Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | Sept. 6, 2021, 6 p.m. | Sept. 6, 2021, 6:10 p.m. |
-
-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
1660 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2848 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
276 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
816 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2136 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2328 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2272 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
508 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2748 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2968 -
wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\test22\AppData\Local\Temp\Dewgkwlbhkrsncbybkhtfpkb.vbs"
1376-
Oggnfkemtibcinconsoleapp16.exe "C:\Users\test22\AppData\Local\Temp\Oggnfkemtibcinconsoleapp16.exe"
2308-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2760 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2988 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
1784 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2168 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
656 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2332 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2504 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
1636 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
900 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
1788
-
-
-
ghjkl.exe C:\Users\test22\AppData\Local\Temp\ghjkl.exe
932
-
-
explorer.exe C:\Windows\Explorer.EXE
1236
Name | Response | Post-Analysis Lookup |
---|---|---|
telete.in | 195.201.225.248 | |
google.com | 172.217.175.78 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49179 -> 195.201.225.248:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 45.142.215.237:80 -> 192.168.56.102:49190 | 2018959 | ET POLICY PE EXE or DLL Windows file download HTTP | Potential Corporate Privacy Violation |
TCP 45.142.215.237:80 -> 192.168.56.102:49190 | 2016538 | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download | Potentially Bad Traffic |
TCP 45.142.215.237:80 -> 192.168.56.102:49190 | 2021076 | ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response | Potentially Bad Traffic |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.102:49179 195.201.225.248:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=telecut.in | be:a6:3d:e8:93:c3:13:0b:5f:1d:3a:f7:63:57:4c:39:0e:96:df:5e |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
file | C:\Program Files (x86)\Google\Chrome\Application\86.0.4240.111\Locales\ru.pak |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://45.142.215.237/ | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://45.142.215.237//l/f/nxZPunsBPvGyIjkLqZcB/38f584651402b87b6e658beea19bc3711efb647c | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://45.142.215.237//l/f/nxZPunsBPvGyIjkLqZcB/e1f57414f8caba2ca5e4d8fa52512fb00d1a14f8 | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET https://telete.in/brikitiki |
request | POST http://45.142.215.237/ |
request | GET http://45.142.215.237//l/f/nxZPunsBPvGyIjkLqZcB/38f584651402b87b6e658beea19bc3711efb647c |
request | GET http://45.142.215.237//l/f/nxZPunsBPvGyIjkLqZcB/e1f57414f8caba2ca5e4d8fa52512fb00d1a14f8 |
request | GET https://telete.in/brikitiki |
request | POST http://45.142.215.237/ |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOCK |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\bhghoamapcdpbohphigoooaddinpkbai |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\QuotaManager-journal |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\4cb013792b196a35_1 |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\4cb013792b196a35_0 |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Crashpad\metadata |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\b1152479bea6c46553d8c242ffa5edf2b0a050a7\290dcccb-9986-4f16-98a9-c54df8312e93 |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\000003.log |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\000003.log |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\databases |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\b1152479bea6c46553d8c242ffa5edf2b0a050a7\290dcccb-9986-4f16-98a9-c54df8312e93\index-dir |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\000003.log |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOG.old |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Thumbnails\000003.log |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1 |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG.old |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000003.log |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Thumbnails\LOG.old |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\index |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\b1152479bea6c46553d8c242ffa5edf2b0a050a7 |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Crashpad\reports\8dc74f67-39b6-4058-9ac1-6f782fcd0d62.dmp |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOCK |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOCK |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\previews_opt_out.db |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Last Session |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Cache\index |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\b1152479bea6c46553d8c242ffa5edf2b0a050a7\index.txt |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Cache |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Sync Data |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\index-dir\the-real-index |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Favicons |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\b1152479bea6c46553d8c242ffa5edf2b0a050a7\290dcccb-9986-4f16-98a9-c54df8312e93\52eca80efb7ea8c5_0 |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1 |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_0 |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\nssckbi.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-math-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\breakpadinjector.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-namedpipe-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-interlocked-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-convert-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\softokn3.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-libraryloader-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-process-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\IA2Marshal.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-conio-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\AccessibleHandler.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\freebl3.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\MapiProxy_InUse.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-locale-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\mozMapi32_InUse.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\libEGL.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\lgpllibs.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\nssdbm3.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-utility-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\MapiProxy.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\nss3.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\msvcp140.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-processthreads-l1-1-1.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-timezone-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\AccessibleMarshal.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-runtime-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-rtlsupport-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-util-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-synch-l1-2-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\ldif60.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-string-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-private-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\Dewgkwlbhkrsncbybkhtfpkb.vbs |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\prldap60.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-file-l1-2-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\vcruntime140.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\mozMapi32.dll |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click.pyw.lnk |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-profile-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\ucrtbase.dll |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\dd81b5e9d99588633b73117e3b1f84f1a6952f9d573057d804047a85abfb8328_1609fbf0d6c26e---38596704027.pdf.lnk |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-environment-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-processthreads-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\mozglue.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\Oggnfkemtibcinconsoleapp16.exe |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-string-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\agent.pyw.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\msi2.png.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Excel 2010.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint\Microsoft SharePoint Workspace 2010.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\Python Manuals.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\Module Docs.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\exe1.zip.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\test.eml.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Word 2010.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Access 2010.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft InfoPath Filler 2010.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\ok1.png.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\util.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\IDLE (Python GUI).lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\Settings.ini.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\³ª¶óÀåÅÍ\G2BSTOP.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\³ª¶óÀåÅÍ\G2BRUN.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HttpWatch Professional Edition\Automation Examples.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\robot2.png.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EditPlus.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HttpWatch Professional Edition\HttpWatch Automation Reference.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\GameExplorer.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\³ª¶óÀåÅÍ\Uninstall.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\doc.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\dd81b5e9d99588633b73117e3b1f84f1a6952f9d573057d804047a85abfb8328_1609fbf0d6c26e---38596704027.pdf.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft OneNote 2010.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\robot3.png.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\msoffice2010_32bit.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\doc2.png.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE (x86).lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click_image.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip Help.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\robot.png.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HttpWatch Professional Edition\HttpWatch Studio.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\KMSAuto_Net_2015_v1.4. 2.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\docx2.png.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Restore.lnk |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com |
cmdline | powershell Test-Connection -ComputerName google.com |
file | C:\Users\test22\AppData\Local\Temp\Dewgkwlbhkrsncbybkhtfpkb.vbs |
file | C:\Users\test22\AppData\Local\Temp\Oggnfkemtibcinconsoleapp16.exe |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-synch-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\AccessibleMarshal.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-locale-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\mozMapi32.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\breakpadinjector.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\prldap60.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-private-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\nss3.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-namedpipe-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\mozglue.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-libraryloader-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\MapiProxy.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\softokn3.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\vcruntime140.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-environment-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-time-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\AccessibleHandler.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-math-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-string-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-memory-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-sysinfo-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-util-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\IA2Marshal.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-processthreads-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\msvcp140.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-stdio-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\qipcap.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-utility-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-processthreads-l1-1-1.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\libEGL.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\Oggnfkemtibcinconsoleapp16.exe |
file | C:\Users\test22\AppData\LocalLow\sqlite3.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\freebl3.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\ucrtbase.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-processenvironment-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-handle-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\nssckbi.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-timezone-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\nssdbm3.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\lgpllibs.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-synch-l1-2-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-conio-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-file-l1-2-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\ldap60.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-interlocked-l1-1-0.dll |
wmi | Select * from Win32_PingStatus where ((Address='google.com') And TimeToLive=80 And BufferSize=32) |
section | {u'size_of_data': u'0x0014a600', u'virtual_address': u'0x00002000', u'entropy': 7.995324654729699, u'name': u'.text', u'virtual_size': u'0x0014a4c4'} | entropy | 7.99532465473 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x0001a800', u'virtual_address': u'0x0014e000', u'entropy': 7.596371189031652, u'name': u'.rsrc', u'virtual_size': u'0x0001a7bc'} | entropy | 7.59637118903 | description | A section with a high entropy has been found | |||||||||
entropy | 0.999649859944 | description | Overall entropy of this PE file is high |
description | Take ScreenShot | rule | ScreenShot | ||||||
description | Match Windows Http API call | rule | Str_Win32_Http_API | ||||||
description | Steal credential | rule | local_credential_Steal | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
host | 45.142.215.237 |
file | C:\ProgramData\Microsoft\Microsoft Antimalware\Network Inspection System\Support |
file | C:\ProgramData\Microsoft\Microsoft Antimalware\Network Inspection System\Support\NisLog.txt |
file | C:\ProgramData\Microsoft\Microsoft Antimalware |
file | C:\ProgramData\Microsoft\Microsoft Antimalware\Network Inspection System |
file | C:\ProgramData\Microsoft\Microsoft Security Client\Support\EppSetup.etl |
file | C:\ProgramData\Microsoft\Microsoft Security Client\Support\EppSetupResult.ini |
file | C:\ProgramData\Microsoft\Microsoft Security Client\Support\MSSecurityClient_Setup_4.10.209.0_epp_Install.log |
file | C:\ProgramData\Microsoft\Microsoft Security Client |
file | C:\ProgramData\Microsoft\Microsoft Security Client\Support\Application.etl |
file | C:\ProgramData\Microsoft\Microsoft Security Client\Support\EppSetup.log |
file | C:\ProgramData\Microsoft\Microsoft Security Client\Support\MSSecurityClient_Setup_4.10.209.0_epp_Uninstall.log |
file | C:\ProgramData\Microsoft\Microsoft Security Client\Support |
file | C:\ProgramData\Microsoft\Microsoft Security Client\Support\EppOobe.etl |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\agent.py |
file | C:\Python27\agent.pyw |