MEDIUM 'WildFire Malware' along with 4 other issues

RESOLVED DUPLICATE INCIDENT ID: #1985 | Created: 2026-01-18 22:57:23
5
Alerts
2
Hosts
7
Files
0
Network
Incident Overview

'WildFire Malware' along with 4 other issues generated by XDR Agent and XDR BIOC detected on 2 hosts involving 2 users

5
2026-01-18 23:10
Unassigned
XDR Agent, XDR BIOC
Malware Execution
Affected Hosts & Users
desktop-fnumv3u\user book-r0be6s1nc3\ubuntu
MITRE ATT&CK Mapping
File Artifacts 7
File Name Path SHA256 Signature Verdict Actions
UltimateXdrGenerator.exe - 7ae4a9f4edd80c1cde8a4bcf49079b769591f422eae8fe4ec0ccac1a5b30cc1c SIGNATURE_UNSIGNED UNKNOWN VT
MegaGenerator.exe - 787dad5ceaf6e4b98a3ba61dcd97a4374c03686d12442e92d419ebd491b9c23e SIGNATURE_UNSIGNED UNKNOWN VT
UltimateXdrGenerator.exe - 39d630bf97d4f13b0d505838e4271408ba66362564adcb4384056f00325823bc SIGNATURE_UNSIGNED UNKNOWN VT
MegaGenerator.exe - c1beaac1b80238a81069d25ed8087bc0f451bc0548bb6a41e91354a8040a59f3 SIGNATURE_UNSIGNED UNKNOWN VT
cmd.exe - badf4752413cb0cbdc03fb95820ca167f0cdc63b597ccdb5ef43111180e088b0 SIGNATURE_SIGNED UNKNOWN VT
cmd.exe - 64afc6db3aad1289533662e2d79e27dd55c7dcdb8cd918b08e145ad82ad5acb4 SIGNATURE_SIGNED UNKNOWN VT
rundll32.exe - 076592ca1957f8f357cc201f0015072c612f5770ad7de85f87f254253c754dd7 SIGNATURE_SIGNED UNKNOWN VT
Network Artifacts 0
No network artifacts found for this incident
Process Artifacts 5
Process Command Line Parent Process User
cmd.exe C:\WINDOWS\system32\cmd.exe /c "rundll32 javascript:"\..\mshtml"" cmd.exe DESKTOP-FNUMV3U\User
UltimateXdrGenerator.exe "C:\app\cortex-xdr-siem-test\xdr_tools\UltimateXdrGenerator\bin\publish\Ultimate... cmd.exe BOOK-R0BE6S1NC3\ubuntu
MegaGenerator.exe "C:\app\cortex-xdr-siem-test\xdr_tools\MegaGenerator\bin\publish\MegaGenerator.e... cmd.exe BOOK-R0BE6S1NC3\ubuntu
UltimateXdrGenerator.exe "C:\app\cortex-xdr-siem-test\xdr_tools\UltimateXdrGenerator\bin\publish\Ultimate... cmd.exe DESKTOP-FNUMV3U\User
MegaGenerator.exe "C:\app\cortex-xdr-siem-test\xdr_tools\MegaGenerator\bin\publish\MegaGenerator.e... cmd.exe DESKTOP-FNUMV3U\User
Registry Artifacts 0
No registry artifacts found for this incident
Analyst Verdict
MEDIUM
  • Monitor for similar activity
  • Verify remediation complete
Summary
5
Alerts
2
Hosts
7
Files
0
Network
Alert Categories
Malware Execution
Timeline
01-18 23:10:06
Incident Modified
Status or details updated
01-18 23:10:06
Incident Resolved
resolved duplicate incident
01-18 23:06:10
Rundll32.exe was used to run JavaScript
medium - Detected
01-18 23:03:01
WildFire Malware
medium - Prevented (Blocked)
01-18 23:02:01
WildFire Malware
medium - Prevented (Blocked)
01-18 23:00:01
WildFire Malware
medium - Prevented (Blocked)
01-18 22:57:23
Incident Created
#1985 - 'WildFire Malware' along with 4 other issues
01-18 22:57:23
UltimateXdrGenerator.exe
Verdict: Unknown
01-18 22:57:23
MegaGenerator.exe
Verdict: Unknown
01-18 22:57:23
UltimateXdrGenerator.exe
Verdict: Unknown
01-18 22:57:23
MegaGenerator.exe
Verdict: Unknown
01-18 22:57:23
cmd.exe
Verdict: Unknown
01-18 22:57:23
cmd.exe
Verdict: Unknown
01-18 22:57:23
rundll32.exe
Verdict: Unknown
01-18 22:56:01
WildFire Malware
medium - Prevented (Blocked)