Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | Sept. 7, 2021, 8:22 a.m. | Sept. 7, 2021, 8:40 a.m. |
Name | Response | Post-Analysis Lookup |
---|---|---|
slx-wave.duckdns.org | 23.146.242.71 | |
sol-bin.duckdns.org | 23.146.242.85 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.56.102:64995 -> 164.124.101.2:53 | 2022918 | ET INFO DYNAMIC_DNS Query to *.duckdns. Domain | Misc activity |
UDP 192.168.56.102:52336 -> 164.124.101.2:53 | 2022918 | ET INFO DYNAMIC_DNS Query to *.duckdns. Domain | Misc activity |
Suricata TLS
No Suricata TLS
resource name | CUSTOM |
domain | slx-wave.duckdns.org |
domain | sol-bin.duckdns.org |
request | GET http://sol-bin.duckdns.org/Remcos_S_tGNeLX139.bin |
host | 104.21.19.200 |
Bkav | W32.AIDetect.malware2 |
Elastic | malicious (high confidence) |
ClamAV | Win.Dropper.Guloader-9890276-0 |
McAfee | GuLoader-FCQZ!CD46DBF532B0 |
Cylance | Unsafe |
Sangfor | Trojan.Win32.Save.a |
K7GW | Trojan-Downloader ( 005661971 ) |
Cybereason | malicious.d1de42 |
ESET-NOD32 | Win32/TrojanDownloader.Agent.FCS |
APEX | Malicious |
Paloalto | generic.ml |
Kaspersky | UDS:DangerousObject.Multi.Generic |
BitDefender | Gen:Variant.Bulz.681383 |
MicroWorld-eScan | Gen:Variant.Bulz.681383 |
Avast | Win32:Trojan-gen |
Ad-Aware | Gen:Variant.Bulz.681383 |
Comodo | Malware@#37rrcy6fahxes |
McAfee-GW-Edition | GuLoader-FCQZ!CD46DBF532B0 |
FireEye | Generic.mg.cd46dbf532b047ca |
Ikarus | Trojan.Win32.Krypt |
eGambit | Unsafe.AI_Score_100% |
MAX | malware (ai score=85) |
Kingsoft | Win32.Troj.Generic_a.a.(kcloud) |
GData | Gen:Variant.Bulz.681383 |
AhnLab-V3 | Trojan/Win.Sabsik.C4622888 |
Malwarebytes | Trojan.MalPack.VB |
SentinelOne | Static AI - Malicious PE |
MaxSecure | Trojan.Malware.300983.susgen |
Fortinet | W32/Malicious_Behavior.VEX |
Webroot | W32.Trojan.Gen |
AVG | Win32:Trojan-gen |
CrowdStrike | win/malicious_confidence_90% (W) |
dead_host | 192.168.56.102:49172 |
dead_host | 192.168.56.102:49187 |
dead_host | 192.168.56.102:49176 |
dead_host | 192.168.56.102:49191 |
dead_host | 192.168.56.102:49171 |
dead_host | 192.168.56.102:49180 |
dead_host | 192.168.56.102:49175 |
dead_host | 192.168.56.102:49186 |
dead_host | 192.168.56.102:49166 |
dead_host | 192.168.56.102:49179 |
dead_host | 192.168.56.102:49190 |
dead_host | 192.168.56.102:49170 |
dead_host | 23.146.242.71:2222 |
dead_host | 192.168.56.102:49183 |
dead_host | 192.168.56.102:49174 |
dead_host | 192.168.56.102:49178 |
dead_host | 192.168.56.102:49185 |
dead_host | 192.168.56.102:49182 |
dead_host | 192.168.56.102:49189 |
dead_host | 192.168.56.102:49169 |
dead_host | 192.168.56.102:49173 |
dead_host | 192.168.56.102:49184 |
dead_host | 23.146.242.71:1111 |
dead_host | 192.168.56.102:49177 |
dead_host | 192.168.56.102:49188 |
dead_host | 192.168.56.102:49168 |
dead_host | 192.168.56.102:49181 |
dead_host | 192.168.56.102:49192 |