mttaggart / wtfbins

WTF are these binaries doing?! A list of benign applications that mimic malicious behavior.
MIT License
150 stars 12 forks source link

[New WTFBin]: WTFBIN Here #49

Closed 0xDeadcell closed 8 months ago

0xDeadcell commented 11 months ago

List of registry keys it opens: "Registry Keys Opened" https://www.virustotal.com/gui/file/7e20bd611bf14082ef28068073abc9f84faeb04fc9f4735b8fc7c0c0a1fbc87b/behavior

In a windows environment it is not uncommon to see execution of rundll32 Startupscan.dll,SusRunTask, however this is normal startup behavior that is executed by task scheduler during startup - it scans startup apps and warns the user if there are too many.

https://www.hybrid-analysis.com/sample/7e20bd611bf14082ef28068073abc9f84faeb04fc9f4735b8fc7c0c0a1fbc87b/5c60484b7ca3e14e0132f425

mttaggart commented 8 months ago

Great submission. Added in 6e626a753a6. Thank you!