Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Jan. 25, 2025, 7:29 a.m. | Jan. 25, 2025, 7:31 a.m. |
-
control.exe "C:\Windows\System32\control.exe" C:\Users\test22\AppData\Local\Temp\krankenhous.exe
2540-
rundll32.exe "C:\Windows\system32\rundll32.exe" Shell32.dll,Control_RunDLL C:\Users\test22\AppData\Local\Temp\krankenhous.exe
2604-
rundll32.exe C:\Windows\system32\RunDll32.exe Shell32.dll,Control_RunDLL C:\Users\test22\AppData\Local\Temp\krankenhous.exe
2648-
rundll32.exe "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\shell32.dll",#44 C:\Users\test22\AppData\Local\Temp\krankenhous.exe
2728
-
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | {u'size_of_data': u'0x0000b000', u'virtual_address': u'0x00001000', u'entropy': 7.027931042494147, u'name': u'.text', u'virtual_size': u'0x0000a966'} | entropy | 7.02793104249 | description | A section with a high entropy has been found | |||||||||
entropy | 0.647058823529 | description | Overall entropy of this PE file is high |
Bkav | W32.FamVT.RorenNHc.Trojan |
Lionic | Trojan.Win32.Swrort.4!c |
Cynet | Malicious (score: 100) |
CAT-QuickHeal | Trojan.Swrort.A |
Skyhigh | BehavesLike.Win32.Swrort.lh |
ALYac | Trojan.CryptZ.Marte.1.Gen |
Cylance | Unsafe |
VIPRE | Trojan.CryptZ.Marte.1.Gen |
Sangfor | Trojan.Win32.Save.a |
CrowdStrike | win/malicious_confidence_100% (W) |
BitDefender | Trojan.CryptZ.Marte.1.Gen |
K7GW | Trojan ( 001172b51 ) |
K7AntiVirus | Trojan ( 001172b51 ) |
Arcabit | Trojan.CryptZ.Marte.1.Gen |
VirIT | Trojan.Win32.Rozena.AA |
Symantec | Packed.Generic.347 |
Elastic | Windows.Trojan.Metasploit |
ESET-NOD32 | a variant of Win32/Rozena.AA |
APEX | Malicious |
Avast | Win32:Meterpreter-C [Trj] |
ClamAV | Win.Trojan.Swrort-5710536-0 |
Kaspersky | HEUR:Trojan.Win32.Generic |
Alibaba | Trojan:Win32/CobaltStrike.5c89 |
NANO-Antivirus | Virus.Win32.Gen-Crypt.ccnc |
SUPERAntiSpyware | Trojan.Backdoor-Shell |
MicroWorld-eScan | Trojan.CryptZ.Marte.1.Gen |
Rising | HackTool.Swrort!1.6477 (CLASSIC) |
Emsisoft | Trojan.CryptZ.Marte.1.Gen (B) |
F-Secure | Trojan.TR/Patched.Gen2 |
Zillya | Trojan.RozenaGen.Win32.2 |
TrendMicro | Backdoor.Win32.COBEACON.SMJMAC |
McAfeeD | Real Protect-LS!5EC6CD34CF91 |
Trapmine | malicious.high.ml.score |
CTX | exe.trojan.swrort |
Sophos | Mal/EncPk-ACE |
SentinelOne | Static AI - Malicious PE |
FireEye | Generic.mg.5ec6cd34cf91f731 |
Webroot | W32.Malware.Gen |
Detected | |
Avira | TR/Patched.Gen2 |
Antiy-AVL | GrayWare/Win32.Tampering.a |
Kingsoft | malware.kb.a.1000 |
Gridinsoft | Trojan.Win32.Swrort.zv!s2 |
Xcitium | TrojWare.Win32.Rozena.A@4jwdqr |
Microsoft | Trojan:Win32/Meterpreter.O |
ViRobot | Trojan.Win32.Elzob.Gen |
GData | Win32.Backdoor.Swrort.C |
Varist | W32/Swrort.A.gen!Eldorado |
AhnLab-V3 | Trojan/Win32.Shell.R1283 |
Acronis | suspicious |