Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Aug. 5, 2024, 2:03 p.m. | Aug. 5, 2024, 2:03 p.m. |
-
-
-
sc.exe sc config "UxSms" start= demand
2684
-
-
-
-
net1.exe C:\Windows\system32\net1 stop "Desktop Window Manager Session Manager"
2868
-
-
-
-
-
net1.exe C:\Windows\system32\net1 start "Desktop Window Manager Session Manager"
3036
-
-
-
rundll32.exe "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,Control_RunDLL C:\Windows\system32\desk.cpl desk,@Themes /Action:OpenTheme /file:"C:\Windows\Resources\Themes\aero.theme"
2076 -
-
-
net1.exe C:\Windows\system32\net1 stop "Desktop Window Manager Session Manager"
2740
-
-
-
-
-
net1.exe C:\Windows\system32\net1 start "Desktop Window Manager Session Manager"
2128
-
-
-
rundll32.exe "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,Control_RunDLL C:\Windows\system32\desk.cpl desk,@Themes /Action:OpenTheme /file:"C:\Windows\Resources\Themes\aero.theme"
3056 -
-
-
net1.exe C:\Windows\system32\net1 stop "Desktop Window Manager Session Manager"
2508
-
-
-
-
-
net1.exe C:\Windows\system32\net1 start "Desktop Window Manager Session Manager"
1304
-
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
name | RT_VERSION | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000f7058 | size | 0x00000240 |
section | {u'size_of_data': u'0x0007d000', u'virtual_address': u'0x00079000', u'entropy': 7.999266911137163, u'name': u'UPX1', u'virtual_size': u'0x0007d000'} | entropy | 7.99926691114 | description | A section with a high entropy has been found | |||||||||
entropy | 0.996015936255 | description | Overall entropy of this PE file is high |
section | UPX0 | description | Section name indicates UPX | ||||||
section | UPX1 | description | Section name indicates UPX | ||||||
section | UPX2 | description | Section name indicates UPX |
cmdline | sc config "UxSms" start= demand |
cmdline | cmd /c sc config "UxSms" start= demand |
cmdline | cmd /c net start "Desktop Window Manager Session Manager" |
cmdline | net stop "Desktop Window Manager Session Manager" |
cmdline | net start "Desktop Window Manager Session Manager" |
cmdline | cmd /c net stop "Desktop Window Manager Session Manager" |
Bkav | W32.AIDetectMalware |
Lionic | Trojan.Win32.BlackMoon.4!c |
Elastic | malicious (high confidence) |
Cynet | Malicious (score: 100) |
Skyhigh | BehavesLike.Win32.Generic.hc |
ALYac | Gen:Variant.Zusy.554925 |
Cylance | Unsafe |
VIPRE | Gen:Variant.Zusy.554925 |
Sangfor | Trojan.Win32.Blackmoon.Vtoi |
BitDefender | Gen:Variant.Zusy.554925 |
K7GW | Trojan ( 005931081 ) |
Cybereason | malicious.2b5c5a |
Arcabit | Trojan.Zusy.D877AD |
Symantec | ML.Attribute.HighConfidence |
ESET-NOD32 | a variant of Win32/Packed.BlackMoon.A suspicious |
APEX | Malicious |
McAfee | Artemis!E91D7D92B5C5 |
Avast | Win32:MalwareX-gen [Trj] |
Kaspersky | UDS:DangerousObject.Multi.Generic |
Alibaba | Worm:Win32/MalwareX.3cf0c735 |
MicroWorld-eScan | Gen:Variant.Zusy.554925 |
Rising | Downloader.Convagent!8.123D1 (CLOUD) |
Emsisoft | Application.Generic (A) |
F-Secure | Trojan.TR/ATRAPS.Gen |
TrendMicro | TrojanSpy.Win32.BLACKMOON.YXEHDZ |
McAfeeD | Real Protect-LS!E91D7D92B5C5 |
Trapmine | malicious.high.ml.score |
FireEye | Generic.mg.e91d7d92b5c5ab6d |
Sophos | BlackMoon Packed (PUA) |
Ikarus | Trojan.Win32.FakeAV |
Detected | |
Avira | TR/ATRAPS.Gen |
MAX | malware (ai score=84) |
Antiy-AVL | Trojan[Packed]/Win32.Blackmoon |
Kingsoft | Win32.Trojan-Downloader.Convagent.gen |
Gridinsoft | Ransom.Win32.Sabsik.sa |
Xcitium | TrojWare.Win32.TrojanSpy.Banker.OV@6e1pyh |
Microsoft | Trojan:Win32/Wacatac.B!ml |
ZoneAlarm | UDS:DangerousObject.Multi.Generic |
GData | Gen:Variant.Zusy.554925 |
Varist | W32/Trojan.GRW.gen!Eldorado |
AhnLab-V3 | Trojan/Win.Generic.R658019 |
BitDefenderTheta | Gen:NN.ZexaF.36810.FqKfamzNWUcb |
DeepInstinct | MALICIOUS |
Malwarebytes | PUP.Optional.ChinAd |
TrendMicro-HouseCall | TrojanSpy.Win32.BLACKMOON.YXEHDZ |
SentinelOne | Static AI - Malicious PE |
Fortinet | W32/CoinMiner.ESFJ!tr |
AVG | Win32:MalwareX-gen [Trj] |
Paloalto | generic.ml |