Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | June 19, 2024, 2:30 p.m. | June 19, 2024, 2:32 p.m. |
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\_MEI20882\libcrypto-3.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20882\libffi-8.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20882\VCRUNTIME140.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20882\numpy.libs\libopenblas64__v0.3.23-293-gc2f4bdbb-gcc_10_3_0-2bde3a66a51006b2b53eb373ff767a3f.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20882\VCRUNTIME140_1.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20882\libssl-3.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20882\python3.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20882\python312.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20882\pywin32_system32\pywintypes312.dll |
section | {u'size_of_data': u'0x0000f000', u'virtual_address': u'0x00049000', u'entropy': 7.350146232003548, u'name': u'.rsrc', u'virtual_size': u'0x0000ef8c'} | entropy | 7.350146232 | description | A section with a high entropy has been found |
Bkav | W64.AIDetectMalware |
Sangfor | Trojan.Win32.Save.a |
APEX | Malicious |
Avast | Win64:SpywareX-gen [Trj] |
Zillya | Trojan.Agent.Win32.3962631 |
McAfeeD | ti!09020E3E1622 |
Jiangmin | TrojanSpy.Python.bf |
Antiy-AVL | Trojan[Spy]/Python.Agent |
Microsoft | Program:Win32/Wacapew.C!ml |
AVG | Win64:SpywareX-gen [Trj] |