| File name: | 2016-08-16-Neutrino-EK.pcap |
| Full analysis: | https://app.any.run/tasks/495eba8a-d334-4bdd-9440-77355f7f94da |
| Verdict: | No threats detected |
| Analysis date: | December 10, 2018, 10:00:40 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MIME: | application/vnd.tcpdump.pcap |
| File info: | tcpdump capture file (little-endian) - version 2.4 (Ethernet, capture length 262144) |
| MD5: | C5C5240053BBA470B7BC86C382215635 |
| SHA1: | 00519FED7F801AC930B2ABD203A9F49BD4D8D6C2 |
| SHA256: | EF3D43B1233084423318FB01FA22DCC31E4AE2B316653020CC7361D936442034 |
| SSDEEP: | 6144:+w8d4Nv9RlkxPFIdcq8QkXOTTpudHsN1Idcq8QkxOevRozr5cIbqLXaIzWabtC+y:+i5oXyEsXNz8gR16gIt |
| .acp/pcap | | | TCPDUMP's style capture (100) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3012 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\2016-08-16-Neutrino-EK.pcap | C:\Windows\system32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||