Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | March 17, 2021, 11:12 p.m. | March 17, 2021, 11:13 p.m. |
-
-
schtasks.exe "C:\Windows\System32\schtasks.exe" /CREATE /SC HOURLY /MO 1 /TN IntelONE /TR C:\ProgramData\Intel\IntelONE.exe /F
4892
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb |
section | .didat |
resource name | PNG |
file | C:\ProgramData\Intel\IntelONE.exe |
cmdline | "C:\Windows\System32\schtasks.exe" /CREATE /SC HOURLY /MO 1 /TN IntelONE /TR C:\ProgramData\Intel\IntelONE.exe /F |
cmdline | SCHTASKS /CREATE /SC HOURLY /MO 1 /TN IntelONE /TR C:\ProgramData\Intel\IntelONE.exe /F |
description | Listen for incoming communication | rule | network_tcp_listen | ||||||
description | Affect system registries | rule | win_registry | ||||||
description | Affect system token | rule | win_token | ||||||
description | Affect private profile | rule | win_files_operation | ||||||
description | Match Winsock 2 API library declaration | rule | Str_Win32_Winsock2_Library | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
cmdline | "C:\Windows\System32\schtasks.exe" /CREATE /SC HOURLY /MO 1 /TN IntelONE /TR C:\ProgramData\Intel\IntelONE.exe /F |
cmdline | SCHTASKS /CREATE /SC HOURLY /MO 1 /TN IntelONE /TR C:\ProgramData\Intel\IntelONE.exe /F |
cmdline | "C:\Windows\System32\schtasks.exe" /CREATE /SC HOURLY /MO 1 /TN IntelONE /TR C:\ProgramData\Intel\IntelONE.exe /F |
cmdline | SCHTASKS /CREATE /SC HOURLY /MO 1 /TN IntelONE /TR C:\ProgramData\Intel\IntelONE.exe /F |
Bkav | W32.AIDetect.malware2 |
Elastic | malicious (high confidence) |
FireEye | Generic.mg.8e2288bfb74d2422 |
McAfee | Artemis!8E2288BFB74D |
Zillya | Trojan.ScriptKD.JS.10 |
Sangfor | Trojan.Win32.Save.a |
CrowdStrike | win/malicious_confidence_60% (W) |
Cyren | W32/Trojan.REOR-6425 |
APEX | Malicious |
Avast | FileRepMalware |
Kaspersky | HEUR:Backdoor.Win32.Xaparo.gen |
Paloalto | generic.ml |
McAfee-GW-Edition | BehavesLike.Win32.Generic.jc |
Sophos | ML/PE-A |
Microsoft | Program:Win32/Wacapew.C!ml |
Cynet | Malicious (score: 100) |
Malwarebytes | Malware.Heuristic.1001 |
Rising | Trojan.TaskRun/SFX!1.D3EF (CLASSIC) |
AVG | FileRepMalware |