Summary | ZeroBOX

CE_Agent_Funding_Advice_pdf.js

Category Machine Started Completed
FILE s1_win7_x6402 July 1, 2021, 8:15 a.m. July 1, 2021, 8:18 a.m.
Size 2.2MB
Type ASCII text, with very long lines, with no line terminators
MD5 dadca572b4e524d5f03a2a4f9b25a050
SHA256 65987f95b365501579431ea8dec1d45940430d8c9defad58908a14e6fb96a347
CRC32 9B76668D
ssdeep 24576:eOa0QS/9pn7qKkxds34NPoE3j2hYW8jecNH2Pzw83ZEkTE50DngGfayxg3qfDOoX:Pl
Yara None matched

Name Response Post-Analysis Lookup
dilideanter.zapto.org 185.19.85.169
IP Address Status Action
164.124.101.2 Active Moloch
172.217.25.14 Active Moloch
185.19.85.169 Active Moloch

Suricata Alerts

Flow SID Signature Category
UDP 192.168.56.102:57660 -> 164.124.101.2:53 2028703 ET POLICY DNS Query to DynDNS Domain *.zapto .org Potentially Bad Traffic
UDP 192.168.56.102:61459 -> 164.124.101.2:53 2028703 ET POLICY DNS Query to DynDNS Domain *.zapto .org Potentially Bad Traffic

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
domain dilideanter.zapto.org
wmi Select * From Win32_OperatingSystem
wmi select * from win32_operatingsystem
wmi select * from win32_logicaldisk
wmi select * from win32_logicaldisk
host 172.217.25.14
dead_host 192.168.56.102:49812
dead_host 192.168.56.102:49813
dead_host 192.168.56.102:49810
dead_host 192.168.56.102:49811
dead_host 192.168.56.102:49808
dead_host 185.19.85.169:7272
dead_host 192.168.56.102:49809
dead_host 192.168.56.102:49814
dead_host 192.168.56.102:49815