Program did not start
MALICIOUS | SUSPICIOUS | INFO |
---|---|---|
Changes the autorun value in the registry
|
Application launched itself
|
Loads main object executable
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0001536E | 0x00015400 | IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ | 6.4151 |
.data | 0x00017000 | 0x0001F998 | 0x00000A00 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 7.00811 |
.rsrc | 0x00037000 | 0x000002A8 | 0x00000400 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 2.17084 |
.reloc | 0x00038000 | 0x000000F0 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ | 0.984884 |
Click at the process to see the details.
Image |
---|
c:\windows\system32\rundll32.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\imagehlp.dll |
c:\windows\system32\apphelp.dll |
c:\windows\apppatch\aclayers.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\userenv.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\winspool.drv |
c:\windows\system32\mpr.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\users\admin\appdata\local\temp\1.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
Image |
---|
c:\windows\system32\rundll32.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\imagehlp.dll |
c:\windows\system32\apphelp.dll |
c:\windows\apppatch\aclayers.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\userenv.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\winspool.drv |
c:\windows\system32\mpr.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\users\admin\appdata\roaming\rjzjnzkex.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\netapi32.dll |
c:\windows\system32\netutils.dll |
c:\windows\system32\srvcli.dll |
c:\windows\system32\wkscli.dll |
c:\windows\system32\wininet.dll |
c:\windows\system32\urlmon.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\iertutil.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\cscapi.dll |
c:\windows\system32\mswsock.dll |
c:\windows\system32\wshtcpip.dll |
c:\windows\system32\nlaapi.dll |
c:\windows\system32\napinsp.dll |
c:\windows\system32\pnrpnsp.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\winrnr.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\ntmarta.dll |
c:\windows\system32\wldap32.dll |
c:\windows\system32\normaliz.dll |
c:\windows\system32\rasapi32.dll |
c:\windows\system32\rasman.dll |
c:\windows\system32\rtutils.dll |
c:\windows\system32\sensapi.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\rasadhlp.dll |
c:\windows\system32\version.dll |
c:\windows\system32\wship6.dll |
c:\windows\system32\fwpuclnt.dll |
Image |
---|
c:\windows\system32\rundll32.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\imagehlp.dll |
c:\windows\system32\apphelp.dll |
c:\windows\apppatch\aclayers.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\userenv.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\winspool.drv |
c:\windows\system32\mpr.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\users\admin\appdata\roaming\tdmkgxa.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\netapi32.dll |
c:\windows\system32\netutils.dll |
c:\windows\system32\srvcli.dll |
c:\windows\system32\wkscli.dll |
c:\windows\system32\wininet.dll |
c:\windows\system32\urlmon.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\iertutil.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\nsi.dll |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2536 | rundll32.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/json | unknown |
text
|
|
shared |
PID | Process | IP | ASN | CN | Reputation |
---|---|---|---|---|---|
2536 | rundll32.exe | 208.95.112.1:80 | IBURST | –– | malicious |
2536 | rundll32.exe | 194.68.27.38:443 | EDIS GmbH | AT | malicious |
Domain | IP | Reputation |
---|---|---|
jp-microsoft-store.com | 194.68.27.38
|
malicious |
ip-api.com | 208.95.112.1
|
shared |
PID | Process | Class | Message |
---|---|---|---|
2536 | rundll32.exe | A Network Trojan was detected | MALWARE [PTsecurity] SDBbot |
2536 | rundll32.exe | Potential Corporate Privacy Violation | ET POLICY External IP Lookup ip-api.com |
2536 | rundll32.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
No debug info.