Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Sept. 13, 2021, 5:55 p.m. | Sept. 13, 2021, 5:57 p.m. |
-
java.exe "C:\Program Files (x86)\Java\jre1.8.0_131\bin\java.exe" -jar C:\Users\test22\AppData\Local\Temp\Inv_INV410599.jar
2300-
cmd.exe cmd.exe /C cscript.exe C:\Users\test22\AppData\Local\Temp\Retrive7608619414195445135.vbs
2612-
cscript.exe cscript.exe C:\Users\test22\AppData\Local\Temp\Retrive7608619414195445135.vbs
2104
-
-
cmd.exe cmd.exe /C cscript.exe C:\Users\test22\AppData\Local\Temp\Retrive6871426135152969709.vbs
2688-
cscript.exe cscript.exe C:\Users\test22\AppData\Local\Temp\Retrive6871426135152969709.vbs
2820
-
-
xcopy.exe xcopy "C:\Program Files (x86)\Java\jre1.8.0_131" "C:\Users\test22\AppData\Roaming\Oracle\" /e
2708 -
cmd.exe cmd.exe
2068 -
reg.exe reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v mIfXYPmidyd /t REG_EXPAND_SZ /d "\"C:\Users\test22\AppData\Roaming\Oracle\bin\javaw.exe\" -jar \"C:\Users\test22\DfSJGumiMVk\lXgvOTPUynR.dWJwxa\"" /f
2408 -
attrib.exe attrib +h "C:\Users\test22\DfSJGumiMVk\*.*"
2568 -
attrib.exe attrib +h "C:\Users\test22\DfSJGumiMVk"
2956 -
javaw.exe C:\Users\test22\AppData\Roaming\Oracle\bin\javaw.exe -jar C:\Users\test22\DfSJGumiMVk\lXgvOTPUynR.dWJwxa
552-
icacls.exe icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage\11e658b105eb7263.timestamp /grant "everyone":(OI)(CI)M
2780 -
cmd.exe cmd.exe /C cscript.exe C:\Users\test22\AppData\Local\Temp\Retrive6188610520026110957.vbs
2760-
cscript.exe cscript.exe C:\Users\test22\AppData\Local\Temp\Retrive6188610520026110957.vbs
1692
-
-
cmd.exe cmd.exe /C cscript.exe C:\Users\test22\AppData\Local\Temp\Retrive6961521396159326292.vbs
1608-
cscript.exe cscript.exe C:\Users\test22\AppData\Local\Temp\Retrive6961521396159326292.vbs
160
-
-
cmd.exe cmd.exe
2564 -
WMIC.exe WMIC /Node:localhost /Namespace:\\root\cimv2 Path Win32_PnpSignedDriver Get /Format:List
2808
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
143.244.165.128 | Active | Moloch |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 143.244.165.128:1231 -> 192.168.56.103:49187 | 2020728 | ET MALWARE Possible Adwind/jSocket SSL Cert (assylias.Inc) | A Network Trojan was detected |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.103:49187 143.244.165.128:1231 |
C=FR, O=assylias.Inc, CN=assylias | C=FR, O=assylias.Inc, CN=assylias | d6:2e:06:53:11:df:fc:ec:ad:9f:8e:92:c3:16:aa:fb:60:19:39:4b |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\j2pkcs11.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\deploy.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\kinit.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\sunmscapi.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jdwp.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\sunec.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\java.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jabswitch.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\pack200.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\gstreamer-lite.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jsoundds.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\net.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\management.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\plugin2\msvcr100.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\msvcp120.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jp2native.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\javaws.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jaas_nt.dll |
file | C:\Users\test22\AppData\Local\Temp\Retrive7608619414195445135.vbs |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\fxplugins.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\hprof.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\nio.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\ssv.dll |
file | C:\Users\test22\AppData\Local\Temp\Retrive6188610520026110957.vbs |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\keytool.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\ssvagent.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jp2ssv.dll |
file | C:\Users\test22\AppData\Local\Temp\Retrive6871426135152969709.vbs |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jjs.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jp2iexp.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\javacpl.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\instrument.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\policytool.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\klist.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\javaw.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\lcms.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\WindowsAccessBridge-32.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\JAWTAccessBridge-32.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\ktab.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\npt.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\prism_sw.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\dcpr.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\zip.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\verify.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\glass.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\decora_sse.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\java_crw_demo.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jawt.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\dt_shmem.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jfr.dll |
cmdline | cmd.exe |
cmdline | cmd.exe /C cscript.exe C:\Users\test22\AppData\Local\Temp\Retrive6871426135152969709.vbs |
cmdline | cmd.exe /C cscript.exe C:\Users\test22\AppData\Local\Temp\Retrive6961521396159326292.vbs |
cmdline | cmd.exe /C cscript.exe C:\Users\test22\AppData\Local\Temp\Retrive7608619414195445135.vbs |
cmdline | cmd.exe /C cscript.exe C:\Users\test22\AppData\Local\Temp\Retrive6188610520026110957.vbs |
cmdline | WMIC /Node:localhost /Namespace:\\root\cimv2 Path Win32_PnpSignedDriver Get /Format:List |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jsoundds.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\unpack.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\awt.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\kinit.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\net.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jaas_nt.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\dt_shmem.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\javafx_font.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\javafx_iio.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jp2launcher.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jfxwebkit.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\glib-lite.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\java-rmi.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\keytool.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\client\jvm.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\msvcr120.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jli.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\t2k.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\management.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\fontmanager.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jp2ssv.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\java_crw_demo.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\prism_d3d.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\msvcp120.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\wsdetect.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jsdt.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\resource.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\plugin2\npjp2.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\j2pcsc.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\ssvagent.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\orbd.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\j2pkcs11.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\prism_sw.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jpeg.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\dcpr.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jfr.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\instrument.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\mlib_image.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\tnameserv.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\splashscreen.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\sunmscapi.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\hprof.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\deploy.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\npt.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jawt.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\javafx_font_t2k.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\policytool.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\jabswitch.exe |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\gstreamer-lite.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\rmid.exe |
cmdline | attrib +h "C:\Users\test22\DfSJGumiMVk" |
cmdline | attrib +h "C:\Users\test22\DfSJGumiMVk\*.*" |
cmdline | reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v mIfXYPmidyd /t REG_EXPAND_SZ /d "\"C:\Users\test22\AppData\Roaming\Oracle\bin\javaw.exe\" -jar \"C:\Users\test22\DfSJGumiMVk\lXgvOTPUynR.dWJwxa\"" /f |
cmdline | WMIC /Node:localhost /Namespace:\\root\cimv2 Path Win32_PnpSignedDriver Get /Format:List |
host | 143.244.165.128 |
reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\mIfXYPmidyd | reg_value | "C:\Users\test22\AppData\Roaming\Oracle\bin\javaw.exe" -jar "C:\Users\test22\DfSJGumiMVk\lXgvOTPUynR.dWJwxa" |
file | C:\Users\test22\AppData\Local\Temp\Retrive6871426135152969709.vbs |
wmi | Select * from AntiVirusProduct |
wmi | Select * from FirewallProduct |
wmi | SELECT * FROM Win32_PnpSignedDriver |
cmdline | icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage\11e658b105eb7263.timestamp /grant "everyone":(OI)(CI)M |
file | C:\Users\test22\AppData\Local\Temp\Windows2173301012068462979.dll |
file | C:\Users\test22\AppData\Roaming\Oracle\bin\javaw.exe |
Lionic | Trojan.Java.Adwind.m!c |
ClamAV | Java.Trojan.Adwind-6 |
Alibaba | Backdoor:JAVA/Adwind.0c21ebf9 |
Arcabit | Trojan.Generic.D23D24CC |
ESET-NOD32 | multiple detections |
Avast | Java:Malware-gen [Trj] |
Kaspersky | HEUR:Backdoor.Java.Adwind.gen |
BitDefender | Trojan.GenericKD.37561548 |
NANO-Antivirus | Exploit.Zip.Heuristic-java.csrvpr |
MicroWorld-eScan | Trojan.GenericKD.37561548 |
Ad-Aware | Trojan.GenericKD.37561548 |
Emsisoft | Trojan.GenericKD.37561548 (B) |
McAfee-GW-Edition | Adwind!jar |
FireEye | Trojan.GenericKD.37561548 |
Ikarus | Trojan.Java.Adwind |
GData | Trojan.GenericKD.37561548 |
ZoneAlarm | HEUR:Backdoor.Java.Adwind.gen |
McAfee | Adwind!jar |
MAX | malware (ai score=88) |
Zoner | Probably Heur.JARAgent |
AVG | Java:Malware-gen [Trj] |