| File name: | 2018-10-31-traffic-analysis-exercise.pcap |
| Full analysis: | https://app.any.run/tasks/1a305c59-9620-42a8-9dc3-edc667d0d3d4 |
| Verdict: | No threats detected |
| Analysis date: | April 08, 2020, 19:04:32 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MIME: | application/vnd.tcpdump.pcap |
| File info: | tcpdump capture file (little-endian) - version 2.4 (Ethernet, capture length 65535) |
| MD5: | 9FF981FFC424BF81E8F3E0C291ADA699 |
| SHA1: | F3008EB75FA223BA5C81CCB488482C99DCAF43B2 |
| SHA256: | 54D43F7C2F95AFEEBD61EB9BA9B247561A4E10267D515038B7569EFDC3FB79FD |
| SSDEEP: | 98304:VVo/UWqE/jE8HJdGxtwOlWeFC2AFUNq6BulD5/ORnWfJDsfsvIxp:/ocWFLzWcOJFC2Al5/EWxDAsa |
| .acp/pcap | | | TCPDUMP's style capture (100) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3828 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\2018-10-31-traffic-analysis-exercise.pcap | C:\Windows\system32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||