Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Feb. 15, 2024, 7:56 a.m. | Feb. 15, 2024, 7:59 a.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,CIrNTzBaPkppGNf
2548 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,CZnIUAAeJ
2632 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,FxJWXdx
2724 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,GbmgwMEzKpXc
2820 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,HipXGmygXapBRYfa
2912 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,IYfRriwGvbgbXBXReH
3004 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,LKSMdMaTT
1152 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,NpZatICsK
2068 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,SOdCGqnNtDWyDo
2256 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,UAyCqwHRBMHCdHlVz
2496 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,ZfDMgndWxjR
2668 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,iBZHcoeoarRd
2804 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,jERKotJBwfw
2948 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,nkYPRlgSTnlUkuDTW
2636 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,rtVNQhSpgienExR
1356 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,start
2364-
powershell.exe "C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath
1644
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,uMRRtkuQVecTfq
2672 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,ukniOqaVKgeX
2780 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,yVmJFl
3024 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\resources.dll,
3008
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\MachineGuid |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\DigitalProductId |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\DigitalProductId |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\InstallDate |
pdb_path | E:\cpp\git7\dll\WndResizerApp.pdb |
file | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
file | C:\Program Files\Mozilla Firefox\firefox.exe |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome\NoModify |
resource name | PNG |
resource name | STYLE_XML |
resource name | None |
description | rundll32.exe tried to sleep 582 seconds, actually delayed analysis time by 582 seconds |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\_locales\bg\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\manifest.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\icon_16.png |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\_locales\de\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Preferences |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOCK |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG.old |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\000003.log |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extension State\MANIFEST-000001 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOCK |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\_locales\en_GB\messages.json |
file | C:\Users\test22\AppData\Roaming\Opera\wand.dat |
file | C:\Users\test22\AppData\Local\Programs\Opera\ |
file | C:\Users\test22\AppData\Local\Yandex\YandexBrowser\Application\browser.exe |
registry | HKEY_CURRENT_USER\Software\Opera Software |
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Add-MpPreference -ExclusionPath |
cmdline | "C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath |
wmi | SELECT * FROM Win32_NetworkAdapter |
wmi | SELECT * FROM Win32_OperatingSystem |
wmi | SELECT * FROM Win32_ComputerSystem |
Skyhigh | BehavesLike.Win32.Dropper.wc |
VirIT | Trojan.Win32.DanaBot.DXA |
ESET-NOD32 | a variant of Win32/GenKryptik.GTWG |
McAfee | Artemis!E758E0711301 |
Kaspersky | UDS:Trojan-Banker.Win32.Danabot |
Rising | Trojan.Kryptik!8.8 (CLOUD) |
Kingsoft | Win32.HeurC.KVM008.a |
Microsoft | Trojan:Win32/Wacatac.B!ml |
section | {u'size_of_data': u'0x0097d800', u'virtual_address': u'0x00001000', u'entropy': 7.742600573834696, u'name': u'.text', u'virtual_size': u'0x0097d68a'} | entropy | 7.74260057383 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00166400', u'virtual_address': u'0x009dc000', u'entropy': 7.564019726941489, u'name': u'.rsrc', u'virtual_size': u'0x00166230'} | entropy | 7.56401972694 | description | A section with a high entropy has been found | |||||||||
entropy | 0.957825115959 | description | Overall entropy of this PE file is high |
wmi | SELECT * FROM Win32_ComputerSystem |
host | 195.133.88.98 | |||
host | 62.173.146.41 | |||
host | 91.201.67.85 |
file | C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe |
file | C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe |
file | C:\Users\test22\AppData\Local\AVAST Software\Browser\Application\AvastBrowser.exe |
registry | HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\1\ProcessorNameString |
registry | HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString |
registry | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnonBadCertRecving |
registry | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnonZoneCrossing |
registry | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect |
file | C:\ProgramData\FlashFXP\4\History.dat |
file | C:\Users\test22\AppData\Local\FlashFXP\4\Quick.dat |
file | C:\Users\test22\AppData\Roaming\FlashFXP\4\Quick.dat |
file | C:\Users\test22\AppData\Roaming\FlashFXP\4\History.dat |
file | C:\Users\test22\AppData\Roaming\FlashFXP\3\Sites.dat |
file | C:\ProgramData\FlashFXP\4\Quick.dat |
file | C:\Users\test22\AppData\Local\FlashFXP\4\History.dat |
file | C:\Users\test22\AppData\Local\FlashFXP\3\Sites.dat |
file | C:\Users\test22\AppData\Roaming\FlashFXP\3\Quick.dat |
file | C:\ProgramData\FlashFXP\3\Sites.dat |
file | C:\ProgramData\FlashFXP\3\History.dat |
file | C:\ProgramData\FlashFXP\4\Sites.dat |
file | C:\Users\test22\AppData\Roaming\FlashFXP\4\Sites.dat |
file | C:\Users\test22\AppData\Local\FlashFXP\3\Quick.dat |
file | C:\Users\test22\AppData\Local\FlashFXP\3\History.dat |
file | C:\Users\test22\AppData\Roaming\FlashFXP\3\History.dat |
file | C:\Users\test22\AppData\Local\FlashFXP\4\Sites.dat |
file | C:\ProgramData\FlashFXP\3\Quick.dat |
file | C:\ProgramData\VanDyke\Config\Sessions\ |
file | C:\Users\test22\AppData\Local\VanDyke\Config\Sessions\ |
file | C:\Users\test22\AppData\Roaming\VanDyke\Config\Sessions\ |
file | C:\Users\test22\AppData\Local\FTP Explorer\profiles.xml |
file | C:\ProgramData\FTP Explorer\profiles.xml |
file | C:\Users\test22\AppData\Roaming\FTP Explorer\profiles.xml |
file | C:\ProgramData\SmartFTP\Favorites.dat |
file | C:\Users\test22\AppData\Roaming\SmartFTP\History.dat |
file | C:\Users\test22\AppData\Local\SmartFTP\History.dat |
file | C:\ProgramData\SmartFTP\Client 2.0\Favorites\Favorites.dat |
file | C:\ProgramData\SmartFTP\History.dat |
file | C:\Users\test22\AppData\Local\SmartFTP\Client 2.0\Favorites\Favorites.dat |
file | C:\Users\test22\AppData\Local\SmartFTP\Client 2.0\Favorites\ |
file | C:\Users\test22\AppData\Roaming\SmartFTP\Favorites.dat |
file | C:\Users\test22\AppData\Local\SmartFTP\Favorites.dat |
file | C:\Users\test22\AppData\Roaming\SmartFTP\Client 2.0\Favorites\ |
file | C:\ProgramData\SmartFTP\Client 2.0\Favorites\ |
file | C:\Users\test22\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Favorites.dat |
file | C:\Users\test22\AppData\Roaming\TurboFTP\addrbk.dat |
file | C:\Users\test22\AppData\Roaming\FTPRush\RushSite.xml |
file | C:\Users\test22\wcx_ftp.ini |
file | C:\Users\test22\AppData\Roaming\FileZilla\sitemanager.xml |
file | C:\Users\test22\AppData\Roaming\FileZilla\recentservers.xml |
registry | HKEY_CURRENT_USER\SOFTWARE\Far\Plugins\FTP\Hosts |
registry | HKEY_CURRENT_USER\SOFTWARE\Far2\Plugins\FTP\Hosts |
registry | HKEY_CURRENT_USER\Software\Far\SavedDialogHistory\FTPHost |
registry | HKEY_CURRENT_USER\Software\Far2\SavedDialogHistory\FTPHost |
registry | HKEY_LOCAL_MACHINE\Software\Ghisler\Windows Commander |
registry | HKEY_CURRENT_USER\Software\Ghisler\Windows Commander |
registry | HKEY_CURRENT_USER\Software\Ghisler\Total Commander |
registry | HKEY_LOCAL_MACHINE\Software\Ghisler\Total Commander |
registry | HKEY_CURRENT_USER\Software\BPFTP\Bullet Proof FTP\Main |
file | C:\Users\test22\AppData\Roaming\Digsby\Digsby.dat |
file | C:\Users\test22\AppData\Roaming\MySpace\IM\users.txt |
file | C:\Users\test22\AppData\Roaming\.purple\accounts.xml |
file | C:\ProgramData\.purple\accounts.xml |
file | C:\Users\test22\AppData\Local\Trillian\users\global\accounts.ini |
file | C:\ProgramData\Trillian\users\global\accounts.ini |
file | C:\Users\test22\AppData\Roaming\Trillian\users\global\accounts.ini |
registry | HKEY_CURRENT_USER\Software\Google\Google Talk\Accounts |
registry | HKEY_CURRENT_USER\Software\Paltalk |
file | C:\ProgramData\SmartFTP\Favorites.dat |
file | C:\Users\test22\AppData\Roaming\SmartFTP\History.dat |
file | C:\Users\test22\AppData\Local\SmartFTP\History.dat |
file | C:\ProgramData\SmartFTP\Client 2.0\Favorites\Favorites.dat |
file | C:\ProgramData\SmartFTP\History.dat |
file | C:\Users\test22\AppData\Local\SmartFTP\Client 2.0\Favorites\Favorites.dat |
file | C:\Users\test22\AppData\Local\SmartFTP\Client 2.0\Favorites\ |
file | C:\Users\test22\AppData\Roaming\SmartFTP\Favorites.dat |
file | C:\Users\test22\AppData\Local\SmartFTP\Favorites.dat |
file | C:\Users\test22\AppData\Roaming\SmartFTP\Client 2.0\Favorites\ |
file | C:\ProgramData\SmartFTP\Client 2.0\Favorites\ |
file | C:\Users\test22\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Favorites.dat |
file | C:\Users\test22\AppData\Local\Microsoft\Windows Live Mail\ |
registry | HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts |
registry | HKEY_CURRENT_USER\Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676 |
registry | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook |
registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Account Manager\Import |
registry | HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts |
registry | HKEY_CURRENT_USER\Software\RimArts\B2\Settings |
registry | HKEY_CURRENT_USER\Software\Poco Systems Inc\PocoMail 4 |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\Scribe\Protocols\mailto\shell |
registry | HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 |
registry | HKEY_CURRENT_USER\Software\Google\Google Talk\Accounts |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\B8A38B78036CCEEF8AC47E93E4EB3FE4D631E3E4\Blob |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |
dead_host | 62.173.146.41:443 |