Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Dec. 15, 2023, 3:04 p.m. | Dec. 15, 2023, 3:14 p.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpAllocMemory
2060 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpAddDynamicSignatureFile
516 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpAmsiCloseSession
2152 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpAmsiNotify
2244 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpAmsiScan
2336 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpAsrSetHipsUserExclusion
2444 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpChangeCapability
2548 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpCheckAccessForClipboardOperation
2640 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpCheckAccessForClipboardOperationEx
2764 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpCheckAccessForClipboardOperationEx2
2864 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpCheckAccessForDragDropOperation
2956 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpCheckAccessForDragDropOperation2
3056 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpCheckAccessForPrintOperation
2192 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpCheckAccessForPrintOperation2
2324 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpCleanControl
2456 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpCleanOpen
2560 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpCleanPrecheckStart
2708 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpCleanStart
2848 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpClientUtilExportFunctions
3000 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpClose
3048 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConfigClose
2260 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConfigDelValue
2428 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConfigGetValue
2580 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConfigGetValueAlloc
2788 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConfigInitialize
2936 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConfigIteratorClose
2704 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConfigIteratorEnum
2356 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConfigIteratorEnumV2
2340 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConfigIteratorOpen
108 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConfigOpen
2320 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConfigQueryProtection
2228 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConfigRefresh
2352 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConfigRegisterForNotifications
2644 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConfigSetValue
3044 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConfigUninitialize
2400 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConfigUnregisterNotifications
2904 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConveyDlpBypass
2944 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConveySampleSubmissionResult
2852 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConveyUserChoiceForDlpNotification
2624 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConveyUserChoiceForDlpNotificationEx
2816 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpConveyUserChoiceForSampleList
2692 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpCreateComInstance
932 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDbgAllocMemory
2588 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDebugExportFunctions
3132 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDefenderIsPrintAccessCheckNeeded
3228 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDefenderPrintAccessCheck
3324 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDefenderPrintDataProvide
3420 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDelegateCopyFile
3516 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDeleteAsrHistory
3612 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDetectionEnumerate
3708 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDetectionQuery
3800 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDeviceControlAuthenticateNetworkShare
3900 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDeviceControlValidateDataDuplicationRemoteLocationConfiguration
3996 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDlpCheckAccessForBuffer
4084 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDlpDelegateEnforcement
3168 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDlpGetEvidenceFileUrl
3300 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDlpGetOperationEnforcmentMode
3452 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDlpInitializeEnforcementMode
3328 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDlpNotifyCloseDocumentFile
3700 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDlpNotifyPostOpenDocumentFile
3820 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDlpNotifyPostSaveAsDocument
3856 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDlpNotifyPostStartPrint
3084 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDlpNotifyPreOpenDocumentFile
3212 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDlpNotifyPrePrint
3368 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDlpNotifyPreSaveAsDocument
3548 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDynamicSignatureEnumerate
3744 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpDynamicSignatureOpen
3712 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpElevateCleanHandle
4076 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpElevationHandleAcquire
4000 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Mpclient.dll,MpElevationHandleActivate
3496
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | D:\ä¸æ¹ Visual Studio 2022\Mpclient\Release\Mpclient.pdb |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Gen:Variant.Jaik.101379 |
Sangfor | Trojan.Win32.Rozena.Vdxq |
Symantec | Trojan.Gen.MBT |
ESET-NOD32 | Win32/Rozena.BUF |
Kaspersky | UDS:DangerousObject.Multi.Generic |
BitDefender | Gen:Variant.Jaik.101379 |
Avast | FileRepMalware [Misc] |
Emsisoft | Gen:Variant.Jaik.101379 (B) |
Ikarus | Win32.Outbreak |
Antiy-AVL | Trojan/Win32.Rozena |
Microsoft | Trojan:Win32/Malgent!MSR |
ZoneAlarm | UDS:DangerousObject.Multi.Generic |
GData | Gen:Variant.Jaik.101379 |
Detected | |
VBA32 | SigCompromised.MEDIATEKINC |
MAX | malware (ai score=83) |
Cylance | unsafe |
TrendMicro-HouseCall | TROJ_GEN.R014H0DLE23 |
Rising | Trojan.Rozena!8.6D (TFE:5:H0Bz8OO6O3T) |
AVG | FileRepMalware [Misc] |
DeepInstinct | MALICIOUS |