Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | July 28, 2021, 9:42 a.m. | July 28, 2021, 9:44 a.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\porto.pdf.exe.dll,
1640 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\porto.pdf.exe.dll,StartW
1524-
wermgr.exe C:\Windows\system32\wermgr.exe
1620
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
138.34.28.219 | Active | Moloch |
185.56.76.108 | Active | Moloch |
185.56.76.28 | Active | Moloch |
185.56.76.72 | Active | Moloch |
185.56.76.94 | Active | Moloch |
204.138.26.60 | Active | Moloch |
24.162.214.166 | Active | Moloch |
38.110.100.104 | Active | Moloch |
38.110.103.124 | Active | Moloch |
38.110.103.136 | Active | Moloch |
60.51.47.65 | Active | Moloch |
74.85.157.139 | Active | Moloch |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49172 38.110.103.136:443 |
C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-78:8A:20:6C:22:98/emailAddress=support@ubnt.com | C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-78:8A:20:6C:22:98/emailAddress=support@ubnt.com | ba:d7:95:38:aa:e6:8c:48:3e:83:06:69:20:ec:3a:a2:9c:0c:61:47 |
TLSv1 192.168.56.103:49169 38.110.103.124:443 |
C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-78:8A:20:EC:48:A1/emailAddress=support@ubnt.com | C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-78:8A:20:EC:48:A1/emailAddress=support@ubnt.com | e6:60:4a:40:4a:b9:63:85:da:e8:fc:ec:75:e2:1a:7e:85:1f:49:1e |
TLSv1 192.168.56.103:49173 38.110.100.104:443 |
C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | b5:21:a8:16:d5:97:b1:67:f6:60:a5:cb:20:27:76:ec:3c:9d:3b:02 |
TLSv1 192.168.56.103:49167 24.162.214.166:443 |
C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | b5:21:a8:16:d5:97:b1:67:f6:60:a5:cb:20:27:76:ec:3c:9d:3b:02 |
TLSv1 192.168.56.103:49170 60.51.47.65:443 |
C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | 50:fd:fd:4e:2c:57:ea:f7:c9:cd:3f:61:4a:a2:40:01:1b:b8:df:02 |
TLSv1 192.168.56.103:49176 38.110.103.136:443 |
None | None | None |
TLSv1 192.168.56.103:49171 138.34.28.219:443 |
C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-F4:92:BF:D6:1C:49/emailAddress=support@ubnt.com | C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-F4:92:BF:D6:1C:49/emailAddress=support@ubnt.com | 0f:6c:9c:c8:a9:10:1e:c8:98:3f:01:df:32:ad:f1:7f:5d:d0:4c:54 |
TLSv1 192.168.56.103:49177 38.110.103.124:443 |
None | None | None |
pdb_path | K:\MFC-Examples-main\MFC-Examples-main\Tab\Release\Tab.pdb |
section | NUM |
suspicious_features | Connection to IP address | suspicious_request | GET https://24.162.214.166/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET https://38.110.103.124/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET https://60.51.47.65/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET https://138.34.28.219/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET https://138.34.28.219/cookiechecker?uri=/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET https://138.34.28.219/index.html | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET https://138.34.28.219/login.cgi?uri=/index.html | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET https://38.110.103.136/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET https://38.110.100.104/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ |
request | GET https://24.162.214.166/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ |
request | GET https://38.110.103.124/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ |
request | GET https://60.51.47.65/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ |
request | GET https://138.34.28.219/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ |
request | GET https://138.34.28.219/cookiechecker?uri=/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ |
request | GET https://138.34.28.219/index.html |
request | GET https://138.34.28.219/login.cgi?uri=/index.html |
request | GET https://38.110.103.136/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ |
request | GET https://38.110.100.104/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ |
description | wermgr.exe tried to sleep 153 seconds, actually delayed analysis time by 153 seconds |
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00056174 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00056174 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00056174 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00056174 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00056174 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00056174 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00056174 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00056174 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00056174 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00056174 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00056174 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00056174 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00056174 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00056174 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00056174 | size | 0x00000134 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00056174 | size | 0x00000134 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00056360 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00056360 | size | 0x00000144 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005d394 | size | 0x00000568 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005d394 | size | 0x00000568 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005d394 | size | 0x00000568 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005d394 | size | 0x00000568 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005d394 | size | 0x00000568 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005d394 | size | 0x00000568 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005d394 | size | 0x00000568 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005d394 | size | 0x00000568 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005d394 | size | 0x00000568 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005d394 | size | 0x00000568 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005d394 | size | 0x00000568 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005d394 | size | 0x00000568 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005d394 | size | 0x00000568 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005d394 | size | 0x00000568 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005d394 | size | 0x00000568 | ||||||||||||||||||
name | RT_MENU | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005d938 | size | 0x0000003a | ||||||||||||||||||
name | RT_MENU | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005d938 | size | 0x0000003a | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005dd64 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005dd64 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005dd64 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005dd64 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005dd64 | size | 0x00000034 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005f344 | size | 0x00000042 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005f344 | size | 0x00000042 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005f344 | size | 0x00000042 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005f344 | size | 0x00000042 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005f344 | size | 0x00000042 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005f344 | size | 0x00000042 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005f344 | size | 0x00000042 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005f344 | size | 0x00000042 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005f344 | size | 0x00000042 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0005f344 | size | 0x00000042 |
cmdline | C:\Windows\system32\cmd.exe |
section | {u'size_of_data': u'0x00043a00', u'virtual_address': u'0x00054000', u'entropy': 7.7534110876181845, u'name': u'.rsrc', u'virtual_size': u'0x000438e8'} | entropy | 7.75341108762 | description | A section with a high entropy has been found | |||||||||
entropy | 0.438767234388 | description | Overall entropy of this PE file is high |
host | 138.34.28.219 | |||
host | 185.56.76.108 | |||
host | 185.56.76.28 | |||
host | 185.56.76.72 | |||
host | 185.56.76.94 | |||
host | 204.138.26.60 | |||
host | 24.162.214.166 | |||
host | 38.110.100.104 | |||
host | 38.110.103.124 | |||
host | 38.110.103.136 | |||
host | 60.51.47.65 | |||
host | 74.85.157.139 |
Bkav | W32.AIDetect.malware1 |
Lionic | Trojan.Win32.Trickpak.4!c |
McAfee | Artemis!8DD7C961C9CD |
Cylance | Unsafe |
Sangfor | Trojan.Win32.Trickpak.gen |
ESET-NOD32 | Win32/TrickBot.DX |
APEX | Malicious |
Paloalto | generic.ml |
Cynet | Malicious (score: 100) |
Kaspersky | HEUR:Trojan.Win32.Trickpak.gen |
McAfee-GW-Edition | BehavesLike.Win32.Emotet.jc |
FireEye | Generic.mg.8dd7c961c9cdbd69 |
GData | Trojan.GenericKD.46691457 |
Webroot | W32.Malware.Gen |
MAX | malware (ai score=81) |
Kingsoft | Win32.Troj.Undef.(kcloud) |
ZoneAlarm | HEUR:Trojan.Win32.Trickpak.gen |
Microsoft | Program:Win32/Wacapew.C!ml |
ALYac | Backdoor.Agent.Trickbot |
Ikarus | Trojan-Spy.Win32.TrickBot |
Fortinet | W32/Trickpak!tr |
dead_host | 185.56.76.28:443 |
dead_host | 74.85.157.139:443 |
dead_host | 185.56.76.72:443 |
dead_host | 204.138.26.60:443 |
dead_host | 185.56.76.108:443 |
dead_host | 192.168.56.103:49165 |
dead_host | 192.168.56.103:49174 |
dead_host | 192.168.56.103:49164 |
dead_host | 192.168.56.103:49178 |
dead_host | 192.168.56.103:49168 |
dead_host | 185.56.76.94:443 |