C:\Users\user\Desktop\SecuriteInfo.com.Trojan.MulDrop28.4265.9101.29722.exe
|
"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.MulDrop28.4265.9101.29722.exe"
|
|
|
Is windows: |
false
|
Is dropped: |
false
|
PID: |
7348
|
Target ID: |
0
|
Parent PID: |
2580
|
Name: |
SecuriteInfo.com.Trojan.MulDrop28.4265.9101.29722.exe
|
Path: |
C:\Users\user\Desktop\SecuriteInfo.com.Trojan.MulDrop28.4265.9101.29722.exe
|
Commandline: |
"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.MulDrop28.4265.9101.29722.exe"
|
Size: |
29696
|
MD5: |
71709092617EEA0ABF55C872E0B41257
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
low
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff730c90000
|
Modulesize: |
49152
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Sigma detected: CurrentVersion Autorun Keys Modification |
System Summary |
|
PE file has an executable .text section and no other executable section |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
Spawns processes |
System Summary |
|
PE file contains a valid data directory to section mapping |
System Summary |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
PE file contains a debug data directory |
System Summary |
|
Contains modern PE file flags such as dynamic base (ASLR) or NX |
Compliance, System Summary |
|
PE file contains a mix of data directories often seen in goodware |
System Summary |
|
PE file has a high image base, often used for DLLs |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7356
|
Target ID: |
1
|
Parent PID: |
7348
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
high
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /c c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7400
|
Target ID: |
2
|
Parent PID: |
7348
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /c c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
high
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7416
|
Target ID: |
3
|
Parent PID: |
7400
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
high
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7424
|
Target ID: |
4
|
Parent PID: |
7416
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
high
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7432
|
Target ID: |
5
|
Parent PID: |
7400
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
high
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7440
|
Target ID: |
6
|
Parent PID: |
7432
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
high
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7492
|
Target ID: |
7
|
Parent PID: |
7400
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
high
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7520
|
Target ID: |
8
|
Parent PID: |
7416
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7528
|
Target ID: |
9
|
Parent PID: |
7492
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7536
|
Target ID: |
10
|
Parent PID: |
7520
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7544
|
Target ID: |
11
|
Parent PID: |
7400
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7552
|
Target ID: |
12
|
Parent PID: |
7416
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7572
|
Target ID: |
13
|
Parent PID: |
7544
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7588
|
Target ID: |
14
|
Parent PID: |
7400
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7600
|
Target ID: |
15
|
Parent PID: |
7552
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7608
|
Target ID: |
16
|
Parent PID: |
7416
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7628
|
Target ID: |
17
|
Parent PID: |
7588
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7644
|
Target ID: |
18
|
Parent PID: |
7432
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:06
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7688
|
Target ID: |
19
|
Parent PID: |
7644
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7696
|
Target ID: |
20
|
Parent PID: |
7608
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7800
|
Target ID: |
21
|
Parent PID: |
7544
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7812
|
Target ID: |
22
|
Parent PID: |
7544
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7820
|
Target ID: |
23
|
Parent PID: |
7800
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7832
|
Target ID: |
24
|
Parent PID: |
7544
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7840
|
Target ID: |
25
|
Parent PID: |
7544
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7852
|
Target ID: |
26
|
Parent PID: |
7544
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7860
|
Target ID: |
27
|
Parent PID: |
7544
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7868
|
Target ID: |
28
|
Parent PID: |
7812
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7880
|
Target ID: |
29
|
Parent PID: |
7832
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7892
|
Target ID: |
30
|
Parent PID: |
7544
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7900
|
Target ID: |
31
|
Parent PID: |
7544
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7908
|
Target ID: |
32
|
Parent PID: |
7840
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7920
|
Target ID: |
33
|
Parent PID: |
7852
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7932
|
Target ID: |
34
|
Parent PID: |
7860
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7940
|
Target ID: |
35
|
Parent PID: |
7544
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7956
|
Target ID: |
36
|
Parent PID: |
7892
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7964
|
Target ID: |
37
|
Parent PID: |
7900
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7972
|
Target ID: |
38
|
Parent PID: |
7544
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7996
|
Target ID: |
39
|
Parent PID: |
7544
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8012
|
Target ID: |
40
|
Parent PID: |
7544
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8052
|
Target ID: |
41
|
Parent PID: |
7972
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8084
|
Target ID: |
42
|
Parent PID: |
7940
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8092
|
Target ID: |
43
|
Parent PID: |
7996
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8112
|
Target ID: |
44
|
Parent PID: |
8012
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:07
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
6580
|
Target ID: |
45
|
Parent PID: |
7588
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:08
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
5776
|
Target ID: |
46
|
Parent PID: |
7552
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:08
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
2568
|
Target ID: |
47
|
Parent PID: |
7800
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:08
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
2520
|
Target ID: |
48
|
Parent PID: |
7588
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:08
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
2676
|
Target ID: |
49
|
Parent PID: |
7520
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:08
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
2484
|
Target ID: |
50
|
Parent PID: |
7800
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:08
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7244
|
Target ID: |
51
|
Parent PID: |
7644
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:08
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
2516
|
Target ID: |
52
|
Parent PID: |
6580
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:08
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
1908
|
Target ID: |
53
|
Parent PID: |
7800
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:08
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
5796
|
Target ID: |
54
|
Parent PID: |
5776
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:08
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
5460
|
Target ID: |
55
|
Parent PID: |
2484
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:08
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
5468
|
Target ID: |
56
|
Parent PID: |
7244
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:08
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
6892
|
Target ID: |
57
|
Parent PID: |
1908
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:08
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7236
|
Target ID: |
58
|
Parent PID: |
2568
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:08
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7368
|
Target ID: |
59
|
Parent PID: |
2520
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:08
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7540
|
Target ID: |
60
|
Parent PID: |
7432
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:08
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7632
|
Target ID: |
61
|
Parent PID: |
2676
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:08
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7968
|
Target ID: |
62
|
Parent PID: |
7540
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:09
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8368
|
Target ID: |
63
|
Parent PID: |
7492
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8376
|
Target ID: |
64
|
Parent PID: |
7400
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8408
|
Target ID: |
65
|
Parent PID: |
8376
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8424
|
Target ID: |
66
|
Parent PID: |
8368
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8432
|
Target ID: |
67
|
Parent PID: |
7492
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8476
|
Target ID: |
68
|
Parent PID: |
8432
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8492
|
Target ID: |
69
|
Parent PID: |
7416
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8500
|
Target ID: |
70
|
Parent PID: |
7996
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8516
|
Target ID: |
71
|
Parent PID: |
8492
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8528
|
Target ID: |
72
|
Parent PID: |
8500
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8556
|
Target ID: |
73
|
Parent PID: |
7520
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8584
|
Target ID: |
74
|
Parent PID: |
8376
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8592
|
Target ID: |
75
|
Parent PID: |
7520
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8600
|
Target ID: |
76
|
Parent PID: |
8556
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8608
|
Target ID: |
77
|
Parent PID: |
7520
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8616
|
Target ID: |
78
|
Parent PID: |
7852
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8632
|
Target ID: |
79
|
Parent PID: |
7608
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8648
|
Target ID: |
80
|
Parent PID: |
8584
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8656
|
Target ID: |
81
|
Parent PID: |
8592
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:10
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8684
|
Target ID: |
82
|
Parent PID: |
8616
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:11
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8692
|
Target ID: |
83
|
Parent PID: |
8632
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:11
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8720
|
Target ID: |
84
|
Parent PID: |
8608
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:11
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8744
|
Target ID: |
85
|
Parent PID: |
5776
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:11
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8808
|
Target ID: |
86
|
Parent PID: |
8744
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:11
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8824
|
Target ID: |
87
|
Parent PID: |
7972
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:11
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8872
|
Target ID: |
88
|
Parent PID: |
8824
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:11
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8888
|
Target ID: |
89
|
Parent PID: |
7544
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:11
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8908
|
Target ID: |
90
|
Parent PID: |
8888
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:11
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8924
|
Target ID: |
91
|
Parent PID: |
2484
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:11
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8960
|
Target ID: |
92
|
Parent PID: |
8924
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:11
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8976
|
Target ID: |
93
|
Parent PID: |
7832
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8992
|
Target ID: |
94
|
Parent PID: |
6580
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9000
|
Target ID: |
95
|
Parent PID: |
1908
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9008
|
Target ID: |
96
|
Parent PID: |
2568
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9036
|
Target ID: |
97
|
Parent PID: |
8976
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9056
|
Target ID: |
98
|
Parent PID: |
7244
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9096
|
Target ID: |
99
|
Parent PID: |
7996
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9124
|
Target ID: |
100
|
Parent PID: |
8012
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9132
|
Target ID: |
101
|
Parent PID: |
7840
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9140
|
Target ID: |
102
|
Parent PID: |
8992
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9148
|
Target ID: |
103
|
Parent PID: |
6580
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9156
|
Target ID: |
104
|
Parent PID: |
9000
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9164
|
Target ID: |
105
|
Parent PID: |
9008
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9176
|
Target ID: |
106
|
Parent PID: |
9056
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9188
|
Target ID: |
107
|
Parent PID: |
9096
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9212
|
Target ID: |
108
|
Parent PID: |
7812
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7364
|
Target ID: |
109
|
Parent PID: |
7860
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8428
|
Target ID: |
110
|
Parent PID: |
8888
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8532
|
Target ID: |
111
|
Parent PID: |
2520
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8688
|
Target ID: |
112
|
Parent PID: |
7552
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8724
|
Target ID: |
113
|
Parent PID: |
7588
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
1196
|
Target ID: |
114
|
Parent PID: |
7800
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
6680
|
Target ID: |
115
|
Parent PID: |
9132
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
6888
|
Target ID: |
116
|
Parent PID: |
7900
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
6312
|
Target ID: |
117
|
Parent PID: |
9148
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
2080
|
Target ID: |
118
|
Parent PID: |
7364
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
1260
|
Target ID: |
119
|
Parent PID: |
7892
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8964
|
Target ID: |
120
|
Parent PID: |
9124
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
8672
|
Target ID: |
121
|
Parent PID: |
8428
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9228
|
Target ID: |
122
|
Parent PID: |
8688
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9240
|
Target ID: |
123
|
Parent PID: |
8724
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9260
|
Target ID: |
124
|
Parent PID: |
1196
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9284
|
Target ID: |
125
|
Parent PID: |
6888
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9300
|
Target ID: |
126
|
Parent PID: |
7644
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9316
|
Target ID: |
127
|
Parent PID: |
9212
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9324
|
Target ID: |
128
|
Parent PID: |
8532
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9348
|
Target ID: |
129
|
Parent PID: |
1260
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9404
|
Target ID: |
130
|
Parent PID: |
7432
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9464
|
Target ID: |
131
|
Parent PID: |
7940
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9484
|
Target ID: |
132
|
Parent PID: |
9300
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9532
|
Target ID: |
133
|
Parent PID: |
9404
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:12
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9648
|
Target ID: |
134
|
Parent PID: |
7400
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:13
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9672
|
Target ID: |
135
|
Parent PID: |
9464
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:13
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9728
|
Target ID: |
136
|
Parent PID: |
2676
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:13
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9780
|
Target ID: |
137
|
Parent PID: |
9648
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:13
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9788
|
Target ID: |
138
|
Parent PID: |
9728
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:13
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9796
|
Target ID: |
139
|
Parent PID: |
7540
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:13
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9832
|
Target ID: |
140
|
Parent PID: |
9796
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:14
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9840
|
Target ID: |
141
|
Parent PID: |
8432
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:14
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9856
|
Target ID: |
142
|
Parent PID: |
8824
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:14
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9900
|
Target ID: |
143
|
Parent PID: |
9840
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:14
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9908
|
Target ID: |
144
|
Parent PID: |
7492
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:14
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9924
|
Target ID: |
145
|
Parent PID: |
9856
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:14
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9952
|
Target ID: |
146
|
Parent PID: |
9908
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:14
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10144
|
Target ID: |
147
|
Parent PID: |
8368
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:15
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10220
|
Target ID: |
148
|
Parent PID: |
10144
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:15
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9264
|
Target ID: |
149
|
Parent PID: |
7608
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:15
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9220
|
Target ID: |
150
|
Parent PID: |
7416
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:15
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9328
|
Target ID: |
151
|
Parent PID: |
8500
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:15
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
4476
|
Target ID: |
152
|
Parent PID: |
9328
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:15
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9836
|
Target ID: |
153
|
Parent PID: |
9220
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:15
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9904
|
Target ID: |
154
|
Parent PID: |
9264
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:15
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
9928
|
Target ID: |
155
|
Parent PID: |
7608
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:15
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10248
|
Target ID: |
156
|
Parent PID: |
9928
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:15
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10264
|
Target ID: |
157
|
Parent PID: |
9132
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:15
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10272
|
Target ID: |
158
|
Parent PID: |
8376
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:15
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10284
|
Target ID: |
159
|
Parent PID: |
8492
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:16
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10308
|
Target ID: |
160
|
Parent PID: |
10264
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:16
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10316
|
Target ID: |
161
|
Parent PID: |
10272
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:16
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10324
|
Target ID: |
162
|
Parent PID: |
7852
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:16
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10332
|
Target ID: |
163
|
Parent PID: |
7520
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:16
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10376
|
Target ID: |
164
|
Parent PID: |
5776
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:16
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10384
|
Target ID: |
165
|
Parent PID: |
10284
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:16
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10392
|
Target ID: |
166
|
Parent PID: |
10324
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:16
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10400
|
Target ID: |
167
|
Parent PID: |
10332
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:16
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10440
|
Target ID: |
168
|
Parent PID: |
8592
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:16
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10452
|
Target ID: |
169
|
Parent PID: |
10376
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:16
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10476
|
Target ID: |
170
|
Parent PID: |
7972
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:16
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10524
|
Target ID: |
171
|
Parent PID: |
10476
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10548
|
Target ID: |
172
|
Parent PID: |
10440
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10572
|
Target ID: |
173
|
Parent PID: |
8584
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10580
|
Target ID: |
174
|
Parent PID: |
8632
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10588
|
Target ID: |
175
|
Parent PID: |
7544
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10596
|
Target ID: |
176
|
Parent PID: |
8616
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10604
|
Target ID: |
177
|
Parent PID: |
8556
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10616
|
Target ID: |
178
|
Parent PID: |
10580
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10632
|
Target ID: |
179
|
Parent PID: |
10572
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10648
|
Target ID: |
180
|
Parent PID: |
8608
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10692
|
Target ID: |
181
|
Parent PID: |
10596
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10700
|
Target ID: |
182
|
Parent PID: |
10648
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10732
|
Target ID: |
183
|
Parent PID: |
8532
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10740
|
Target ID: |
184
|
Parent PID: |
8924
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10748
|
Target ID: |
185
|
Parent PID: |
8744
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10756
|
Target ID: |
186
|
Parent PID: |
2484
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10768
|
Target ID: |
187
|
Parent PID: |
10604
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10780
|
Target ID: |
188
|
Parent PID: |
8556
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10812
|
Target ID: |
189
|
Parent PID: |
10588
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10828
|
Target ID: |
190
|
Parent PID: |
10732
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10836
|
Target ID: |
191
|
Parent PID: |
10740
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10844
|
Target ID: |
192
|
Parent PID: |
10756
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10860
|
Target ID: |
193
|
Parent PID: |
10780
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:17
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10912
|
Target ID: |
194
|
Parent PID: |
10748
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:18
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10944
|
Target ID: |
195
|
Parent PID: |
7832
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:18
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11084
|
Target ID: |
196
|
Parent PID: |
2568
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:18
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11100
|
Target ID: |
197
|
Parent PID: |
7244
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:18
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11108
|
Target ID: |
198
|
Parent PID: |
7996
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:18
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11120
|
Target ID: |
199
|
Parent PID: |
1908
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:18
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11128
|
Target ID: |
200
|
Parent PID: |
10944
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:18
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11140
|
Target ID: |
201
|
Parent PID: |
11084
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:18
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11176
|
Target ID: |
202
|
Parent PID: |
9096
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:18
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11184
|
Target ID: |
203
|
Parent PID: |
11100
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:18
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11192
|
Target ID: |
204
|
Parent PID: |
11176
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:18
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11208
|
Target ID: |
205
|
Parent PID: |
8976
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:18
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11216
|
Target ID: |
206
|
Parent PID: |
8012
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:18
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11224
|
Target ID: |
207
|
Parent PID: |
7840
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:18
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11232
|
Target ID: |
208
|
Parent PID: |
6580
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:18
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11244
|
Target ID: |
209
|
Parent PID: |
11120
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11256
|
Target ID: |
210
|
Parent PID: |
11108
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10312
|
Target ID: |
211
|
Parent PID: |
7860
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
5852
|
Target ID: |
212
|
Parent PID: |
8888
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10388
|
Target ID: |
213
|
Parent PID: |
7552
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10404
|
Target ID: |
214
|
Parent PID: |
2520
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
4416
|
Target ID: |
215
|
Parent PID: |
7588
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10620
|
Target ID: |
216
|
Parent PID: |
7800
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10704
|
Target ID: |
217
|
Parent PID: |
11216
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10636
|
Target ID: |
218
|
Parent PID: |
11224
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10816
|
Target ID: |
219
|
Parent PID: |
11208
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10840
|
Target ID: |
220
|
Parent PID: |
11232
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11288
|
Target ID: |
221
|
Parent PID: |
7900
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11296
|
Target ID: |
222
|
Parent PID: |
7812
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11304
|
Target ID: |
223
|
Parent PID: |
7892
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11352
|
Target ID: |
224
|
Parent PID: |
9000
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11380
|
Target ID: |
225
|
Parent PID: |
10312
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11388
|
Target ID: |
226
|
Parent PID: |
5852
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11396
|
Target ID: |
227
|
Parent PID: |
10388
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11404
|
Target ID: |
228
|
Parent PID: |
4416
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11412
|
Target ID: |
229
|
Parent PID: |
10404
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11428
|
Target ID: |
230
|
Parent PID: |
10620
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11444
|
Target ID: |
231
|
Parent PID: |
11296
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11452
|
Target ID: |
232
|
Parent PID: |
11304
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11460
|
Target ID: |
233
|
Parent PID: |
7644
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11480
|
Target ID: |
234
|
Parent PID: |
7432
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11536
|
Target ID: |
235
|
Parent PID: |
11288
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11552
|
Target ID: |
236
|
Parent PID: |
9008
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11624
|
Target ID: |
237
|
Parent PID: |
11352
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11644
|
Target ID: |
238
|
Parent PID: |
11460
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11652
|
Target ID: |
239
|
Parent PID: |
11480
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11660
|
Target ID: |
240
|
Parent PID: |
11552
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:19
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11684
|
Target ID: |
241
|
Parent PID: |
7940
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:20
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11860
|
Target ID: |
242
|
Parent PID: |
7400
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:20
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11868
|
Target ID: |
243
|
Parent PID: |
2676
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:20
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11900
|
Target ID: |
244
|
Parent PID: |
8428
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11908
|
Target ID: |
245
|
Parent PID: |
7540
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11916
|
Target ID: |
246
|
Parent PID: |
9404
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11924
|
Target ID: |
247
|
Parent PID: |
8724
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11932
|
Target ID: |
248
|
Parent PID: |
9056
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11940
|
Target ID: |
249
|
Parent PID: |
11684
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11948
|
Target ID: |
250
|
Parent PID: |
11860
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11956
|
Target ID: |
251
|
Parent PID: |
11868
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11972
|
Target ID: |
252
|
Parent PID: |
1260
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11984
|
Target ID: |
253
|
Parent PID: |
11900
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11992
|
Target ID: |
254
|
Parent PID: |
11908
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12000
|
Target ID: |
255
|
Parent PID: |
11916
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12012
|
Target ID: |
256
|
Parent PID: |
11924
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12020
|
Target ID: |
257
|
Parent PID: |
11972
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12060
|
Target ID: |
258
|
Parent PID: |
7364
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12068
|
Target ID: |
259
|
Parent PID: |
9124
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12076
|
Target ID: |
260
|
Parent PID: |
8432
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12084
|
Target ID: |
261
|
Parent PID: |
9648
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12112
|
Target ID: |
262
|
Parent PID: |
11932
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12172
|
Target ID: |
263
|
Parent PID: |
8992
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12184
|
Target ID: |
264
|
Parent PID: |
9464
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12192
|
Target ID: |
265
|
Parent PID: |
8688
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12236
|
Target ID: |
266
|
Parent PID: |
12060
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12244
|
Target ID: |
267
|
Parent PID: |
12068
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12252
|
Target ID: |
268
|
Parent PID: |
12076
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12272
|
Target ID: |
269
|
Parent PID: |
12084
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11196
|
Target ID: |
270
|
Parent PID: |
8824
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10696
|
Target ID: |
271
|
Parent PID: |
11120
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11448
|
Target ID: |
272
|
Parent PID: |
9728
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
10772
|
Target ID: |
273
|
Parent PID: |
9300
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11456
|
Target ID: |
274
|
Parent PID: |
1196
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11408
|
Target ID: |
275
|
Parent PID: |
9212
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
6016
|
Target ID: |
276
|
Parent PID: |
9148
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
1308
|
Target ID: |
277
|
Parent PID: |
7492
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
1696
|
Target ID: |
278
|
Parent PID: |
10696
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
1860
|
Target ID: |
279
|
Parent PID: |
12184
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
1360
|
Target ID: |
280
|
Parent PID: |
12172
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
2756
|
Target ID: |
281
|
Parent PID: |
6888
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11988
|
Target ID: |
282
|
Parent PID: |
12192
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11996
|
Target ID: |
283
|
Parent PID: |
11448
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
11944
|
Target ID: |
284
|
Parent PID: |
10772
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12024
|
Target ID: |
285
|
Parent PID: |
11408
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:21
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12340
|
Target ID: |
286
|
Parent PID: |
9840
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:22
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12356
|
Target ID: |
287
|
Parent PID: |
11196
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:22
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12364
|
Target ID: |
288
|
Parent PID: |
6016
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:22
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12372
|
Target ID: |
289
|
Parent PID: |
1308
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:22
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12380
|
Target ID: |
290
|
Parent PID: |
2756
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:22
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12428
|
Target ID: |
291
|
Parent PID: |
11456
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:22
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12464
|
Target ID: |
292
|
Parent PID: |
9908
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:22
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12472
|
Target ID: |
293
|
Parent PID: |
9796
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:22
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12480
|
Target ID: |
294
|
Parent PID: |
9856
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:22
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12628
|
Target ID: |
295
|
Parent PID: |
12340
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:23
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12660
|
Target ID: |
296
|
Parent PID: |
12480
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:23
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12776
|
Target ID: |
297
|
Parent PID: |
12472
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:23
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12792
|
Target ID: |
298
|
Parent PID: |
12464
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:23
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12836
|
Target ID: |
299
|
Parent PID: |
8368
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:23
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12968
|
Target ID: |
300
|
Parent PID: |
12836
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:23
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13000
|
Target ID: |
301
|
Parent PID: |
10272
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:24
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13104
|
Target ID: |
303
|
Parent PID: |
13000
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:24
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13124
|
Target ID: |
304
|
Parent PID: |
8500
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:24
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13160
|
Target ID: |
305
|
Parent PID: |
7416
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:24
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13188
|
Target ID: |
306
|
Parent PID: |
13124
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:24
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13204
|
Target ID: |
307
|
Parent PID: |
7608
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:25
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13216
|
Target ID: |
308
|
Parent PID: |
9328
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:25
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13224
|
Target ID: |
309
|
Parent PID: |
13160
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:25
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /c ""C:\file.bat" "
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13232
|
Target ID: |
310
|
Parent PID: |
2580
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /c ""C:\file.bat" "
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:25
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
false
|
Is elevated: |
false
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13244
|
Target ID: |
311
|
Parent PID: |
10144
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:25
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13276
|
Target ID: |
313
|
Parent PID: |
8376
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:25
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13300
|
Target ID: |
314
|
Parent PID: |
9132
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:26
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12292
|
Target ID: |
315
|
Parent PID: |
13216
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:26
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
3592
|
Target ID: |
316
|
Parent PID: |
13232
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:26
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
false
|
Is elevated: |
false
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
1544
|
Target ID: |
317
|
Parent PID: |
13276
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:26
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12004
|
Target ID: |
318
|
Parent PID: |
10476
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:26
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
2828
|
Target ID: |
319
|
Parent PID: |
13244
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:26
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
4432
|
Target ID: |
321
|
Parent PID: |
13300
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:26
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12500
|
Target ID: |
322
|
Parent PID: |
13204
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:26
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12376
|
Target ID: |
323
|
Parent PID: |
8492
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:26
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12360
|
Target ID: |
324
|
Parent PID: |
7852
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:26
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7714f0000
|
Modulesize: |
163840
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
12432
|
Target ID: |
325
|
Parent PID: |
7520
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:26
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
2472
|
Target ID: |
326
|
Parent PID: |
9264
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:26
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
1228
|
Target ID: |
327
|
Parent PID: |
5776
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:26
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
5600
|
Target ID: |
328
|
Parent PID: |
12432
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:27
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
5356
|
Target ID: |
329
|
Parent PID: |
12360
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:27
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff72bec0000
|
Modulesize: |
135168
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
5516
|
Target ID: |
330
|
Parent PID: |
9928
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:27
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
3236
|
Target ID: |
331
|
Parent PID: |
1228
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:27
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13328
|
Target ID: |
332
|
Parent PID: |
12004
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:27
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13336
|
Target ID: |
333
|
Parent PID: |
12376
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:27
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13360
|
Target ID: |
334
|
Parent PID: |
2472
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:27
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13384
|
Target ID: |
335
|
Parent PID: |
8592
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:28
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13392
|
Target ID: |
336
|
Parent PID: |
7972
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:28
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13400
|
Target ID: |
337
|
Parent PID: |
10264
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:28
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13448
|
Target ID: |
338
|
Parent PID: |
5516
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:28
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13464
|
Target ID: |
339
|
Parent PID: |
9220
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:28
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13652
|
Target ID: |
340
|
Parent PID: |
8584
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:29
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13644
|
Target ID: |
341
|
Parent PID: |
8632
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:29
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13660
|
Target ID: |
342
|
Parent PID: |
13392
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:29
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13668
|
Target ID: |
343
|
Parent PID: |
13384
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:29
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13704
|
Target ID: |
344
|
Parent PID: |
10332
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:29
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13720
|
Target ID: |
345
|
Parent PID: |
13464
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:29
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13728
|
Target ID: |
346
|
Parent PID: |
13400
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:29
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13736
|
Target ID: |
347
|
Parent PID: |
13652
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:29
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13744
|
Target ID: |
348
|
Parent PID: |
13644
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
862208
|
MD5: |
0D698AF330FD17BEE3BF90011D49251D
|
Time: |
02:24:29
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7699e0000
|
Modulesize: |
892928
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13772
|
Target ID: |
349
|
Parent PID: |
8616
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:29
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13824
|
Target ID: |
350
|
Parent PID: |
10588
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:30
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13836
|
Target ID: |
351
|
Parent PID: |
10376
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:30
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\cmd.exe
|
C:\Windows\system32\cmd.exe /K c:/file.bat
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
13844
|
Target ID: |
352
|
Parent PID: |
8608
|
Name: |
cmd.exe
|
Class: |
cmd
|
Path: |
C:\Windows\System32\cmd.exe
|
Commandline: |
C:\Windows\system32\cmd.exe /K c:/file.bat
|
Size: |
289792
|
MD5: |
8A2122E8162DBEF04694B9C3E0B6CDEE
|
Time: |
02:24:30
|
Date: |
25/10/2024
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff7d8090000
|
Modulesize: |
421888
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Executes batch files |
System Summary |
|
Spawns processes |
System Summary |
|
|