Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Aug. 6, 2021, 9:17 a.m. | Aug. 6, 2021, 9:48 a.m. |
Name | Response | Post-Analysis Lookup |
---|---|---|
www.baileyfred.com | ||
www.mood-street-food.com |
CNAME
mood-street-food.com
|
66.235.200.147 |
www.livesupgrade.com |
CNAME
shops.myshopify.com
|
23.227.38.74 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49203 -> 23.227.38.74:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49203 -> 23.227.38.74:80 | 2031449 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49203 -> 23.227.38.74:80 | 2031453 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49204 -> 66.235.200.147:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49204 -> 66.235.200.147:80 | 2031449 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49204 -> 66.235.200.147:80 | 2031453 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
Suricata TLS
No Suricata TLS
pdb_path | C:\depar.pdb |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.livesupgrade.com/c244/?jPg8=sHXsfwOXiK7jrrP9uOC/H86ZPlKBjRkw0E3ojIegjKKr3xSRhIPhHgoL2XAJK99QMXFfUNAT&P0D=AdsxIRr | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.mood-street-food.com/c244/?jPg8=/7wWxO8qWNv6Gj71bI065/AN6akWd6fpCE5qVo3rjtTiIXX+bkB7ykTM4tcn3R0DCd4x72pR&P0D=AdsxIRr |
request | GET http://www.livesupgrade.com/c244/?jPg8=sHXsfwOXiK7jrrP9uOC/H86ZPlKBjRkw0E3ojIegjKKr3xSRhIPhHgoL2XAJK99QMXFfUNAT&P0D=AdsxIRr |
request | GET http://www.mood-street-food.com/c244/?jPg8=/7wWxO8qWNv6Gj71bI065/AN6akWd6fpCE5qVo3rjtTiIXX+bkB7ykTM4tcn3R0DCd4x72pR&P0D=AdsxIRr |
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02881390 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02881390 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02881390 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02881390 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02881390 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02881390 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02881390 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02881390 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02881390 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02881390 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02881390 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02881390 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02881390 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_SERBIAN | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02881390 | size | 0x00000468 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_DEFAULT | offset | 0x02883590 | size | 0x000001f8 | ||||||||||||||||||
name | RT_STRING | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_DEFAULT | offset | 0x02883590 | size | 0x000001f8 | ||||||||||||||||||
name | RT_ACCELERATOR | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_DEFAULT | offset | 0x02881898 | size | 0x00000028 | ||||||||||||||||||
name | RT_ACCELERATOR | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_DEFAULT | offset | 0x02881898 | size | 0x00000028 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_DEFAULT | offset | 0x028817f8 | size | 0x00000068 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_DEFAULT | offset | 0x028817f8 | size | 0x00000068 |
section | {u'size_of_data': u'0x00038c00', u'virtual_address': u'0x00001000', u'entropy': 7.724287305571445, u'name': u'.text', u'virtual_size': u'0x00038a70'} | entropy | 7.72428730557 | description | A section with a high entropy has been found | |||||||||
entropy | 0.741830065359 | description | Overall entropy of this PE file is high |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Bypass DEP | rule | disable_dep |