Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | April 14, 2021, 7:57 a.m. | April 14, 2021, 7:59 a.m. |
IP Address | Status | Action |
---|---|---|
103.149.26.92 | Active | Moloch |
104.165.219.251 | Active | Moloch |
104.21.86.40 | Active | Moloch |
164.124.101.2 | Active | Moloch |
184.168.131.241 | Active | Moloch |
192.185.35.176 | Active | Moloch |
210.152.86.230 | Active | Moloch |
34.102.136.180 | Active | Moloch |
35.186.238.101 | Active | Moloch |
52.15.160.167 | Active | Moloch |
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .wuxer |
section | .cowubag |
section | .new |
resource name | None |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.nyclgbxyi.icu/u6nq/?jfIXkD=UXYrmMJ4u/B1+0WUExyHbxAt0m6f2mslIKSkRRcWxo5onae3DrFHsgQkCsGRGM+FoeqLQIti&YPc=yVylp85xvxIXPV | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.foivgohl.com/u6nq/?jfIXkD=YHvWfgyTeOO8vJz3Qr0CaGVWOjPM5DV68PGCAW/ufgQebwovY+nib4yut9ZTDzE2UXFvF8SK&YPc=yVylp85xvxIXPV | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.drinkjoisi.com/u6nq/?jfIXkD=HHLZx8uXdVEL5sIi4Qhl+dXD0XjsJeb2Y3TX8/ZiLqv3S+d10eFI57bZ+Tv9ScYahdp7TaH4&YPc=yVylp85xvxIXPV | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.webgomo.com/u6nq/?jfIXkD=SJahp8ZgLKBLeEw+JP1CtZAjO/8RCCYuCYBr+ahXFSbTuZjNHmVgp8Kfz4Je2Pt/IjurR7iF&YPc=yVylp85xvxIXPV | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.205southsignalstojai.com/u6nq/?jfIXkD=6KwRkc8GCQPM+S+o9hKUwrpx/IpjrLCdEWb8uFULZjP+PN2NkxQcmVQosxnw4NrdoJLUPJkh&YPc=yVylp85xvxIXPV | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.legalopinion.guru/u6nq/?jfIXkD=D5mIrqti24HNtHmeGm2yPUY1hS7UiwTv12d5cjxJfuLLMvFCw4k9mM+pM/mMxbtRmkmPxt7v&YPc=yVylp85xvxIXPV | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.kenkelconsulting.com/u6nq/?jfIXkD=ErxCIhrfUCX6Yp5sejZJtF+wo6Jo148aBDn7Fzy+yibKoXLFQcLoBP6k6zU4f2Fwwu1Afjl1&YPc=yVylp85xvxIXPV | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.nubiaurquizopeluqueria.com/u6nq/?jfIXkD=hf/WfZBHYY4DdyGWkhub7RWq0Z7p5DE7Wbr3yBhKMx/2QIu4qyMRNQCZ6eRRdvBNtSfiWcZc&YPc=yVylp85xvxIXPV | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.xn--3bss1rzz1apulk7k.com/u6nq/?jfIXkD=R4wRqmGFPjH8JAb+A8lzOmKJPejSdwbfE+Ot6R13XYj1gCI5taOp9+IDE08PqvW/QAI/rZfv&YPc=yVylp85xvxIXPV |
request | POST http://www.nyclgbxyi.icu/u6nq/ |
request | GET http://www.nyclgbxyi.icu/u6nq/?jfIXkD=UXYrmMJ4u/B1+0WUExyHbxAt0m6f2mslIKSkRRcWxo5onae3DrFHsgQkCsGRGM+FoeqLQIti&YPc=yVylp85xvxIXPV |
request | POST http://www.foivgohl.com/u6nq/ |
request | GET http://www.foivgohl.com/u6nq/?jfIXkD=YHvWfgyTeOO8vJz3Qr0CaGVWOjPM5DV68PGCAW/ufgQebwovY+nib4yut9ZTDzE2UXFvF8SK&YPc=yVylp85xvxIXPV |
request | POST http://www.drinkjoisi.com/u6nq/ |
request | GET http://www.drinkjoisi.com/u6nq/?jfIXkD=HHLZx8uXdVEL5sIi4Qhl+dXD0XjsJeb2Y3TX8/ZiLqv3S+d10eFI57bZ+Tv9ScYahdp7TaH4&YPc=yVylp85xvxIXPV |
request | POST http://www.webgomo.com/u6nq/ |
request | GET http://www.webgomo.com/u6nq/?jfIXkD=SJahp8ZgLKBLeEw+JP1CtZAjO/8RCCYuCYBr+ahXFSbTuZjNHmVgp8Kfz4Je2Pt/IjurR7iF&YPc=yVylp85xvxIXPV |
request | POST http://www.205southsignalstojai.com/u6nq/ |
request | GET http://www.205southsignalstojai.com/u6nq/?jfIXkD=6KwRkc8GCQPM+S+o9hKUwrpx/IpjrLCdEWb8uFULZjP+PN2NkxQcmVQosxnw4NrdoJLUPJkh&YPc=yVylp85xvxIXPV |
request | POST http://www.legalopinion.guru/u6nq/ |
request | GET http://www.legalopinion.guru/u6nq/?jfIXkD=D5mIrqti24HNtHmeGm2yPUY1hS7UiwTv12d5cjxJfuLLMvFCw4k9mM+pM/mMxbtRmkmPxt7v&YPc=yVylp85xvxIXPV |
request | POST http://www.kenkelconsulting.com/u6nq/ |
request | GET http://www.kenkelconsulting.com/u6nq/?jfIXkD=ErxCIhrfUCX6Yp5sejZJtF+wo6Jo148aBDn7Fzy+yibKoXLFQcLoBP6k6zU4f2Fwwu1Afjl1&YPc=yVylp85xvxIXPV |
request | POST http://www.nubiaurquizopeluqueria.com/u6nq/ |
request | GET http://www.nubiaurquizopeluqueria.com/u6nq/?jfIXkD=hf/WfZBHYY4DdyGWkhub7RWq0Z7p5DE7Wbr3yBhKMx/2QIu4qyMRNQCZ6eRRdvBNtSfiWcZc&YPc=yVylp85xvxIXPV |
request | POST http://www.xn--3bss1rzz1apulk7k.com/u6nq/ |
request | GET http://www.xn--3bss1rzz1apulk7k.com/u6nq/?jfIXkD=R4wRqmGFPjH8JAb+A8lzOmKJPejSdwbfE+Ot6R13XYj1gCI5taOp9+IDE08PqvW/QAI/rZfv&YPc=yVylp85xvxIXPV |
request | POST http://www.nyclgbxyi.icu/u6nq/ |
request | POST http://www.foivgohl.com/u6nq/ |
request | POST http://www.drinkjoisi.com/u6nq/ |
request | POST http://www.webgomo.com/u6nq/ |
request | POST http://www.205southsignalstojai.com/u6nq/ |
request | POST http://www.legalopinion.guru/u6nq/ |
request | POST http://www.kenkelconsulting.com/u6nq/ |
request | POST http://www.nubiaurquizopeluqueria.com/u6nq/ |
request | POST http://www.xn--3bss1rzz1apulk7k.com/u6nq/ |
section | {u'size_of_data': u'0x00049400', u'virtual_address': u'0x00001000', u'entropy': 7.50402962764412, u'name': u'.text', u'virtual_size': u'0x0004938f'} | entropy | 7.50402962764 | description | A section with a high entropy has been found | |||||||||
entropy | 0.808275862069 | description | Overall entropy of this PE file is high |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Bypass DEP | rule | disable_dep |