Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | April 30, 2025, 1:29 p.m. | April 30, 2025, 1:32 p.m. |
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\VCRUNTIME140.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\libssl-1_1.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tk86t.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\python311.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl86t.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\libcrypto-1_1.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\libffi-8.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\libcrypto-1_1.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\_decimal.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\select.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\libffi-8.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\_ssl.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\_socket.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\unicodedata.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl86t.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\python311.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tk86t.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\_uuid.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\_ctypes.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\VCRUNTIME140.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\_bz2.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\_hashlib.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\_queue.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\_lzma.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\_tkinter.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\libssl-1_1.dll |
section | {u'size_of_data': u'0x0000f600', u'virtual_address': u'0x00044000', u'entropy': 7.555532167563682, u'name': u'.rsrc', u'virtual_size': u'0x0000f494'} | entropy | 7.55553216756 | description | A section with a high entropy has been found | |||||||||
entropy | 0.222826086957 | description | Overall entropy of this PE file is high |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp852.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\koi8-r.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp862.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\euc-cn.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp950.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp1250.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\gb1988.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp863.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\gb12345.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\iso8859-4.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\iso2022-jp.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp861.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp1258.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\iso8859-1.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp855.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp737.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\euc-jp.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\ascii.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\macCentEuro.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\iso8859-10.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\macRomania.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp860.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp936.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\ksc5601.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\jis0201.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp1256.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp437.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\macDingbats.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\macCroatian.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\iso8859-15.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp864.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp775.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp850.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\macTurkish.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp949.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\iso8859-16.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\dingbats.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\iso2022-kr.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\symbol.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cns11643.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\macCyrillic.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\ebcdic.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\iso8859-5.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp1252.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp1253.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp869.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp874.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\iso8859-6.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\gb2312.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\iso2022.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\America\Belem |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\America\Manaus |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Africa\Lagos |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Antarctica\Mawson |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\US\Indiana-Starke |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tk\focus.tcl |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\America\Resolute |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\msgs\en_ie.msg |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Europe\London |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\msgs\it.msg |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\msgs\nl.msg |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Asia\Macao |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Asia\Aqtobe |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\America\Virgin |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Indian\Mahe |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\America\Paramaribo |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\America\Atikokan |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\America\Moncton |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Europe\Samara |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Europe\Kiev |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\msgs\te.msg |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\msgs\fr_ch.msg |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Pacific\Tahiti |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Turkey |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\cp949.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Australia\Melbourne |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tk\msgs\el.msg |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\America\Argentina\San_Juan |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Portugal |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Africa\Bangui |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\_queue.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Asia\Aqtau |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Pacific\Fakaofo |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\msgs\mk.msg |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\SystemV\MST7 |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Asia\Gaza |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\America\Rosario |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Europe\Chisinau |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Etc\GMT-2 |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tk\megawidget.tcl |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\America\St_Barthelemy |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\encoding\iso8859-13.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\EST5EDT |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Asia\Srednekolymsk |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Egypt |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\America\Dawson_Creek |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\America\Antigua |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\tzdata\Asia\Oral |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\base_library.zip |
file | C:\Users\test22\AppData\Local\Temp\_MEI1842\tcl\opt0.4\optparse.tcl |
Bkav | W32.AIDetectMalware |
Lionic | Trojan.Win32.Generic.4!c |
CAT-QuickHeal | Trojan.Ghanarava.17262270534ca352 |
Skyhigh | BehavesLike.Win32.Generic.vc |
Cylance | Unsafe |
Sangfor | Trojan.Win32.Save.a |
K7GW | Trojan ( 0059e2471 ) |
K7AntiVirus | Trojan ( 0059e2471 ) |
VirIT | Trojan.Win32.Genus.WHZ |
Symantec | ML.Attribute.HighConfidence |
Elastic | malicious (high confidence) |
APEX | Malicious |
Avast | FileRepMalware [Misc] |
Kaspersky | UDS:DangerousObject.Multi.Generic |
NANO-Antivirus | Trojan.Win32.Mlw.jzgfaj |
McAfeeD | ti!752DD7563038 |
CTX | exe.trojan.generic |
Sophos | Generic ML PUA (PUA) |
Jiangmin | Trojan.Blocker.vcn |
Webroot | W32.Trojan.Gen |
Detected | |
Antiy-AVL | Trojan/Win32.Wacatac |
Kingsoft | Win32.Troj.Unknown.a |
Xcitium | Malware@#3at0voxrx76nf |
Varist | W32/ABTrojan.MBGF-0789 |
McAfee | Artemis!FD2BAA8F4A91 |
DeepInstinct | MALICIOUS |
Malwarebytes | Agent.Spyware.Stealer.DDS |
Panda | Trj/Chgt.AD |
MaxSecure | Trojan.Malware.1728101.susgen |
Fortinet | W32/PossibleThreat |
AVG | FileRepMalware [Misc] |
Paloalto | generic.ml |