Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Aug. 6, 2021, 9:17 a.m. | Aug. 6, 2021, 9:41 a.m. |
Name | Response | Post-Analysis Lookup |
---|---|---|
www.fussionpromos.com |
CNAME
fussionpromos.com
|
192.254.185.89 |
www.sergrtr.com |
CNAME
shops.myshopify.com
CNAME
sergeg.myshopify.com
|
23.227.38.74 |
www.lenatwo.com |
CNAME
lenatwo.com
|
46.4.153.33 |
www.vidacocktails.com |
CNAME
vidacocktails.com
|
34.102.136.180 |
Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | C:\bucosiriyuj5.pdb |
resource name | FIJUYOPECETALAVUTIVENAHIS |
resource name | LOMELIBEGOCIROVURILOHIYESAD |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.sergrtr.com/otcl/?uVjH=mBDnt/Gh8erpdJmR5LUsgS6AYomiYv6KKx4Ciy1VWZ+lm+O2aYdlFCHe7BXtcsumDYUDE2bt&R2Mxt=MjOp3dr0kBhPCb6P | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.fussionpromos.com/otcl/?uVjH=R6pBimEX126Y/7jz26NSIB+pAf+iSCkbIcynLs+ia55rI8fnMgFdof6zFKq4BsG3kSXOUZFo&R2Mxt=MjOp3dr0kBhPCb6P | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.vidacocktails.com/otcl/?uVjH=rypAyBghX+oRSAWiWZi6HXfSOOQXpfwEtRIEbFlRCYHxrojr5D9YoFHDjuuw3w1SPlmQfBvX&R2Mxt=MjOp3dr0kBhPCb6P | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.lenatwo.com/otcl/?uVjH=jjpdYGPxaq0GEExKffhLJbVQdJjKexSz1KEBGQRYOyI7/Bdn/luiGJqh0JO76VQxmlxEikAe&R2Mxt=MjOp3dr0kBhPCb6P |
request | GET http://www.sergrtr.com/otcl/?uVjH=mBDnt/Gh8erpdJmR5LUsgS6AYomiYv6KKx4Ciy1VWZ+lm+O2aYdlFCHe7BXtcsumDYUDE2bt&R2Mxt=MjOp3dr0kBhPCb6P |
request | GET http://www.fussionpromos.com/otcl/?uVjH=R6pBimEX126Y/7jz26NSIB+pAf+iSCkbIcynLs+ia55rI8fnMgFdof6zFKq4BsG3kSXOUZFo&R2Mxt=MjOp3dr0kBhPCb6P |
request | GET http://www.vidacocktails.com/otcl/?uVjH=rypAyBghX+oRSAWiWZi6HXfSOOQXpfwEtRIEbFlRCYHxrojr5D9YoFHDjuuw3w1SPlmQfBvX&R2Mxt=MjOp3dr0kBhPCb6P |
request | GET http://www.lenatwo.com/otcl/?uVjH=jjpdYGPxaq0GEExKffhLJbVQdJjKexSz1KEBGQRYOyI7/Bdn/luiGJqh0JO76VQxmlxEikAe&R2Mxt=MjOp3dr0kBhPCb6P |
name | FIJUYOPECETALAVUTIVENAHIS | language | LANG_SERBIAN | filetype | ASCII text, with very long lines, with no line terminators | sublanguage | SUBLANG_DEFAULT | offset | 0x0287bc28 | size | 0x000021af | ||||||||||||||||||
name | LOMELIBEGOCIROVURILOHIYESAD | language | LANG_SERBIAN | filetype | ASCII text, with very long lines, with no line terminators | sublanguage | SUBLANG_DEFAULT | offset | 0x0287b5f0 | size | 0x00000636 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x0287b120 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x0287b120 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x0287b120 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x0287b120 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x0287b120 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x0287b120 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x0287b120 | size | 0x00000468 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_DEFAULT | offset | 0x0287e310 | size | 0x000002b2 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_DEFAULT | offset | 0x0287e310 | size | 0x000002b2 | ||||||||||||||||||
name | RT_ACCELERATOR | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_DEFAULT | offset | 0x0287de10 | size | 0x00000028 | ||||||||||||||||||
name | RT_ACCELERATOR | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_DEFAULT | offset | 0x0287de10 | size | 0x00000028 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_DEFAULT | offset | 0x0287b588 | size | 0x00000068 |
section | {u'size_of_data': u'0x00039a00', u'virtual_address': u'0x00001000', u'entropy': 7.661293889575676, u'name': u'.text', u'virtual_size': u'0x00039940'} | entropy | 7.66129388958 | description | A section with a high entropy has been found | |||||||||
entropy | 0.808771929825 | description | Overall entropy of this PE file is high |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Bypass DEP | rule | disable_dep |