Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Feb. 15, 2024, 7:55 a.m. | Feb. 15, 2024, 7:58 a.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,CIrNTzBaPkppGNf
1460 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,FxJWXdx
2188 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,CZnIUAAeJ
2100 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,GbmgwMEzKpXc
2280 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,HipXGmygXapBRYfa
2388 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,IYfRriwGvbgbXBXReH
2476 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,LKSMdMaTT
2568 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,NpZatICsK
2664 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,SOdCGqnNtDWyDo
2768 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,UAyCqwHRBMHCdHlVz
2860 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,ZfDMgndWxjR
2972 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,iBZHcoeoarRd
1188 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,jERKotJBwfw
2208 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,nkYPRlgSTnlUkuDTW
2360 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,rtVNQhSpgienExR
2496 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,start
2632-
powershell.exe "C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath
2368
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,uMRRtkuQVecTfq
2712 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,ukniOqaVKgeX
2856 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,yVmJFl
2992 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,
2072
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\MachineGuid |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\DigitalProductId |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\DigitalProductId |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallDate |
pdb_path | E:\cpp\git7\dll\WndResizerApp.pdb |
file | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
file | C:\Program Files\Mozilla FireFox\firefox.exe |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome\NoModify |
resource name | PNG |
resource name | STYLE_XML |
resource name | None |
description | rundll32.exe tried to sleep 550 seconds, actually delayed analysis time by 550 seconds |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db-journal |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG.old |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Preferences |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOCK |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG.old |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000100 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOCK |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\000005.ldb |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\index-dir\the-real-index |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\MANIFEST-000001 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\000003.log |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOCK |
file | C:\Users\test22\AppData\Roaming\Opera\wand.dat |
file | C:\Users\test22\AppData\Local\Programs\Opera\ |
file | C:\Users\test22\AppData\Local\Yandex\YandexBrowser\Application\browser.exe |
registry | HKEY_CURRENT_USER\Software\Opera Software |
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Add-MpPreference -ExclusionPath |
cmdline | "C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath |
wmi | SELECT * FROM Win32_NetworkAdapter |
wmi | SELECT * FROM Win32_OperatingSystem |
wmi | SELECT * FROM Win32_ComputerSystem |
Skyhigh | BehavesLike.Win32.Dropper.wc |
ESET-NOD32 | a variant of Win32/GenKryptik.GTWG |
McAfee | Artemis!6C072BE39ED9 |
Kaspersky | UDS:Trojan-Banker.Win32.Danabot |
Trapmine | suspicious.low.ml.score |
Microsoft | Program:Win32/Wacapew.C!ml |
section | {u'size_of_data': u'0x0097d800', u'virtual_address': u'0x00001000', u'entropy': 7.742600573834696, u'name': u'.text', u'virtual_size': u'0x0097d68a'} | entropy | 7.74260057383 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00166400', u'virtual_address': u'0x009dc000', u'entropy': 7.564019726941489, u'name': u'.rsrc', u'virtual_size': u'0x00166230'} | entropy | 7.56401972694 | description | A section with a high entropy has been found | |||||||||
entropy | 0.957825115959 | description | Overall entropy of this PE file is high |
wmi | SELECT * FROM Win32_ComputerSystem |
host | 195.133.88.98 | |||
host | 62.173.146.41 | |||
host | 91.201.67.85 |
file | C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe |
file | C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe |
file | C:\Users\test22\AppData\Local\AVAST Software\Browser\Application\AvastBrowser.exe |
registry | HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString |
registry | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnonBadCertRecving |
registry | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnHTTPSToHTTPRedirect |
file | C:\ProgramData\FlashFXP\4\History.dat |
file | C:\Users\test22\AppData\Local\FlashFXP\4\Quick.dat |
file | C:\Users\test22\AppData\Roaming\FlashFXP\4\Quick.dat |
file | C:\Users\test22\AppData\Roaming\FlashFXP\4\History.dat |
file | C:\Users\test22\AppData\Roaming\FlashFXP\3\Sites.dat |
file | C:\ProgramData\FlashFXP\4\Quick.dat |
file | C:\Users\test22\AppData\Local\FlashFXP\4\History.dat |
file | C:\Users\test22\AppData\Roaming\FlashFXP\3\History.dat |
file | C:\Users\test22\AppData\Roaming\FlashFXP\3\Quick.dat |
file | C:\ProgramData\FlashFXP\3\Sites.dat |
file | C:\ProgramData\FlashFXP\3\History.dat |
file | C:\ProgramData\FlashFXP\4\Sites.dat |
file | C:\Users\test22\AppData\Roaming\FlashFXP\4\Sites.dat |
file | C:\Users\test22\AppData\Local\FlashFXP\3\Quick.dat |
file | C:\Users\test22\AppData\Local\FlashFXP\3\History.dat |
file | C:\Users\test22\AppData\Local\FlashFXP\3\Sites.dat |
file | C:\Users\test22\AppData\Local\FlashFXP\4\Sites.dat |
file | C:\ProgramData\FlashFXP\3\Quick.dat |
file | C:\ProgramData\VanDyke\Config\Sessions\ |
file | C:\Users\test22\AppData\Local\VanDyke\Config\Sessions\ |
file | C:\Users\test22\AppData\Roaming\VanDyke\Config\Sessions\ |
file | C:\Users\test22\AppData\Local\FTP Explorer\profiles.xml |
file | C:\ProgramData\FTP Explorer\profiles.xml |
file | C:\Users\test22\AppData\Roaming\FTP Explorer\profiles.xml |
file | C:\ProgramData\SmartFTP\Favorites.dat |
file | C:\Users\test22\AppData\Roaming\SmartFTP\History.dat |
file | C:\Users\test22\AppData\Local\SmartFTP\History.dat |
file | C:\ProgramData\SmartFTP\Client 2.0\Favorites\Favorites.dat |
file | C:\ProgramData\SmartFTP\History.dat |
file | C:\Users\test22\AppData\Local\SmartFTP\Client 2.0\Favorites\Favorites.dat |
file | C:\Users\test22\AppData\Local\SmartFTP\Client 2.0\Favorites\ |
file | C:\Users\test22\AppData\Roaming\SmartFTP\Favorites.dat |
file | C:\Users\test22\AppData\Local\SmartFTP\Favorites.dat |
file | C:\Users\test22\AppData\Roaming\SmartFTP\Client 2.0\Favorites\ |
file | C:\ProgramData\SmartFTP\Client 2.0\Favorites\ |
file | C:\Users\test22\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Favorites.dat |
file | C:\Users\test22\AppData\Roaming\TurboFTP\addrbk.dat |
file | C:\Users\test22\AppData\Roaming\FTPRush\RushSite.xml |
file | C:\Users\test22\wcx_ftp.ini |
file | C:\Users\test22\AppData\Roaming\FileZilla\sitemanager.xml |
file | C:\Users\test22\AppData\Roaming\FileZilla\recentservers.xml |
registry | HKEY_CURRENT_USER\SOFTWARE\Far\Plugins\FTP\Hosts |
registry | HKEY_CURRENT_USER\SOFTWARE\Far2\Plugins\FTP\Hosts |
registry | HKEY_CURRENT_USER\Software\Far\SavedDialogHistory\FTPHost |
registry | HKEY_CURRENT_USER\Software\Far2\SavedDialogHistory\FTPHost |
registry | HKEY_LOCAL_MACHINE\Software\Ghisler\Windows Commander |
registry | HKEY_CURRENT_USER\Software\Ghisler\Windows Commander |
registry | HKEY_CURRENT_USER\Software\Ghisler\Total Commander |
registry | HKEY_LOCAL_MACHINE\Software\Ghisler\Total Commander |
registry | HKEY_CURRENT_USER\Software\BPFTP\Bullet Proof FTP\Main |
file | C:\Users\test22\AppData\Roaming\Digsby\Digsby.dat |
file | C:\Users\test22\AppData\Roaming\MySpace\IM\users.txt |
file | C:\Users\test22\AppData\Roaming\.purple\accounts.xml |
file | C:\ProgramData\.purple\accounts.xml |
file | C:\Users\test22\AppData\Local\Trillian\users\global\accounts.ini |
file | C:\ProgramData\Trillian\users\global\accounts.ini |
file | C:\Users\test22\AppData\Roaming\Trillian\users\global\accounts.ini |
registry | HKEY_CURRENT_USER\Software\Google\Google Talk\Accounts |
registry | HKEY_CURRENT_USER\Software\Paltalk |
file | C:\ProgramData\SmartFTP\Favorites.dat |
file | C:\Users\test22\AppData\Roaming\SmartFTP\History.dat |
file | C:\Users\test22\AppData\Local\SmartFTP\History.dat |
file | C:\ProgramData\SmartFTP\Client 2.0\Favorites\Favorites.dat |
file | C:\ProgramData\SmartFTP\History.dat |
file | C:\Users\test22\AppData\Local\SmartFTP\Client 2.0\Favorites\Favorites.dat |
file | C:\Users\test22\AppData\Local\SmartFTP\Client 2.0\Favorites\ |
file | C:\Users\test22\AppData\Roaming\SmartFTP\Favorites.dat |
file | C:\Users\test22\AppData\Local\SmartFTP\Favorites.dat |
file | C:\Users\test22\AppData\Roaming\SmartFTP\Client 2.0\Favorites\ |
file | C:\ProgramData\SmartFTP\Client 2.0\Favorites\ |
file | C:\Users\test22\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Favorites.dat |
file | C:\Users\test22\AppData\Local\Microsoft\Windows Live Mail\ |
file | C:\Users\test22\AppData\Roaming\Thunderbird\profiles.ini |
registry | HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts |
registry | HKEY_CURRENT_USER\Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676 |
registry | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\c02ebc5353d9cd11975200aa004ae40e\HTTP Password |
registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Account Manager\Import |
registry | HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts |
registry | HKEY_CURRENT_USER\Software\RimArts\B2\Settings |
registry | HKEY_CURRENT_USER\Software\Poco Systems Inc\PocoMail 4 |
registry | HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Thunderbird 78.4.0\extensions |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\Scribe\Protocols\mailto\shell |
registry | HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003\POP3 Password2 |
registry | HKEY_CURRENT_USER\Software\Google\Google Talk\Accounts |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A2F66E87A7CA1FBA923BD6BE809298B088A47E68\Blob |
dead_host | 62.173.146.41:443 |