Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | April 23, 2021, 6:13 p.m. | April 23, 2021, 6:36 p.m. |
-
-
FastStoneImageViewer.exe C:\Users\test22\AppData\Roaming\FastStoneSoft\FastStoneImageViewer.exe
2636
-
Name | Response | Post-Analysis Lookup |
---|---|---|
api.faceit.com | 104.17.63.50 |
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://185.215.113.67/4dcYcWsw3/index.php | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://176.121.14.159/build.exe |
request | POST http://185.215.113.67/4dcYcWsw3/index.php |
request | GET http://176.121.14.159/build.exe |
request | POST http://185.215.113.67/4dcYcWsw3/index.php |
file | C:\Users\test22\AppData\Roaming\FastStoneSoft\libgcc_s_sjlj-1.dll |
file | C:\Users\test22\AppData\Roaming\FastStoneSoft\libxml4.dll |
file | C:\Users\test22\AppData\Local\Temp\build.exe |
file | C:\Users\test22\AppData\Roaming\FastStoneSoft\FastStoneImageViewer.exe |
file | C:\Users\test22\AppData\Roaming\FastStoneSoft\libbonjour.dll |
file | C:\Users\test22\AppData\Roaming\FastStoneSoft\libogg-0.dll |
file | C:\Users\test22\AppData\Roaming\FastStoneSoft\zlib.dll |
file | C:\Users\test22\AppData\Roaming\FastStoneSoft\libEGL.dll |
file | C:\Users\test22\AppData\Roaming\FastStoneSoft\libgraph31.dll |
file | C:\Users\test22\AppData\Roaming\FastStoneSoft\libpangoft2-1.0-0.dll |
file | C:\Users\test22\AppData\Roaming\FastStoneSoft\libgcc_s_sjlj-1.dll |
file | C:\Users\test22\AppData\Roaming\FastStoneSoft\libbonjour.dll |
file | C:\Users\test22\AppData\Roaming\FastStoneSoft\libEGL.dll |
file | C:\Users\test22\AppData\Roaming\FastStoneSoft\libxml4.dll |
file | C:\Users\test22\AppData\Roaming\FastStoneSoft\libgraph31.dll |
file | C:\Users\test22\AppData\Local\Temp\build.exe |
file | C:\Users\test22\AppData\Roaming\FastStoneSoft\FastStoneImageViewer.exe |