Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | June 16, 2024, 9:53 a.m. | June 16, 2024, 10:17 a.m. |
-
%E9%98%B2%E5%8A%AB%E6%8C%811.0.exe "C:\Users\test22\AppData\Local\Temp\%E9%98%B2%E5%8A%AB%E6%8C%811.0.exe"
1680
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
packer | Armadillo v1.71 |
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0000b448 | size | 0x00000128 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0000b448 | size | 0x00000128 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0000b598 | size | 0x000001c6 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0000b570 | size | 0x00000022 |
file | C:\Users\test22\AppData\Local\Temp\31314376.dll |
cmdline | cmd.exe /c ping 127.0.0.1 -n 1 && del /f/q "C:\Users\test22\AppData\Local\Temp\%E9%98%B2%E5%8A%AB%E6%8C%811.0.exe" |
cmdline | "C:\Windows\System32\cmd.exe" /c ping 127.0.0.1 -n 1 && del /f/q "C:\Users\test22\AppData\Local\Temp\%E9%98%B2%E5%8A%AB%E6%8C%811.0.exe" |
file | C:\Users\test22\AppData\Local\Temp\31314376.dll |
file | C:\Users\test22\AppData\Local\Temp\%E9%98%B2%E5%8A%AB%E6%8C%811.0.exe |
cmdline | cmd.exe /c ping 127.0.0.1 -n 1 && del /f/q "C:\Users\test22\AppData\Local\Temp\%E9%98%B2%E5%8A%AB%E6%8C%811.0.exe" |
cmdline | "C:\Windows\System32\cmd.exe" /c ping 127.0.0.1 -n 1 && del /f/q "C:\Users\test22\AppData\Local\Temp\%E9%98%B2%E5%8A%AB%E6%8C%811.0.exe" |
cmdline | ping 127.0.0.1 -n 1 |
host | 142.250.66.129 | |||
host | 120.79.191.234 | |||
host | 216.58.203.78 |
service_name | Remocte1 | service_path | C:\Users\test22\AppData\Local\Temp\%SystemRoot%\System32\svchost.exe -k "Remocte1" | ||||||
reg_key | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Remocte1\Parameters\ServiceDll | reg_value | C:\Users\test22\AppData\Local\Temp\31314376.dll |