Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | July 9, 2021, 9:50 a.m. | July 9, 2021, 10 a.m. |
-
-
svchost.exe C:\Windows\System32\svchost.exe
2688
-
Name | Response | Post-Analysis Lookup |
---|---|---|
sudepallon.com | 77.222.42.67 | |
pospvisis.com | 95.213.179.67 | |
srand04rf.ru | 8.211.241.0 | |
api.ipify.org | 23.21.173.155 |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
pdb_path | c:\HighNature\Straightbusy\conditionSurface\Jobhas\industryCountryfeel.pdb |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
suspicious_features | POST method with no referer header | suspicious_request | POST http://sudepallon.com/8/forum.php |
request | GET http://api.ipify.org/ |
request | POST http://sudepallon.com/8/forum.php |
request | GET http://srand04rf.ru/7hfjsdfjks.exe |
request | GET http://api.ipify.org/?format=xml |
request | POST http://sudepallon.com/8/forum.php |
domain | srand04rf.ru | description | Russian Federation domain TLD |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local State |
domain | api.ipify.org |
cmdline | C:\Windows\System32\svchost.exe |