Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Feb. 24, 2025, 12:03 p.m. | Feb. 24, 2025, 12:09 p.m. |
-
wmic.exe c:\QCpUhj\QCpU\..\..\Windows\QCpU\QCpU\..\..\system32\QCpU\QCpU\..\..\wbem\QCpU\QCpUh\..\..\wmic.exe shadowcopy delete
1216 -
wmic.exe c:\ZqQSua\ZqQS\..\..\Windows\ZqQS\ZqQS\..\..\system32\ZqQS\ZqQS\..\..\wbem\ZqQS\ZqQSu\..\..\wmic.exe shadowcopy delete
1376 -
cmd.exe cmd.exe /C ping 1.1.1.1 -n 1 -w 3000 > Nul & Del /f /q "C:\Users\test22\AppData\Local\Temp\Dpose.exe"
2424-
PING.EXE ping 1.1.1.1 -n 1 -w 3000
2076
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | Z:\scvhost\Release\scvhost.pdb |
cmdline | ping 1.1.1.1 -n 1 -w 3000 |
Bkav | W32.Common.2B42ED15 |
Lionic | Trojan.Win32.SPPk.j!c |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Generic.Malware.SPPk!2.CC79BBAB |
CAT-QuickHeal | Trojanransom.Generic |
Skyhigh | BehavesLike.Win32.Injector.ch |
ALYac | Generic.Malware.SPPk!2.CC79BBAB |
Cylance | Unsafe |
VIPRE | Generic.Malware.SPPk!2.CC79BBAB |
Sangfor | Trojan.Win32.Agent.Agz6 |
K7AntiVirus | Trojan ( 005bdbe71 ) |
BitDefender | Generic.Malware.SPPk!2.CC79BBAB |
K7GW | Trojan ( 005bdbe71 ) |
Arcabit | Generic.Malware.SPPk!2.CC79BBAB |
Symantec | ML.Attribute.HighConfidence |
ESET-NOD32 | a variant of Win32/Filecoder.ORR |
Avast | Win32:MalwareX-gen [Trj] |
Cynet | Malicious (score: 99) |
Kaspersky | HEUR:Trojan-Ransom.Win32.Generic |
Alibaba | Ransom:Win32/StopCrypt.6d3b7c88 |
NANO-Antivirus | Trojan.Win32.Encoder.kvqbvh |
SUPERAntiSpyware | PUP.Bundler/Variant |
Rising | Ransom.Stop!1.10761 (CLASSIC) |
Emsisoft | Generic.Malware.SPPk!2.CC79BBAB (B) |
F-Secure | Trojan.TR/AD.Nekark.dvyvl |
DrWeb | Trojan.Encoder.41670 |
McAfeeD | ti!1A4B61F07E83 |
Trapmine | suspicious.low.ml.score |
CTX | exe.trojan.generic |
Sophos | Troj/Ransom-HGH |
SentinelOne | Static AI - Suspicious PE |
FireEye | Generic.Malware.SPPk!2.CC79BBAB |
Jiangmin | AdWare.StartSurf.cwmd |
Detected | |
Avira | TR/AD.Nekark.dvyvl |
MAX | malware (ai score=86) |
Antiy-AVL | Trojan[Ransom]/Win32.StopCrypt |
Kingsoft | Win32.Trojan-Ransom.Generic.a |
Gridinsoft | Ransom.Win32.STOP.oa!s1 |
Microsoft | Ransom:Win32/StopCrypt.ASC!MTB |
ViRobot | Trojan.Win.Z.Stopcrypt.896512.W |
ZoneAlarm | UDS:DangerousObject.Multi.Generic |
GData | Generic.Malware.SPPk!2.CC79BBAB |
Varist | W32/Filecoder.JEKP-5583 |
AhnLab-V3 | Trojan/Win.Generic.R692586 |
McAfee | Artemis!331031DC04A8 |
DeepInstinct | MALICIOUS |
VBA32 | BScope.TrojanBanker.ChePro |
Malwarebytes | Ransom.Cactus |
Ikarus | Trojan-Ransom.FileCrypter |