Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Aug. 2, 2024, 7:40 a.m. | Aug. 2, 2024, 7:43 a.m. |
-
-
cmd.exe C:\Windows\system32\cmd.exe /c del /q "C:\Windows\System32\SRU" >nul 2>nul
2132 -
cmd.exe C:\Windows\system32\cmd.exe /c del /q "C:\Windows\Prefetch" >nul 2>nul
2180 -
-
taskkill.exe taskkill /F /IM SystemInformer.exe
2320
-
-
-
taskkill.exe taskkill /F /IM ProcessHacker.exe
2464
-
-
-
taskkill.exe taskkill /F /IM JournalTrace.exe
2572
-
-
-
taskkill.exe taskkill /F /IM RegScanner.exe
2688
-
-
-
taskkill.exe taskkill /F /IM BrowsingHistoryView.exe
2936
-
-
-
taskkill.exe taskkill /F /IM Everything.exe
2152
-
-
-
taskkill.exe taskkill /F /IM Taskmgr.exe
2368
-
-
-
taskkill.exe taskkill /F /IM WinRAR.exe
2584
-
-
-
taskkill.exe taskkill /F /IM SystemInformer.exe
2764
-
-
-
taskkill.exe taskkill /F /IM ProcessHacker.exe
2940
-
-
-
taskkill.exe taskkill /F /IM JournalTrace.exe
2376
-
-
-
taskkill.exe taskkill /F /IM RegScanner.exe
2620
-
-
-
taskkill.exe taskkill /F /IM BrowsingHistoryView.exe
2796
-
-
-
taskkill.exe taskkill /F /IM Everything.exe
2292
-
-
-
taskkill.exe taskkill /F /IM Taskmgr.exe
2516
-
-
-
taskkill.exe taskkill /F /IM WinRAR.exe
2616
-
-
-
taskkill.exe taskkill /F /IM SystemInformer.exe
808
-
-
-
taskkill.exe taskkill /F /IM ProcessHacker.exe
2900
-
-
-
taskkill.exe taskkill /F /IM JournalTrace.exe
2540
-
-
-
taskkill.exe taskkill /F /IM RegScanner.exe
2220
-
-
-
taskkill.exe taskkill /F /IM BrowsingHistoryView.exe
2964
-
-
-
taskkill.exe taskkill /F /IM Everything.exe
3124
-
-
-
taskkill.exe taskkill /F /IM Taskmgr.exe
3232
-
-
-
taskkill.exe taskkill /F /IM WinRAR.exe
3340
-
-
-
taskkill.exe taskkill /F /IM SystemInformer.exe
3456
-
-
-
taskkill.exe taskkill /F /IM ProcessHacker.exe
3564
-
-
-
taskkill.exe taskkill /F /IM JournalTrace.exe
3672
-
-
-
taskkill.exe taskkill /F /IM RegScanner.exe
3784
-
-
-
taskkill.exe taskkill /F /IM BrowsingHistoryView.exe
3892
-
-
-
taskkill.exe taskkill /F /IM Everything.exe
4000
-
-
-
taskkill.exe taskkill /F /IM Taskmgr.exe
2272
-
-
-
taskkill.exe taskkill /F /IM WinRAR.exe
3216
-
-
-
taskkill.exe taskkill /F /IM SystemInformer.exe
3392
-
-
-
taskkill.exe taskkill /F /IM ProcessHacker.exe
3540
-
-
-
taskkill.exe taskkill /F /IM JournalTrace.exe
2284
-
-
-
taskkill.exe taskkill /F /IM RegScanner.exe
3780
-
-
-
taskkill.exe taskkill /F /IM BrowsingHistoryView.exe
4020
-
-
-
taskkill.exe taskkill /F /IM Everything.exe
3144
-
-
-
taskkill.exe taskkill /F /IM Taskmgr.exe
3368
-
-
-
taskkill.exe taskkill /F /IM WinRAR.exe
3568
-
-
-
taskkill.exe taskkill /F /IM SystemInformer.exe
3648
-
-
-
taskkill.exe taskkill /F /IM ProcessHacker.exe
1808
-
-
-
taskkill.exe taskkill /F /IM JournalTrace.exe
3288
-
-
-
taskkill.exe taskkill /F /IM RegScanner.exe
3452
-
-
-
taskkill.exe taskkill /F /IM BrowsingHistoryView.exe
3860
-
-
-
taskkill.exe taskkill /F /IM Everything.exe
3108
-
-
-
taskkill.exe taskkill /F /IM Taskmgr.exe
3624
-
-
-
taskkill.exe taskkill /F /IM WinRAR.exe
3804
-
-
-
taskkill.exe taskkill /F /IM SystemInformer.exe
2012
-
-
-
taskkill.exe taskkill /F /IM ProcessHacker.exe
2348
-
-
-
taskkill.exe taskkill /F /IM JournalTrace.exe
3444
-
-
-
taskkill.exe taskkill /F /IM RegScanner.exe
1948
-
-
-
taskkill.exe taskkill /F /IM BrowsingHistoryView.exe
3056
-
-
-
taskkill.exe taskkill /F /IM Everything.exe
916
-
-
-
taskkill.exe taskkill /F /IM Taskmgr.exe
3660
-
-
-
taskkill.exe taskkill /F /IM WinRAR.exe
3548
-
-
-
taskkill.exe taskkill /F /IM SystemInformer.exe
3960
-
-
-
taskkill.exe taskkill /F /IM ProcessHacker.exe
3788
-
-
-
taskkill.exe taskkill /F /IM JournalTrace.exe
4160
-
-
-
taskkill.exe taskkill /F /IM RegScanner.exe
4268
-
-
-
taskkill.exe taskkill /F /IM BrowsingHistoryView.exe
4376
-
-
-
taskkill.exe taskkill /F /IM Everything.exe
4484
-
-
-
taskkill.exe taskkill /F /IM Taskmgr.exe
4592
-
-
-
taskkill.exe taskkill /F /IM WinRAR.exe
4704
-
-
-
taskkill.exe taskkill /F /IM SystemInformer.exe
4812
-
-
-
taskkill.exe taskkill /F /IM ProcessHacker.exe
4920
-
-
-
taskkill.exe taskkill /F /IM JournalTrace.exe
5028
-
-
-
taskkill.exe taskkill /F /IM RegScanner.exe
4104
-
-
-
taskkill.exe taskkill /F /IM BrowsingHistoryView.exe
4244
-
-
-
taskkill.exe taskkill /F /IM Everything.exe
4404
-
-
-
taskkill.exe taskkill /F /IM Taskmgr.exe
4536
-
-
-
taskkill.exe taskkill /F /IM WinRAR.exe
4552
-
-
-
taskkill.exe taskkill /F /IM SystemInformer.exe
4828
-
-
-
taskkill.exe taskkill /F /IM ProcessHacker.exe
4960
-
-
-
taskkill.exe taskkill /F /IM JournalTrace.exe
5108
-
-
-
taskkill.exe taskkill /F /IM RegScanner.exe
4296
-
-
-
taskkill.exe taskkill /F /IM BrowsingHistoryView.exe
4372
-
-
-
taskkill.exe taskkill /F /IM Everything.exe
4640
-
-
-
taskkill.exe taskkill /F /IM Taskmgr.exe
4852
-
-
-
taskkill.exe taskkill /F /IM WinRAR.exe
5084
-
-
-
taskkill.exe taskkill /F /IM SystemInformer.exe
4312
-
-
-
taskkill.exe taskkill /F /IM ProcessHacker.exe
4380
-
-
-
taskkill.exe taskkill /F /IM JournalTrace.exe
4840
-
-
-
taskkill.exe taskkill /F /IM RegScanner.exe
1708
-
-
-
taskkill.exe taskkill /F /IM BrowsingHistoryView.exe
4336
-
-
-
taskkill.exe taskkill /F /IM Everything.exe
1972
-
-
-
taskkill.exe taskkill /F /IM Taskmgr.exe
4188
-
-
-
taskkill.exe taskkill /F /IM WinRAR.exe
4540
-
-
-
taskkill.exe taskkill /F /IM SystemInformer.exe
4204
-
-
-
taskkill.exe taskkill /F /IM ProcessHacker.exe
444
-
-
-
taskkill.exe taskkill /F /IM JournalTrace.exe
4308
-
-
-
taskkill.exe taskkill /F /IM RegScanner.exe
4228
-
-
-
taskkill.exe taskkill /F /IM BrowsingHistoryView.exe
4924
-
-
-
taskkill.exe taskkill /F /IM Everything.exe
2100
-
-
-
taskkill.exe taskkill /F /IM Taskmgr.exe
5180
-
-
-
taskkill.exe taskkill /F /IM WinRAR.exe
5292
-
-
-
taskkill.exe taskkill /F /IM SystemInformer.exe
5404
-
-
-
taskkill.exe taskkill /F /IM ProcessHacker.exe
5516
-
-
-
taskkill.exe taskkill /F /IM JournalTrace.exe
5632
-
-
cmd.exe C:\Windows\system32\cmd.exe /c taskkill /F /IM RegScanner.exe >nul 2>nul
5756
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | E:\IDDE\pon\x64\Release\pon.pdb |
cmdline | C:\Windows\system32\cmd.exe /c del /q "C:\Windows\System32\SRU" >nul 2>nul |
cmdline | C:\Windows\system32\cmd.exe /c taskkill /F /IM JournalTrace.exe >nul 2>nul |
cmdline | C:\Windows\system32\cmd.exe /c del /q "C:\Windows\Prefetch" >nul 2>nul |
cmdline | C:\Windows\system32\cmd.exe /c taskkill /F /IM WinRAR.exe >nul 2>nul |
cmdline | C:\Windows\system32\cmd.exe /c taskkill /F /IM RegScanner.exe >nul 2>nul |
cmdline | C:\Windows\system32\cmd.exe /c taskkill /F /IM SystemInformer.exe >nul 2>nul |
cmdline | C:\Windows\system32\cmd.exe /c taskkill /F /IM BrowsingHistoryView.exe >nul 2>nul |
cmdline | C:\Windows\system32\cmd.exe /c taskkill /F /IM Taskmgr.exe >nul 2>nul |
cmdline | C:\Windows\system32\cmd.exe /c taskkill /F /IM Everything.exe >nul 2>nul |
cmdline | C:\Windows\system32\cmd.exe /c taskkill /F /IM ProcessHacker.exe >nul 2>nul |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "Taskmgr.exe") |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "SystemInformer.exe") |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "JournalTrace.exe") |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "Everything.exe") |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "ProcessHacker.exe") |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "BrowsingHistoryView.exe") |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "RegScanner.exe") |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "WinRAR.exe") |
cmdline | taskkill /F /IM SystemInformer.exe |
cmdline | C:\Windows\system32\cmd.exe /c del /q "C:\Windows\System32\SRU" >nul 2>nul |
cmdline | taskkill /F /IM WinRAR.exe |
cmdline | taskkill /F /IM ProcessHacker.exe |
cmdline | C:\Windows\system32\cmd.exe /c taskkill /F /IM JournalTrace.exe >nul 2>nul |
cmdline | C:\Windows\system32\cmd.exe /c del /q "C:\Windows\Prefetch" >nul 2>nul |
cmdline | C:\Windows\system32\cmd.exe /c taskkill /F /IM WinRAR.exe >nul 2>nul |
cmdline | taskkill /F /IM JournalTrace.exe |
cmdline | taskkill /F /IM BrowsingHistoryView.exe |
cmdline | C:\Windows\system32\cmd.exe /c taskkill /F /IM RegScanner.exe >nul 2>nul |
cmdline | C:\Windows\system32\cmd.exe /c taskkill /F /IM SystemInformer.exe >nul 2>nul |
cmdline | C:\Windows\system32\cmd.exe /c taskkill /F /IM BrowsingHistoryView.exe >nul 2>nul |
cmdline | taskkill /F /IM Taskmgr.exe |
cmdline | taskkill /F /IM RegScanner.exe |
cmdline | C:\Windows\system32\cmd.exe /c taskkill /F /IM Taskmgr.exe >nul 2>nul |
cmdline | C:\Windows\system32\cmd.exe /c taskkill /F /IM Everything.exe >nul 2>nul |
cmdline | taskkill /F /IM Everything.exe |
cmdline | C:\Windows\system32\cmd.exe /c taskkill /F /IM ProcessHacker.exe >nul 2>nul |
Bkav | W64.AIDetectMalware |
Skyhigh | BehavesLike.Win64.Dropper.mt |
APEX | Malicious |
McAfee | Artemis!3FBAD097793F |
DrWeb | Trojan.KillFiles2.3011 |
Webroot | W32.Trojan.Casdet |
Antiy-AVL | Trojan/Win32.Agent |
Microsoft | Trojan:Win32/Casdet!rfn |
DeepInstinct | MALICIOUS |
MaxSecure | Trojan.Malware.300983.susgen |
Fortinet | PossibleThreat.PALLAS.H |
Paloalto | generic.ml |
CrowdStrike | win/malicious_confidence_70% (W) |
file | C:\Windows\Prefetch\PYTHON.EXE-C663CFDC.pf |
file | C:\Windows\Prefetch\GOOGLEUPDATESETUP.EXE-305B5E54.pf |
file | C:\Windows\Prefetch\AUDIODG.EXE-BDFD3029.pf |
file | C:\Windows\Prefetch\THUNDERBIRD.EXE-A0DA674F.pf |
file | C:\Windows\Prefetch\DLLHOST.EXE-4F28A26F.pf |
file | C:\Windows\Prefetch\SVCHOST.EXE-7AC6742A.pf |
file | C:\Windows\Prefetch\GOOGLEUPDATE.EXE-D0E66F4A.pf |
file | C:\Windows\Prefetch\WERMGR.EXE-0F2AC88C.pf |
file | C:\Windows\Prefetch\86.0.4240.111_CHROME_INSTALLE-AF26656A.pf |
file | C:\Windows\Prefetch\CSC.EXE-BE9AC2DF.pf |
file | C:\Windows\Prefetch\SEARCHPROTOCOLHOST.EXE-0CB8CADE.pf |
file | C:\Windows\Prefetch\SOFTWARE_REPORTER_TOOL.EXE-EB18F4FF.pf |
file | C:\Windows\Prefetch\IEXPLORE.EXE-908C99F8.pf |
file | C:\Windows\Prefetch\DLLHOST.EXE-5E46FA0D.pf |
file | C:\Windows\Prefetch\SLUI.EXE-724E99D9.pf |
file | C:\Windows\Prefetch\RUNDLL32.EXE-1304AE86.pf |
file | C:\Windows\Prefetch\PING.EXE-7E94E73E.pf |
file | C:\Windows\Prefetch\GOOGLEUPDATE.EXE-C3A1B497.pf |
file | C:\Windows\Prefetch\IEXPLORE.EXE-4B6C9213.pf |
file | C:\Windows\Prefetch\WMIPRVSE.EXE-1628051C.pf |
file | C:\Windows\Prefetch\DEFRAG.EXE-588F90AD.pf |
file | C:\Windows\Prefetch\CHROME.EXE-D999B1BA.pf |
file | C:\Windows\Prefetch\IMKRMIG.EXE-AAA206C5.pf |
file | C:\Windows\Prefetch\UNPACK200.EXE-E4DF1A4E.pf |
file | C:\Windows\Prefetch\DLLHOST.EXE-40DD444D.pf |
file | C:\Windows\Prefetch\7ZFM.EXE-22E64FB8.pf |
file | C:\Windows\Prefetch\GOOGLEUPDATESETUP.EXE-B0D5C571.pf |
file | C:\Windows\Prefetch\GOOGLEUPDATESETUP.EXE-34B7EAE8.pf |
file | C:\Windows\Prefetch\SVCHOST.EXE-E1E0ACE0.pf |
file | C:\Windows\Prefetch\LOGONUI.EXE-09140401.pf |
file | C:\Windows\Prefetch\AgGlFgAppHistory.db |
file | C:\Windows\Prefetch\JAVAW.EXE-D0AA8787.pf |
file | C:\Windows\Prefetch\SSVAGENT.EXE-0CD059B7.pf |
file | C:\Windows\Prefetch\AgGlUAD_P_S-1-5-21-3832866432-4053218753-3017428901-1001.db |
file | C:\Windows\Prefetch\OSE.EXE-2B23CA4C.pf |
file | C:\Windows\Prefetch\INSTALLER.EXE-60163557.pf |
file | C:\Windows\Prefetch\PINGSENDER.EXE-8E79128B.pf |
file | C:\Windows\Prefetch\MOBSYNC.EXE-C5E2284F.pf |
file | C:\Windows\Prefetch\RUNDLL32.EXE-5A853E81.pf |
file | C:\Windows\Prefetch\AgRobust.db |
file | C:\Windows\Prefetch\ICACLS.EXE-B19DE1F7.pf |
file | C:\Windows\Prefetch\IMEKLMG.EXE-3FEB7CC0.pf |
file | C:\Windows\Prefetch\GOOGLEUPDATECOMREGISTERSHELL6-BB6760AF.pf |
file | C:\Windows\Prefetch\NOTEPAD.EXE-D8414F97.pf |
file | C:\Windows\Prefetch\7ZG.EXE-0F8C4081.pf |
file | C:\Windows\Prefetch\CMD.EXE-AC113AA8.pf |
file | C:\Windows\Prefetch\CMD.EXE-4A81B364.pf |
file | C:\Windows\Prefetch\AgGlGlobalHistory.db |
file | C:\Windows\Prefetch\MMC.EXE-561C5A40.pf |
file | C:\Windows\Prefetch\MSPAINT.EXE-76E10B24.pf |
file | C:\Windows\Prefetch\SETUP.EXE-9129729F.pf |
file | C:\Windows\Prefetch\IMEKLMG.EXE-3FEB7CC0.pf |
file | C:\Windows\Prefetch\DRVINST.EXE-4CB4314A.pf |
file | C:\Windows\Prefetch\SNIPPINGTOOL.EXE-EFFDAFDE.pf |
file | C:\Windows\Prefetch\OSE00000.EXE-D36F8D80.pf |
file | C:\Windows\Prefetch\AgGlUAD_S-1-5-21-3832866432-4053218753-3017428901-1001.db |
file | C:\Windows\Prefetch\COMPMGMTLAUNCHER.EXE-D8C6028E.pf |
file | C:\Windows\Prefetch\GOOGLEUPDATECOMREGISTERSHELL6-BB6760AF.pf |
file | C:\Windows\Prefetch\SVCHOST.EXE-7AC6742A.pf |
file | C:\Windows\Prefetch\HELPER.EXE-B63E9F86.pf |
file | C:\Windows\Prefetch\THUNDERBIRD SETUP 78.4.0.EXE-A278C73F.pf |
file | C:\Windows\Prefetch\MSIEXEC.EXE-E09A077A.pf |
file | C:\Windows\Prefetch\IMEKLMG.EXE-CF8CFA9B.pf |
file | C:\Windows\Prefetch\RUNDLL32.EXE-411A328D.pf |
file | C:\Windows\Prefetch\SVCHOST.EXE-A1476A17.pf |
file | C:\Windows\Prefetch\JAVAW.EXE-D0AA8787.pf |
file | C:\Windows\Prefetch\RUNDLL32.EXE-7BCB21A1.pf |
file | C:\Windows\Prefetch\CONTROL.EXE-817F8F1D.pf |
file | C:\Windows\Prefetch\MSCORSVW.EXE-90526FAC.pf |
file | C:\Windows\Prefetch\GOOGLEUPDATESETUP.EXE-34B7EAE8.pf |
file | C:\Windows\Prefetch\RUNDLL32.EXE-5A853E81.pf |
file | C:\Windows\Prefetch\CVTRES.EXE-2B9D810D.pf |
file | C:\Windows\Prefetch\RUNDLL32.EXE-8C11D845.pf |
file | C:\Windows\Prefetch\TASKHOST.EXE-7238F31D.pf |
file | C:\Windows\Prefetch\SEARCHFILTERHOST.EXE-77482212.pf |
file | C:\Windows\Prefetch\SVCHOST.EXE-5901D5E8.pf |
file | C:\Windows\Prefetch\BSPATCH.EXE-C0E5ADBC.pf |
file | C:\Windows\Prefetch\JRE.EXE-A621F6AA.pf |
file | C:\Windows\Prefetch\GOOGLEUPDATESETUP.EXE-305B5E54.pf |
file | C:\Windows\Prefetch\GOOGLEUPDATESETUP.EXE-B0D5C571.pf |
file | C:\Windows\Prefetch\SETUP.EXE-E199D442.pf |
file | C:\Windows\Prefetch\SEARCHPROTOCOLHOST.EXE-0CB8CADE.pf |
file | C:\Windows\Prefetch\MAINTENANCESERVICE.EXE-FA0B1B99.pf |
file | C:\Windows\Prefetch\WERMGR.EXE-0F2AC88C.pf |
file | C:\Windows\Prefetch\CMD.EXE-AC113AA8.pf |
file | C:\Windows\Prefetch\AgGlUAD_P_S-1-5-21-3832866432-4053218753-3017428901-1001.db |
file | C:\Windows\Prefetch\AgAppLaunch.db |
file | C:\Windows\Prefetch\NOTEPAD.EXE-D8414F97.pf |
file | C:\Windows\Prefetch\SEARCHINDEXER.EXE-4A6353B9.pf |
file | C:\Windows\Prefetch\IEXPLORE.EXE-908C99F8.pf |
file | C:\Windows\Prefetch\GOOGLEUPDATE.EXE-C3A1B497.pf |
file | C:\Windows\Prefetch\RUNDLL32.EXE-1304AE86.pf |
file | C:\Windows\Prefetch\AgGlFaultHistory.db |
file | C:\Windows\Prefetch\AUDIODG.EXE-BDFD3029.pf |
file | C:\Windows\Prefetch\PfSvPerfStats.bin |
file | C:\Windows\Prefetch\DEFRAG.EXE-588F90AD.pf |
file | C:\Windows\Prefetch\DLLHOST.EXE-97F6A314.pf |
file | C:\Windows\Prefetch\CSC.EXE-BE9AC2DF.pf |
file | C:\Windows\Prefetch\GOOGLEUPDATE.EXE-F2AAEA76.pf |
file | C:\Windows\Prefetch\SVCHOST.EXE-CF79EE4C.pf |
file | C:\Windows\Prefetch\VBOXDRVINST.EXE-7DCD6070.pf |