Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Jan. 8, 2025, 1:41 p.m. | Jan. 8, 2025, 1:45 p.m. |
-
wmic.exe c:\WluFed\WluF\..\..\Windows\WluF\WluF\..\..\system32\WluF\WluF\..\..\wbem\WluF\WluFe\..\..\wmic.exe shadowcopy delete
2476 -
wmic.exe c:\iGqzlL\iGqz\..\..\Windows\iGqz\iGqz\..\..\system32\iGqz\iGqz\..\..\wbem\iGqz\iGqzl\..\..\wmic.exe shadowcopy delete
1664 -
cmd.exe cmd.exe /C ping 1.1.1.1 -n 1 -w 3000 > Nul & Del /f /q "C:\Users\test22\AppData\Local\Temp\Crawl.exe"
2556-
PING.EXE ping 1.1.1.1 -n 1 -w 3000
3068
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | Z:\scvhost\Release\scvhost.pdb |
cmdline | ping 1.1.1.1 -n 1 -w 3000 |
Lionic | Trojan.Win32.Generic.j!c |
MicroWorld-eScan | Trojan.GenericKD.75307398 |
CAT-QuickHeal | Trojan.Ghanarava.1736279327da88bb |
Skyhigh | BehavesLike.Win32.Injector.ch |
Cylance | Unsafe |
VIPRE | Gen:Heur.Ransom.REntS.Gen.1 |
Sangfor | Ransom.Win32.Filecoder.Ve48 |
CrowdStrike | win/malicious_confidence_70% (W) |
BitDefender | Trojan.GenericKD.75307398 |
Arcabit | Trojan.Generic.D47D1986 |
Symantec | ML.Attribute.HighConfidence |
Elastic | malicious (high confidence) |
ESET-NOD32 | a variant of Win32/Filecoder.ORR |
Avast | Win32:Evo-gen [Trj] |
Cynet | Malicious (score: 99) |
Kaspersky | HEUR:Trojan-Ransom.Win32.Generic |
Alibaba | Ransom:Win32/Filecoder.6b0f21d2 |
Rising | Ransom.Stop!1.10761 (CLASSIC) |
Emsisoft | Trojan.GenericKD.75307398 (B) |
F-Secure | Trojan.TR/AD.Nekark.tbmqs |
McAfeeD | ti!066DC9A1134B |
Trapmine | suspicious.low.ml.score |
CTX | exe.trojan.filecoder |
Sophos | Mal/Generic-S |
SentinelOne | Static AI - Suspicious PE |
FireEye | Trojan.GenericKD.75307398 |
Jiangmin | Trojan.Zudochka.di |
Detected | |
Avira | TR/AD.Nekark.tbmqs |
Antiy-AVL | GrayWare/Win32.Wacapew |
Kingsoft | Win32.Trojan-Ransom.Generic.a |
Gridinsoft | Ransom.Win32.STOP.sa |
Microsoft | Ransom:Win32/Genasom |
GData | Trojan.GenericKD.75307398 |
Varist | W32/Filecoder.DYZK-1348 |
AhnLab-V3 | Trojan/Win.Generic.C5714952 |
McAfee | Artemis!2D2C7EE748D9 |
DeepInstinct | MALICIOUS |
VBA32 | BScope.TrojanBanker.ChePro |
Malwarebytes | Ransom.Cactus |
Ikarus | Trojan-Ransom.FileCrypter |
TrendMicro-HouseCall | TROJ_GEN.R002H09A725 |
Tencent | Win32.Trojan.Filecoder.Qzfl |
huorong | Ransom/LockFile.nb |
Fortinet | W32/Filecoder.ORR!tr |
AVG | Win32:Evo-gen [Trj] |
alibabacloud | Ransomware:Win/Wacapew.C9nj |