Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | April 8, 2025, 5:16 a.m. | April 8, 2025, 5:18 a.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,AppsrvSysPrepSpecializeOffline
2632-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,AppsrvSysPrepSpecializeOffline
2976
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,AppsrvSysPrepGeneralize
2548-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,AppsrvSysPrepGeneralize
2984
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,AppsrvSysPrepSpecializeOnline
2724-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,AppsrvSysPrepSpecializeOnline
1120
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,CBrokerSysPrepGeneralize
2812-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,CBrokerSysPrepGeneralize
1400
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,CBrokerSysPrepSpecializeOffline
2908-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,CBrokerSysPrepSpecializeOffline
2464
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,CBrokerSysPrepSpecializeOnline
2052-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,CBrokerSysPrepSpecializeOnline
2504
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,LSMSysPrepBackup
196-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,LSMSysPrepBackup
2540
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,LSMSysPrepRestoreOffline
2436-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,LSMSysPrepRestoreOffline
2892
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,LSMSysPrepRestoreOnline
2792-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,LSMSysPrepRestoreOnline
2088
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,RCMSysPrepGeneralize
2068-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,RCMSysPrepGeneralize
2720
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,RdpSysPrepGeneralize
2616-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,RdpSysPrepGeneralize
2232
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,RdpSysPrepRestoreOffline
2836-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,RdpSysPrepRestoreOffline
2860
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,RdpSysPrepRestoreOnline
3032-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,RdpSysPrepRestoreOnline
2416
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\tssysprep.dll,
2772
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | TSSysprep.pdb |
section | fothk |