Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Sept. 29, 2021, 4:17 p.m. | Sept. 29, 2021, 4:19 p.m. |
-
EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Office15\EXCEL.EXE" C:\Users\test22\AppData\Local\Temp\CompensationClaim-1630636598-09282021.xls
2364-
regsvr32.exe regsvr32 -silent ..\Drezd.red
1716 -
regsvr32.exe regsvr32 -silent ..\Drezd1.red
2544 -
regsvr32.exe regsvr32 -silent ..\Drezd2.red
2264
-
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
cmdline | regsvr32 -silent ..\Drezd1.red |
cmdline | regsvr32 -silent ..\Drezd2.red |
cmdline | regsvr32 -silent ..\Drezd.red |
McAfee | X97M/Downloader.ln |
Cyren | X97M/Downldr.TS.gen!Eldorado |
TrendMicro-HouseCall | TROJ_FRS.VSNTIS21 |
BitDefender | VB:Trojan.VBA.Agent.BLB |
McAfee-GW-Edition | Artemis!Trojan |
host | 185.141.27.213 | |||
host | 190.14.37.187 | |||
host | 94.140.112.126 |
parent_process | excel.exe | martian_process | regsvr32 -silent ..\Drezd1.red | ||||||
parent_process | excel.exe | martian_process | regsvr32 -silent ..\Drezd2.red | ||||||
parent_process | excel.exe | martian_process | regsvr32 -silent ..\Drezd.red |
dead_host | 94.140.112.126:80 |
dead_host | 190.14.37.187:80 |
dead_host | 185.141.27.213:80 |