Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | April 21, 2025, 10:09 a.m. | April 21, 2025, 1:19 p.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_HttpAgent
2560 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_HttpClient
2728 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_HttpAgentListener
2644 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_HttpClientListener
2824 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_HttpServer
2920 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_HttpServerListener
3012 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_HttpSyncClient
908 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_HttpsAgent
192 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_HttpsClient
2248 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_HttpsServer
2500 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_HttpsSyncClient
2656 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_SSLAgent
2792 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_SSLClient
2936 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_SSLPackAgent
2904 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_SSLPackClient
2108 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_SSLPackServer
2212 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_SSLPullAgent
2612 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_SSLPullClient
2772 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_SSLPullServer
2952 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_SSLServer
2056 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_SocketTaskObj
2260 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_TcpAgent
2608 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_TcpAgentListener
2956 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_TcpClient
2124 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_TcpClientListener
2624 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_TcpPackAgent
2972 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_TcpPackAgentListener
2256 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_TcpPackClient
3008 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_TcpPackClientListener
744 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_TcpPackServer
2908 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_TcpPackServerListener
1400 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_TcpPullAgent
2940 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_TcpPullAgentListener
3076 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_TcpPullClient
3172 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_TcpPullClientListener
3264 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_TcpPullServer
3356 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_TcpPullServerListener
3448 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_TcpServer
3540 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_TcpServerListener
3632 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_ThreadPool
3724 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_UdpCast
3816 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_UdpCastListener
3912 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_UdpClient
4004 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_UdpClientListener
2840 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_UdpServer
3184 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Create_HP_UdpServerListener
3288 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_HttpAgent
3392 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_HttpAgentListener
3268 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_HttpClient
3620 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_HttpClientListener
3752 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_HttpServer
3708 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_HttpServerListener
3880 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_HttpSyncClient
2204 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_HttpsAgent
3280 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_HttpsClient
3252 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_HttpsServer
3580 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_HttpsSyncClient
3740 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_SSLAgent
3956 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_SSLClient
3116 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_SSLPackAgent
3300 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_SSLPackClient
3520 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_SSLPackServer
3856 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_SSLPullAgent
4056 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_SSLPullClient
3344 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_SSLPullServer
3452 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_SSLServer
3120 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_SocketTaskObj
4100 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_TcpAgent
4348 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_TcpAgentListener
4520 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_TcpClient
4716 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\HPSocket4C.dll,Destroy_HP_TcpClientListener
5000
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
185.39.17.70 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | D:\MyWork\Linux\MyWork\HP-Socket\Windows\Bin\HPSocket4C\x86\HPSocket4C.pdb |
name | RT_VERSION | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x001ac0a0 | size | 0x000002dc |
host | 185.39.17.70 |
Bkav | W32.AIDetectMalware |
Skyhigh | BehavesLike.Win32.Infected.th |
Elastic | malicious (moderate confidence) |
ESET-NOD32 | a variant of Win32/Packed.FlyStudio_AGen.AG potentially unwanted |
Avast | Win32:Malware-gen |
Alibaba | Trojan:Win32/Generic.cfee0137 |
Rising | Trojan.Agent!8.B1E (TFE:5:quIQS5beG2O) |
McAfeeD | ti!1B81D5E63F9D |
Sophos | Mal/Generic-S |
Webroot | W32.Adware.Gen |
Detected | |
Antiy-AVL | Trojan/Win32.Agent |
AhnLab-V3 | Malware/Win32.RL_Generic.R299471 |
McAfee | Artemis!5785700F701C |
DeepInstinct | MALICIOUS |
Malwarebytes | Ramnit.Virus.FileInfector.DDS |
Ikarus | Trojan.Win32.Agent |
Yandex | Trojan.GenAsa!SKQl05IfCYg |
MaxSecure | Trojan.Malware.219210455.susgen |
Fortinet | W32/Agent.TGJ!tr |
AVG | Win32:Malware-gen |