Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Aug. 15, 2024, 10:34 a.m. | Aug. 15, 2024, 10:36 a.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\e93629b052f25d25c92a4afaee51cc81.dll,DllGetClassObject
2556-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\e93629b052f25d25c92a4afaee51cc81.dll,DllGetClassObject
2960
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\e93629b052f25d25c92a4afaee51cc81.dll,DllRegisterServer
2640-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\e93629b052f25d25c92a4afaee51cc81.dll,DllRegisterServer
3016
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\e93629b052f25d25c92a4afaee51cc81.dll,DllRegisterServerEx
2736-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\e93629b052f25d25c92a4afaee51cc81.dll,DllRegisterServerEx
1152
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\e93629b052f25d25c92a4afaee51cc81.dll,DllUnregisterServer
2824-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\e93629b052f25d25c92a4afaee51cc81.dll,DllUnregisterServer
1356
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\e93629b052f25d25c92a4afaee51cc81.dll,Start
2920-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\e93629b052f25d25c92a4afaee51cc81.dll,Start
148
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\e93629b052f25d25c92a4afaee51cc81.dll,
1216 -
explorer.exe C:\Windows\Explorer.EXE
1452
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | E:\work\ooooooops\181\knock_v1.1.8\knock\bin64\knock.pdb |
section | .gfids |
Elastic | Windows.Trojan.WarmCookie |
Cynet | Malicious (score: 100) |
ClamAV | Win.Malware.Lazy-10030858-0 |
Rising | Trojan.DllInject!8.1984B (TFE:6:S2mcB0MBV6U) |
FireEye | Generic.mg.7a799f4f9aa63745 |
Detected | |
DeepInstinct | MALICIOUS |
Ikarus | Trojan.Win64.Agent |
file | C:\Windows\Tasks\Syberry.job |
file | C:\ProgramData\Tandem\Updater.exe |
file | C:\Users\test22\AppData\Roaming\SoftServe\Updater.exe |
file | C:\ProgramData\Tivix\Updater.exe |
file | C:\Users\test22\AppData\Roaming\West Agile Labs\Updater.exe |
file | C:\ProgramData\SnapMobile\Updater.exe |
file | C:\ProgramData\TechSparq\Updater.exe |
file | C:\ProgramData\Thinkship\Updater.exe |
file | C:\ProgramData\Specbee\Updater.exe |
file | C:\ProgramData\Vectorform\Updater.exe |
file | C:\ProgramData\TECLA\Updater.dll |
file | C:\Users\test22\AppData\Roaming\ValueLabs\Updater.dll |
file | C:\ProgramData\SiteRocket Labs\Updater.exe |
file | C:\ProgramData\Copious\Updater.exe |
file | C:\Users\test22\AppData\Roaming\SnapMobile\Updater.exe |
file | C:\ProgramData\TechSparq\Updater.dll |
file | C:\ProgramData\Stride\Updater.exe |
file | C:\ProgramData\Tvisha Technologies\Updater.dll |
file | C:\Users\test22\AppData\Roaming\Vectorform\Updater.dll |
file | C:\ProgramData\Software Allies\Updater.dll |
file | C:\Users\test22\AppData\Roaming\SiteRocket Labs\Updater.dll |
file | C:\ProgramData\Stride\Updater.dll |
file | C:\Users\test22\AppData\Roaming\Tivix\Updater.dll |
file | C:\Users\test22\AppData\Roaming\Software AG\Updater.dll |
file | C:\Users\test22\AppData\Roaming\Tandem\Updater.dll |
file | C:\Users\test22\AppData\Roaming\Snyxius Technologies\Updater.dll |
file | C:\Users\test22\AppData\Roaming\Oxagile\Updater.dll |
file | C:\ProgramData\SoftServe\Updater.dll |
file | C:\ProgramData\Ventuso LLC\Updater.dll |
file | C:\Users\test22\AppData\Roaming\Tandem\Updater.exe |
file | C:\Users\test22\AppData\Roaming\Copious\Updater.dll |
file | C:\Users\test22\AppData\Roaming\Specbee\Updater.dll |
file | C:\Users\test22\AppData\Roaming\Vermonster\Updater.exe |
file | C:\Users\test22\AppData\Roaming\TECLA\Updater.dll |
file | C:\Users\test22\AppData\Roaming\Stride\Updater.dll |
file | C:\ProgramData\Zagaran Software\Updater.dll |
file | C:\Users\test22\AppData\Roaming\Thinkship\Updater.dll |
file | C:\Users\test22\AppData\Roaming\Touchtap\Updater.exe |
file | C:\ProgramData\Tyrannosaurus Tech\Updater.exe |
file | C:\Users\test22\AppData\Roaming\Software AG\Updater.exe |
file | C:\ProgramData\Solid Digital\Updater.exe |
file | C:\Users\test22\AppData\Roaming\Solid Digital\Updater.dll |
file | C:\ProgramData\TECLA\Updater.exe |
file | C:\Users\test22\AppData\Roaming\Snyxius Technologies\Updater.exe |
file | C:\Users\test22\AppData\Roaming\Copious\Updater.exe |
file | C:\ProgramData\Specbee\Updater.dll |
file | C:\ProgramData\Solid Digital\Updater.dll |
file | C:\Users\test22\AppData\Roaming\Software Allies\Updater.dll |
file | C:\ProgramData\Tyrannosaurus Tech\Updater.dll |
file | C:\Users\test22\AppData\Roaming\Zagaran Software\Updater.dll |
file | C:\Users\test22\AppData\Roaming\Vectorform\Updater.exe |