Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | March 12, 2025, 11:25 a.m. | March 12, 2025, 11:32 a.m. |
-
-
uptime.exe "C:\Users\test22\AppData\Roaming\update\uptime.exe"
2616
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
135.125.189.140 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
description | uptime.exe tried to sleep 158 seconds, actually delayed analysis time by 158 seconds |
host | 135.125.189.140 |
reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ROA35Q-Y3LF93 | reg_value | "C:\Users\test22\AppData\Roaming\update\uptime.exe" | ||||||
reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ROA35Q-Y3LF93 | reg_value | "C:\Users\test22\AppData\Roaming\update\uptime.exe" |
Bkav | W32.AIDetectMalware |
Lionic | Trojan.Win32.Remcos.m!c |
Cynet | Malicious (score: 100) |
CAT-QuickHeal | Trojan.Ghanarava.17417137956d868b |
Skyhigh | BehavesLike.Win32.Remcos.gh |
ALYac | Generic.Dacic.A9349469.A.EE20628E |
Cylance | Unsafe |
VIPRE | Generic.Dacic.A9349469.A.EE20628E |
Sangfor | Trojan.Win32.Save.a |
CrowdStrike | win/malicious_confidence_100% (W) |
BitDefender | Generic.Dacic.A9349469.A.EE20628E |
K7GW | Trojan ( 0053ac2c1 ) |
K7AntiVirus | Trojan ( 0053ac2c1 ) |
Arcabit | Generic.Dacic.A9349469.A.EE20628E |
VirIT | Trojan.Win32.Remcos.DFP |
Symantec | ML.Attribute.HighConfidence |
Elastic | Windows.Trojan.Remcos |
ESET-NOD32 | a variant of Win32/Rescoms.B |
APEX | Malicious |
Avast | Win32:RATX-gen [Trj] |
ClamAV | Win.Trojan.Remcos-9841897-0 |
Kaspersky | HEUR:Backdoor.Win32.Remcos.gen |
Alibaba | Backdoor:Win32/Remcos.2cdafff9 |
NANO-Antivirus | Trojan.Win32.Remcos.kvsovm |
MicroWorld-eScan | Generic.Dacic.A9349469.A.EE20628E |
Rising | Backdoor.Remcos!1.BAC7 (CLASSIC) |
Emsisoft | Generic.Dacic.A9349469.A.EE20628E (B) |
F-Secure | Backdoor.BDS/Backdoor.Gen |
DrWeb | BackDoor.Remcos.491 |
Zillya | Trojan.Rescoms.Win32.2189 |
McAfeeD | Real Protect-LS!CF8C5DEBE04E |
CTX | exe.trojan.remcos |
Sophos | Mal/Remcos-B |
SentinelOne | Static AI - Malicious PE |
FireEye | Generic.mg.cf8c5debe04e96be |
Webroot | Win.Backdoor.Remcos |
Detected | |
Avira | BDS/Backdoor.Gen |
Antiy-AVL | GrayWare/Win32.Wacapew |
Kingsoft | malware.kb.a.1000 |
Gridinsoft | Trojan.Win32.Remcos.tr |
Microsoft | Backdoor:Win32/Remcos.GA!MTB |
ViRobot | Trojan.Win.Z.Remcos.498176.F |
ZoneAlarm | Mal/Remcos-B |
GData | Generic.Dacic.A9349469.A.EE20628E |
Varist | W32/Agent.JUB.gen!Eldorado |
AhnLab-V3 | Backdoor/Win.Remcos.R693720 |
McAfee | Artemis!CF8C5DEBE04E |
DeepInstinct | MALICIOUS |
Malwarebytes | Backdoor.Remcos |
dead_host | 192.168.56.101:49191 |
dead_host | 192.168.56.101:49171 |
dead_host | 192.168.56.101:49192 |
dead_host | 192.168.56.101:49202 |
dead_host | 192.168.56.101:49175 |
dead_host | 192.168.56.101:49196 |
dead_host | 192.168.56.101:49176 |
dead_host | 192.168.56.101:49184 |
dead_host | 135.125.189.140:1040 |
dead_host | 192.168.56.101:49162 |
dead_host | 192.168.56.101:49180 |
dead_host | 192.168.56.101:49193 |
dead_host | 192.168.56.101:49203 |
dead_host | 192.168.56.101:49188 |
dead_host | 192.168.56.101:49166 |
dead_host | 192.168.56.101:49168 |
dead_host | 192.168.56.101:49197 |
dead_host | 192.168.56.101:49177 |
dead_host | 192.168.56.101:49172 |
dead_host | 192.168.56.101:49185 |
dead_host | 192.168.56.101:49181 |
dead_host | 192.168.56.101:49194 |
dead_host | 192.168.56.101:49189 |
dead_host | 192.168.56.101:49167 |
dead_host | 192.168.56.101:49169 |
dead_host | 192.168.56.101:49198 |
dead_host | 192.168.56.101:49200 |
dead_host | 192.168.56.101:49178 |
dead_host | 192.168.56.101:49173 |
dead_host | 192.168.56.101:49186 |
dead_host | 192.168.56.101:49204 |
dead_host | 192.168.56.101:49182 |
dead_host | 192.168.56.101:49195 |
dead_host | 192.168.56.101:49190 |
dead_host | 192.168.56.101:49170 |
dead_host | 192.168.56.101:49199 |
dead_host | 192.168.56.101:49201 |
dead_host | 192.168.56.101:49179 |
dead_host | 192.168.56.101:49164 |
dead_host | 192.168.56.101:49174 |
dead_host | 192.168.56.101:49187 |
dead_host | 192.168.56.101:49183 |