Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Nov. 8, 2024, 4:56 p.m. | Nov. 8, 2024, 5:08 p.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1
2644 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun0
2552 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun10
2732 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1001
2856 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1002
2964 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1003
3060 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1004
2124 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1005
2232 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1006
2436 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1007
2600 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1008
2820 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1009
2956 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1010
2056 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1011
2164 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1012
2548 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1013
2752 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1014
2764 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1015
908 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1016
2432 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1017
2696 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1018
3008 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1019
2076 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1020
2516 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1021
800 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1022
1384 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1023
2640 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1024
1336 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1025
2648 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1026
2504 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1027
2532 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1028
2920 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1029
2868 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1030
2948 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1031
3160 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1032
3252 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1033
3344 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1034
3460 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1035
3556 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1036
3644 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1037
3736 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1038
3836 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1039
3940 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1040
4032 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1041
3088 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1042
3220 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1043
3168 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1044
3476 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1045
3592 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1046
3712 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1047
3876 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1048
3972 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1049
2972 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1050
3944 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1051
3444 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1052
3608 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1053
3832 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1054
3932 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1055
3756 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1056
3384 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1057
3544 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1058
3796 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1059
3104 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1060
4084 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1061
3244 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1062
3924 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun1063
3200 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun11
2240 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun12
3844 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun13
3240 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\plugin.dll,fun15
3436
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x004ef288 | size | 0x00000134 | ||||||||||||||||||
name | RT_GROUP_CURSOR | language | LANG_CHINESE | filetype | Lotus unknown worksheet or configuration, revision 0x1 | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00508268 | size | 0x00000014 |
section | {u'size_of_data': u'0x0026ea00', u'virtual_address': u'0x00280000', u'entropy': 7.884903764752581, u'name': u'UPX1', u'virtual_size': u'0x0026f000'} | entropy | 7.88490376475 | description | A section with a high entropy has been found | |||||||||
entropy | 0.959175813595 | description | Overall entropy of this PE file is high |
section | UPX0 | description | Section name indicates UPX | ||||||
section | UPX1 | description | Section name indicates UPX |
buffer | Buffer with sha1: 8939cf35447b22dd2c6e6f443446acc1bf986d58 |
Lionic | Trojan.Multi.Generic.lmpu |
Skyhigh | Artemis!Trojan |
ALYac | Gen:Variant.Razy.597737 |
Cylance | Unsafe |
VIPRE | Gen:Variant.Razy.597737 |
BitDefender | Gen:Variant.Razy.597737 |
Arcabit | Trojan.Razy.D91EE9 |
Elastic | malicious (moderate confidence) |
ESET-NOD32 | a variant of Win32/FlyStudio.HackTool.C potentially unwanted |
Avast | Win32:Malware-gen |
MicroWorld-eScan | Gen:Variant.Razy.597737 |
Emsisoft | Gen:Variant.Razy.597737 (B) |
McAfeeD | ti!F0ECADC90EF7 |
CTX | dll.trojan.flystudio |
Sophos | Generic Reputation PUA (PUA) |
Ikarus | PUA.BlackMoon |
FireEye | Gen:Variant.Razy.597737 |
Antiy-AVL | RiskWare/Win32.FlyStudio.a |
GData | Win32.Trojan.PSE.1N7T5RZ |
AhnLab-V3 | Trojan/Win.Generic.C5570248 |
McAfee | Artemis!C306B71FA8F0 |
DeepInstinct | MALICIOUS |
VBA32 | BScope.Backdoor.BlackMoon |
Malwarebytes | Generic.Malware.AI.DDS |
MaxSecure | Trojan.Malware.74780839.susgen |
Fortinet | Riskware/FlyStudio_HackTool |
AVG | Win32:Malware-gen |
Paloalto | generic.ml |