Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Sept. 13, 2021, 8:51 a.m. | Sept. 13, 2021, 8:58 a.m. |
-
-
schtasks.exe /C /create /F /sc minute /mo 1 /tn "Azure-Update-Task" /tr "C:\Users\test22\AppData\Roaming\Microsoft\Network\sihost.exe"
1684
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | .data0 |
section | .data1 |
section | {u'size_of_data': u'0x004bec00', u'virtual_address': u'0x002d5000', u'entropy': 7.945538836690714, u'name': u'.data1', u'virtual_size': u'0x004bea30'} | entropy | 7.94553883669 | description | A section with a high entropy has been found | |||||||||
entropy | 0.997536440156 | description | Overall entropy of this PE file is high |
cmdline | /C /create /F /sc minute /mo 1 /tn "Azure-Update-Task" /tr "C:\Users\test22\AppData\Roaming\Microsoft\Network\sihost.exe" |