive\MSCOMM32.OCX |
file | C:\infolive\VBAME.DLL |
file | C:\infolive\vfp9r.dll |
file | C:\infolive\register.bat |
file | C:\infolive\MS64.DLL |
file | C:\infolive\VFP9RENU.DLL |
file | C:\infolive\msvcr71.dll |
file | C:\infolive\aamd532.dll |
file | C:\infolive\download.vbs |
file | C:\infolive\ChangeBetType.exe |
file | C:\infolive\dbxsmtp.dll |
file | C:\infolive\Setup1.msi |
file | C:\infolive\MS32.dll |
file | C:\infolive\vfpcom.dll |
file | C:\infolive\patch.reg |
file | C:\infolive\reg.bat |
file | C:\infolive\ResetAuthenticate.exe |
file | C:\infolive\odbc.reg |
file | C:\infolive\Initialize.exe |
file | C:\Users\test22\Desktop\InfoLive.lnk |
file | C:\infolive\dbximage.dll |
file | C:\infolive\Preferences.exe |
file | C:\infolive\InitializeBets.exe |
file | C:\Users\test22\Desktop\InfoLive.lnk |
cmdline | C:\Windows\Syswow64\regsvr32 /s C:\infolive\vfpres.dll |
cmdline | regsvr32 /s C:\infolive\MSCOMM32.ocx |
cmdline | C:\Windows\Syswow64\regsvr32 /s C:\infolive\MSCOMM32.ocx |
cmdline | regsvr32 /s C:\infolive\vfpres.dll |
cmdline | C:\Windows\Syswow64\regsvr32 /s C:\infolive\vfp9r.dll |
cmdline | C:\Windows\Syswow64\regsvr32 /s C:\infolive\vfpcom.dll |
cmdline | C:\Windows\Syswow64\regsvr32 /s C:\infolive\VFP9RENU.DLL |
cmdline | C:\Windows\Syswow64\regsvr32 /s C:\infolive\msvcr71.dll |
cmdline | regsvr32 /s C:\infolive\VFP9RENU.DLL |
cmdline | regsvr32 /s C:\infolive\vfpcom.dll |
cmdline | regsvr32 /s C:\infolive\msvcr71.dll |
cmdline | regsvr32 /s C:\infolive\vfp9r.dll |
file | C:\infolive\reg.bat |
Sangfor | Trojan.Win32.Agent.Vu07 |
K7AntiVirus | Trojan ( 005506ea1 ) |
K7GW | Trojan ( 005506ea1 ) |
APEX | Malicious |
Avast | Win32:Malware-gen |
Rising | Trojan.Generic@AI.87 (RDML:D2zJSotK4qSgAw/76GZAlg) |
McAfee-GW-Edition | HTool-VBSDldr |
Gridinsoft | Trojan.Win32.Agent.sa |
Zoner | Probably Heur.ExeHeaderP |
SentinelOne | Static AI - Suspicious SFX |
Fortinet | VBS/Agent.ODO!tr |
AVG | Win32:Malware-gen |