Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 18, 2024, 10:07 a.m. | Oct. 18, 2024, 10:18 a.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\swift-obfuscation-side-loading.dll,DllMain
2544-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\swift-obfuscation-side-loading.dll,DllMain
2780
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\swift-obfuscation-side-loading.dll,Start
2628-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\swift-obfuscation-side-loading.dll,Start
2788
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\swift-obfuscation-side-loading.dll,
2720
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
Bkav | W64.AIDetectMalware |
Lionic | Trojan.Win32.Havoc.m!c |
Cynet | Malicious (score: 100) |
CAT-QuickHeal | Trojan.Havocp.S33863897 |
Skyhigh | Agent-FYC!60FEA8C8E969 |
ALYac | Generic.Trojan.Havokiz.Marte.D.3988198C |
Cylance | Unsafe |
VIPRE | Generic.Trojan.Havokiz.Marte.D.3988198C |
Sangfor | Backdoor.Win64.Havoc.Vzap |
CrowdStrike | win/malicious_confidence_70% (D) |
BitDefender | Generic.Trojan.Havokiz.Marte.D.3988198C |
Arcabit | Generic.Trojan.Havokiz.Marte.D.D3CDAE6C |
Symantec | ML.Attribute.HighConfidence |
Elastic | Windows.Generic.Threat |
ESET-NOD32 | a variant of Win64/Havoc.M |
APEX | Malicious |
Avast | Win64:Evo-gen [Trj] |
ClamAV | Win.Trojan.Havoc-10019366-0 |
Kaspersky | HEUR:Backdoor.Win64.Havoc.pef |
MicroWorld-eScan | Generic.Trojan.Havokiz.Marte.D.3988198C |
Emsisoft | Generic.Trojan.Havokiz.Marte.D.3988198C (B) |
F-Secure | Heuristic.HEUR/AGEN.1376803 |
DrWeb | Trojan.Siggen29.14420 |
TrendMicro | TROJ_GEN.R002C0DJH24 |
McAfeeD | ti!C0F272047EEC |
CTX | dll.trojan.havoc |
Sophos | ATK/Havoc-G |
SentinelOne | Static AI - Malicious PE |
FireEye | Generic.Trojan.Havokiz.Marte.D.3988198C |
Detected | |
Avira | HEUR/AGEN.1376803 |
Kingsoft | Win64.Backdoor.Havoc.pef |
Gridinsoft | Trojan.Win64.Agent.sa |
Microsoft | Trojan:Win64/Havoc.AA!MTB |
ZoneAlarm | HEUR:Backdoor.Win64.Havoc.pef |
GData | Generic.Trojan.Havokiz.Marte.D.3988198C |
Varist | W64/ABTrojan.CVFU-3370 |
McAfee | Agent-FYC!60FEA8C8E969 |
DeepInstinct | MALICIOUS |
Malwarebytes | Trojan.Havoc |
Ikarus | Trojan.Win64.Havoc |
Panda | Trj/CI.A |
Tencent | Trojan.Win64.Havoc.16001250 |
huorong | Backdoor/Meterpreter.ey |
Fortinet | PossibleThreat.PALLAS.H |
AVG | Win64:Evo-gen [Trj] |
Paloalto | generic.ml |
alibabacloud | Backdoor:Win/Meterpreter.ey |