Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | June 22, 2021, 7:57 a.m. | June 22, 2021, 8 a.m. |
-
-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\test22\AppData\Local\Temp\oki.exe" -Force
6928 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\7324971p7b2Sfi.exe" -Force
8992 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\7324971p7b2Sfi.exe" -Force
3800 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\test22\AppData\Local\Temp\oki.exe" -Force
2776 -
7324971p7b2Sfi.exe "C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\7324971p7b2Sfi.exe"
4408-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\7324971p7b2Sfi.exe" -Force
8700 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\Public\Documents\595354a157307x11cwdO5b8e72e4hQ1c8cd50a426gU\svchost.exe" -Force
9060 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\7324971p7b2Sfi.exe" -Force
7096 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\Public\Documents\595354a157307x11cwdO5b8e72e4hQ1c8cd50a426gU\svchost.exe" -Force
5988 -
7324971p7b2Sfi.exe "C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\7324971p7b2Sfi.exe"
1568
-
-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\Public\Documents\595354a157307x11cwdO5b8e72e4hQ1c8cd50a426gU\svchost.exe" -Force
4368 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\test22\AppData\Local\Temp\oki.exe" -Force
5272 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\Public\Documents\595354a157307x11cwdO5b8e72e4hQ1c8cd50a426gU\svchost.exe" -Force
8628 -
oki.exe "C:\Users\test22\AppData\Local\Temp\oki.exe"
500
-
Name | Response | Post-Analysis Lookup |
---|---|---|
apdocroto.gq | 172.67.158.27 |
Suricata Alerts
Suricata TLS
No Suricata TLS
suspicious_features | GET method with no useragent header | suspicious_request | GET http://apdocroto.gq/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-C6FEFDB4D5C1D411D177D75771792D61.html | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://apdocroto.gq/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-AF112CDD77AAF014CB96EAE02F666573.html |
request | GET http://apdocroto.gq/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-C6FEFDB4D5C1D411D177D75771792D61.html |
request | GET http://apdocroto.gq/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-AF112CDD77AAF014CB96EAE02F666573.html |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ |
file | C:\Users\test22\AppData\Local\Chromium\User Data |
file | C:\Users\test22\AppData\Local\MapleStudio\ChromePlus\User Data |
file | C:\Users\test22\AppData\Local\Yandex\YandexBrowser\User Data |
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | powershell Add-MpPreference -ExclusionPath "C:\Users\test22\AppData\Local\Temp\oki.exe" -Force |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\7324971p7b2Sfi.exe" -Force |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\test22\AppData\Local\Temp\oki.exe" -Force |
cmdline | powershell Add-MpPreference -ExclusionPath "C:\Users\Public\Documents\595354a157307x11cwdO5b8e72e4hQ1c8cd50a426gU\svchost.exe" -Force |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\Public\Documents\595354a157307x11cwdO5b8e72e4hQ1c8cd50a426gU\svchost.exe" -Force |
cmdline | powershell Add-MpPreference -ExclusionPath "C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\7324971p7b2Sfi.exe" -Force |
file | C:\Users\test22\AppData\Local\Temp\qweruiuyt\qweruiuyt.exe |
description | Communications smtp | rule | Network_SMTP_dotNet | ||||||
description | Run a KeyLogger | rule | KeyLogger | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Affect hook table | rule | win_hook | ||||||
description | Communications smtp | rule | Network_SMTP_dotNet | ||||||
description | Run a KeyLogger | rule | KeyLogger | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Affect hook table | rule | win_hook |
host | 172.217.25.14 |
description | oki.exe tried to sleep 13641050 seconds, actually delayed analysis time by 13641050 seconds | |||
description | 7324971p7b2Sfi.exe tried to sleep 13641050 seconds, actually delayed analysis time by 13641050 seconds |
reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\7324971p7b2Sfi | reg_value | C:\Users\Public\Documents\595354a157307x11cwdO5b8e72e4hQ1c8cd50a426gU\svchost.exe | ||||||
reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\7324971p7b2Sfi | reg_value | C:\Users\Public\Documents\595354a157307x11cwdO5b8e72e4hQ1c8cd50a426gU\svchost.exe | ||||||
reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\qweruiuyt | reg_value | C:\Users\test22\AppData\Local\Temp\qweruiuyt\qweruiuyt.exe | ||||||
reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\qweruiuyt | reg_value | C:\Users\test22\AppData\Local\Temp\qweruiuyt\qweruiuyt.exe |
file | C:\Users\test22\AppData\Roaming\FTPGetter\servers.xml |
file | C:\Users\test22\AppData\Roaming\Ipswitch\WS_FTP\Sites\ws_ftp.ini |
file | C:\Users\test22\AppData\Roaming\FileZilla\recentservers.xml |
registry | HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions |
registry | HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites |