Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | July 1, 2021, 8:15 a.m. | July 1, 2021, 8:18 a.m. |
-
wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\CE_Agent_Funding_Advice_pdf.js
2288
Name | Response | Post-Analysis Lookup |
---|---|---|
dilideanter.zapto.org | 185.19.85.169 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.56.102:57660 -> 164.124.101.2:53 | 2028703 | ET POLICY DNS Query to DynDNS Domain *.zapto .org | Potentially Bad Traffic |
UDP 192.168.56.102:61459 -> 164.124.101.2:53 | 2028703 | ET POLICY DNS Query to DynDNS Domain *.zapto .org | Potentially Bad Traffic |
Suricata TLS
No Suricata TLS
domain | dilideanter.zapto.org |
wmi | Select * From Win32_OperatingSystem |
wmi | select * from win32_operatingsystem |
wmi | select * from win32_logicaldisk |
wmi | select * from win32_logicaldisk |
host | 172.217.25.14 |
dead_host | 192.168.56.102:49812 |
dead_host | 192.168.56.102:49813 |
dead_host | 192.168.56.102:49810 |
dead_host | 192.168.56.102:49811 |
dead_host | 192.168.56.102:49808 |
dead_host | 185.19.85.169:7272 |
dead_host | 192.168.56.102:49809 |
dead_host | 192.168.56.102:49814 |
dead_host | 192.168.56.102:49815 |