Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | May 16, 2024, 9:01 a.m. | May 16, 2024, 9:05 a.m. |
Name | Response | Post-Analysis Lookup |
---|---|---|
leetboy.dynuddns.net | 185.196.11.252 |
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .gfids |
description | svcs.exe tried to sleep 426 seconds, actually delayed analysis time by 426 seconds |
reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Rmc-3XK1S0 | reg_value | "C:\Users\test22\AppData\Roaming\microsofts\svcs.exe" | ||||||
reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rmc-3XK1S0 | reg_value | "C:\Users\test22\AppData\Roaming\microsofts\svcs.exe" | ||||||
reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Rmc-3XK1S0 | reg_value | "C:\Users\test22\AppData\Roaming\microsofts\svcs.exe" | ||||||
reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rmc-3XK1S0 | reg_value | "C:\Users\test22\AppData\Roaming\microsofts\svcs.exe" |
Bkav | W32.Common.111DAF76 |
Lionic | Trojan.Win32.Remcos.m!c |
Elastic | Windows.Trojan.Remcos |
Cynet | Malicious (score: 100) |
CAT-QuickHeal | Backdoor.RemcosIH.S31010159 |
Skyhigh | BehavesLike.Win32.Remcos.gh |
ALYac | Trojan.GenericKD.72165769 |
Cylance | unsafe |
VIPRE | Trojan.GenericKD.72165769 |
Sangfor | Trojan.Win32.Save.a |
K7AntiVirus | Riskware ( 00584baa1 ) |
BitDefender | Trojan.GenericKD.72165769 |
K7GW | Riskware ( 00584baa1 ) |
Arcabit | Trojan.Generic.D44D2989 |
Baidu | Win32.Trojan.Kryptik.awm |
VirIT | Trojan.Win32.Genus.UED |
Symantec | Trojan Horse |
ESET-NOD32 | Win32/Rescoms.V |
APEX | Malicious |
McAfee | Remcos-FDQO!06F5B8DFFC6C |
Avast | Win32:RATX-gen [Trj] |
ClamAV | Win.Trojan.Remcos-9841897-0 |
Kaspersky | HEUR:Backdoor.Win32.Remcos.gen |
Alibaba | Backdoor:Win32/Remcos.8894472e |
NANO-Antivirus | Trojan.Win32.Remcos.keikbt |
SUPERAntiSpyware | Trojan.Agent/Gen-Remcos |
MicroWorld-eScan | Trojan.GenericKD.72165769 |
Rising | Backdoor.Remcos!1.BAC7 (CLASSIC) |
Emsisoft | Trojan.GenericKD.72165769 (B) |
F-Secure | Backdoor.BDS/Backdoor.Gen |
DrWeb | Trojan.Siggen22.19832 |
Zillya | Trojan.Rescoms.Win32.1521 |
TrendMicro | Backdoor.Win32.REMCOS.YXEC3Z |
FireEye | Generic.mg.06f5b8dffc6c1388 |
Sophos | Mal/Remcos-B |
Ikarus | Backdoor.Remcos |
Jiangmin | Backdoor.Remcos.dyc |
Webroot | W32.Trojan.Remcos |
Detected | |
Avira | BDS/Backdoor.Gen |
MAX | malware (ai score=83) |
Antiy-AVL | Trojan[Backdoor]/Win32.Rescoms.b |
Kingsoft | Win32.Hack.Remcos.gen |
Gridinsoft | Trojan.Win32.Remcos.tr |
Microsoft | Trojan:Win32/Remcos.ARM!MTB |
ViRobot | Trojan.Win.Z.Remcos.494592.LK |
ZoneAlarm | HEUR:Backdoor.Win32.Remcos.gen |
GData | Win32.Trojan.PSE.1OHYAG0 |
Varist | W32/Trojan.SMWB-4856 |
AhnLab-V3 | Backdoor/Win.Remcos.R625673 |