Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Oct. 15, 2024, 2:18 p.m. | Oct. 15, 2024, 2:24 p.m. |
-
-
worker.exe "C:\Users\test22\AppData\Local\Temp\worker.exe"
2564
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-file-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\ucrtbase.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-crt-environment-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-debug-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-crt-locale-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-crt-process-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-errorhandling-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\pywin32_system32\pywintypes312.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-libraryloader-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-processthreads-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-crt-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-crt-utility-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-util-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-crt-stdio-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\libffi-8.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-rtlsupport-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-sysinfo-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-handle-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-interlocked-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\VCRUNTIME140_1.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-console-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\VCRUNTIME140.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-profile-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-synch-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\libcrypto-3.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-processthreads-l1-1-1.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-crt-string-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-memory-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-crt-conio-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-crt-time-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-crt-math-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-datetime-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\libssl-3.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-crt-convert-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-timezone-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-namedpipe-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-string-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\python312.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-synch-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-file-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-processenvironment-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-crt-runtime-l1-1-0.dll |
section | {u'size_of_data': u'0x0000f600', u'virtual_address': u'0x00047000', u'entropy': 7.554976062358976, u'name': u'.rsrc', u'virtual_size': u'0x0000f41c'} | entropy | 7.55497606236 | description | A section with a high entropy has been found |
Bkav | W64.AIDetectMalware |
CrowdStrike | win/malicious_confidence_60% (D) |
APEX | Malicious |
Kaspersky | UDS:DangerousObject.Multi.Generic |
Zillya | Trojan.Agent.Win32.3991781 |
McAfeeD | ti!D5008A50F286 |
Kingsoft | Win32.Troj.Unknown.a |
ZoneAlarm | UDS:DangerousObject.Multi.Generic |
DeepInstinct | MALICIOUS |
Paloalto | generic.ml |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\America\Mendoza |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\America\Creston |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Asia\Novokuznetsk |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Pacific\Kosrae |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Europe\Volgograd |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-crt-process-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Asia\Aqtobe |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\America\Anchorage |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Europe\Budapest |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Europe\Warsaw |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Asia\Barnaul |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\eth_utils\__json\eth_networks.json |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\America\North_Dakota\New_Salem |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Asia\Baghdad |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Pacific\Bougainville |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\America\Moncton |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\leapseconds |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Africa\Kinshasa |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\America\Dawson_Creek |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Africa\Ndjamena |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\attrs-24.2.0.dist-info\licenses\LICENSE |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Pacific\Norfolk |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\eth_abi-5.1.0.dist-info\RECORD |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Africa\Luanda |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Australia\Canberra |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Europe\Saratov |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\VCRUNTIME140_1.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\America\St_Kitts |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Africa\Niamey |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\Crypto\Cipher\_raw_des.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\Crypto\Hash\_keccak.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\America\Merida |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Africa\Ceuta |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\US\Mountain |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\Crypto\Hash\_poly1305.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\Crypto\Hash\_MD2.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\eth_account-0.13.3.dist-info\LICENSE |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\America\Matamoros |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\UCT |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\_zoneinfo.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\America\Havana |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\eth_keys-0.5.1.dist-info\LICENSE |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Australia\Broken_Hill |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\Crypto\Hash\_ghash_portable.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\America\Argentina\Mendoza |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Asia\Almaty |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Etc\GMT-8 |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\multidict\_multidict.cp312-win_amd64.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI20562\tzdata\zoneinfo\Asia\Atyrau |