Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x3201 | March 17, 2021, 11:10 p.m. | March 17, 2021, 11:10 p.m. |
-
-
schtasks.exe "C:\Windows\System32\schtasks.exe" /CREATE /SC HOURLY /MO 1 /TN IntelTWO /TR C:\ProgramData\Intel\IntelTWO.exe /F
3520
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb |
section | .didat |
resource name | PNG |
file | C:\ProgramData\Intel\IntelTWO.exe |
cmdline | SCHTASKS /CREATE /SC HOURLY /MO 1 /TN IntelTWO /TR C:\ProgramData\Intel\IntelTWO.exe /F |
cmdline | "C:\Windows\System32\schtasks.exe" /CREATE /SC HOURLY /MO 1 /TN IntelTWO /TR C:\ProgramData\Intel\IntelTWO.exe /F |
description | Listen for incoming communication | rule | network_tcp_listen | ||||||
description | Affect system registries | rule | win_registry | ||||||
description | Affect system token | rule | win_token | ||||||
description | Affect private profile | rule | win_files_operation | ||||||
description | Match Winsock 2 API library declaration | rule | Str_Win32_Winsock2_Library | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
cmdline | SCHTASKS /CREATE /SC HOURLY /MO 1 /TN IntelTWO /TR C:\ProgramData\Intel\IntelTWO.exe /F |
cmdline | "C:\Windows\System32\schtasks.exe" /CREATE /SC HOURLY /MO 1 /TN IntelTWO /TR C:\ProgramData\Intel\IntelTWO.exe /F |
cmdline | SCHTASKS /CREATE /SC HOURLY /MO 1 /TN IntelTWO /TR C:\ProgramData\Intel\IntelTWO.exe /F |
cmdline | "C:\Windows\System32\schtasks.exe" /CREATE /SC HOURLY /MO 1 /TN IntelTWO /TR C:\ProgramData\Intel\IntelTWO.exe /F |
Bkav | W32.AIDetect.malware2 |
Elastic | malicious (high confidence) |
FireEye | Generic.mg.d2054b1b66e0d190 |
McAfee | Artemis!D2054B1B66E0 |
Zillya | Trojan.ScriptKD.JS.10 |
Sangfor | Trojan.Win32.Save.a |
CrowdStrike | win/malicious_confidence_80% (W) |
Cyren | W32/Trojan.REOR-6425 |
APEX | Malicious |
Avast | FileRepMalware |
Kaspersky | HEUR:Backdoor.Win32.Xaparo.gen |
Paloalto | generic.ml |
Sophos | ML/PE-A |
McAfee-GW-Edition | BehavesLike.Win32.Generic.jc |
SentinelOne | Static AI - Suspicious SFX |
Microsoft | Program:Win32/Wacapew.C!ml |
Cynet | Malicious (score: 100) |
Malwarebytes | Malware.Heuristic.1001 |
Rising | Trojan.TaskRun/SFX!1.D3EF (CLASSIC) |
AVG | FileRepMalware |
Qihoo-360 | Win32/Backdoor.Generic.HgIASQ8A |