Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 5, 2021, 5:45 p.m. | Oct. 5, 2021, 5:47 p.m. |
IP Address | Status | Action |
---|---|---|
121.254.178.253 | Active | Moloch |
134.122.133.133 | Active | Moloch |
145.131.10.226 | Active | Moloch |
150.95.54.145 | Active | Moloch |
164.124.101.2 | Active | Moloch |
185.46.123.48 | Active | Moloch |
198.54.121.137 | Active | Moloch |
2.57.90.16 | Active | Moloch |
209.17.116.163 | Active | Moloch |
23.227.38.74 | Active | Moloch |
45.35.13.43 | Active | Moloch |
91.184.0.100 | Active | Moloch |
92.205.12.148 | Active | Moloch |
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.adult-affi2401.com/p08r/?b6A=YBD8ehEBguM+6gGh+VaunkeJelFsPauf8nWvRLa2Q8b5I/eD3+1cxq8HW72tGpOj6qnVLgtZ&D8S=_FNHAt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.kennycheng.tech/p08r/?b6A=RPRpMFG5DiuH4Me2ReofCDIxeK3pjVq+7UTLX2dtWYx9bGYak7LoJY9NsO7Y0IdpYyXG1k8C&D8S=_FNHAt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.lockolock.com/p08r/?b6A=BojzXC5XtUXJCn/sviLjp1FSKX3F4rfFxOtL/HTn2WsxIabSXw8AIYc51ovw4Dh6Oxhyfgcs&D8S=_FNHAt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.serviciomovistar.online/p08r/?b6A=F620ax2IXshNfJXYyz520Uk8ZUO6TkBejSV6e6QrtPv/Tnjc0fjbzMUqFeGXtuHmpTp57JhT&D8S=_FNHAt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.globalservicesproviders.com/p08r/?b6A=kc0HlcHOykXtlE83QAp9W1Y7yFJ/9Iqs5v9tv8rxcf4fEK7gRz8fegFivJuBABnMLio7jmeg&D8S=_FNHAt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.puremicrodosing.com/p08r/?b6A=S62BtV/OXf7l+Oi9TcRmwChwada/mHY3jxfUfEoy5xEvr99fIfi+QJg3WuTcsjgo8nY7wmXr&D8S=_FNHAt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.cyworldl.com/p08r/?b6A=NwV8JJ6ZJlAEmD5b4H2bl/w3OwpG2MFDo8NShXAeVJkYkzdeWNbXotIvNWoszNS/7oJ1T3z8&D8S=_FNHAt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.cameroon-infos.net/p08r/?b6A=IYc7WM2wy7ET8TsfVSWUiPW1jV3rdQu07vYpL+EaMYvNKjdhepHWyqeEAJ8IIY8trn3trjsC&D8S=_FNHAt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.989451.com/p08r/?b6A=wgGfLhEduyoESPnrST6AXTlsvRUW71KfhZuOrHw7TI51lUsZgWgyOnM3Xtx4zYYaTke8CEyN&D8S=_FNHAt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.consumersvoice.net/p08r/?b6A=R7Z4cCaC1e2zv+EAWAiOXCWhjhnPFC37ZRsWBv89zgeIsWdkaTqQTyClsbCcSyhG48O6u0Ah&D8S=_FNHAt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.clarysvillemotel.online/p08r/?b6A=/y0eURr3ltnoyVqmCF5+hABmIP5vOnvBOsV4557ulpQQHqCgOASkt/vB2/md2DwCkqo9P7oS&D8S=_FNHAt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.flintandfern.com/p08r/?b6A=Ig7E2VbjhUNLzfDSaZHXL8/SDch0w/CqTC9CFS6jYTZ7o1whS6OcAV/jB/WfzBNJNz1c2WE1&D8S=_FNHAt |
request | POST http://www.adult-affi2401.com/p08r/ |
request | GET http://www.adult-affi2401.com/p08r/?b6A=YBD8ehEBguM+6gGh+VaunkeJelFsPauf8nWvRLa2Q8b5I/eD3+1cxq8HW72tGpOj6qnVLgtZ&D8S=_FNHAt |
request | POST http://www.kennycheng.tech/p08r/ |
request | GET http://www.kennycheng.tech/p08r/?b6A=RPRpMFG5DiuH4Me2ReofCDIxeK3pjVq+7UTLX2dtWYx9bGYak7LoJY9NsO7Y0IdpYyXG1k8C&D8S=_FNHAt |
request | POST http://www.lockolock.com/p08r/ |
request | GET http://www.lockolock.com/p08r/?b6A=BojzXC5XtUXJCn/sviLjp1FSKX3F4rfFxOtL/HTn2WsxIabSXw8AIYc51ovw4Dh6Oxhyfgcs&D8S=_FNHAt |
request | POST http://www.serviciomovistar.online/p08r/ |
request | GET http://www.serviciomovistar.online/p08r/?b6A=F620ax2IXshNfJXYyz520Uk8ZUO6TkBejSV6e6QrtPv/Tnjc0fjbzMUqFeGXtuHmpTp57JhT&D8S=_FNHAt |
request | POST http://www.globalservicesproviders.com/p08r/ |
request | GET http://www.globalservicesproviders.com/p08r/?b6A=kc0HlcHOykXtlE83QAp9W1Y7yFJ/9Iqs5v9tv8rxcf4fEK7gRz8fegFivJuBABnMLio7jmeg&D8S=_FNHAt |
request | POST http://www.puremicrodosing.com/p08r/ |
request | GET http://www.puremicrodosing.com/p08r/?b6A=S62BtV/OXf7l+Oi9TcRmwChwada/mHY3jxfUfEoy5xEvr99fIfi+QJg3WuTcsjgo8nY7wmXr&D8S=_FNHAt |
request | POST http://www.cyworldl.com/p08r/ |
request | GET http://www.cyworldl.com/p08r/?b6A=NwV8JJ6ZJlAEmD5b4H2bl/w3OwpG2MFDo8NShXAeVJkYkzdeWNbXotIvNWoszNS/7oJ1T3z8&D8S=_FNHAt |
request | POST http://www.cameroon-infos.net/p08r/ |
request | GET http://www.cameroon-infos.net/p08r/?b6A=IYc7WM2wy7ET8TsfVSWUiPW1jV3rdQu07vYpL+EaMYvNKjdhepHWyqeEAJ8IIY8trn3trjsC&D8S=_FNHAt |
request | POST http://www.989451.com/p08r/ |
request | GET http://www.989451.com/p08r/?b6A=wgGfLhEduyoESPnrST6AXTlsvRUW71KfhZuOrHw7TI51lUsZgWgyOnM3Xtx4zYYaTke8CEyN&D8S=_FNHAt |
request | POST http://www.consumersvoice.net/p08r/ |
request | GET http://www.consumersvoice.net/p08r/?b6A=R7Z4cCaC1e2zv+EAWAiOXCWhjhnPFC37ZRsWBv89zgeIsWdkaTqQTyClsbCcSyhG48O6u0Ah&D8S=_FNHAt |
request | POST http://www.clarysvillemotel.online/p08r/ |
request | GET http://www.clarysvillemotel.online/p08r/?b6A=/y0eURr3ltnoyVqmCF5+hABmIP5vOnvBOsV4557ulpQQHqCgOASkt/vB2/md2DwCkqo9P7oS&D8S=_FNHAt |
request | POST http://www.flintandfern.com/p08r/ |
request | GET http://www.flintandfern.com/p08r/?b6A=Ig7E2VbjhUNLzfDSaZHXL8/SDch0w/CqTC9CFS6jYTZ7o1whS6OcAV/jB/WfzBNJNz1c2WE1&D8S=_FNHAt |
request | POST http://www.adult-affi2401.com/p08r/ |
request | POST http://www.kennycheng.tech/p08r/ |
request | POST http://www.lockolock.com/p08r/ |
request | POST http://www.serviciomovistar.online/p08r/ |
request | POST http://www.globalservicesproviders.com/p08r/ |
request | POST http://www.puremicrodosing.com/p08r/ |
request | POST http://www.cyworldl.com/p08r/ |
request | POST http://www.cameroon-infos.net/p08r/ |
request | POST http://www.989451.com/p08r/ |
request | POST http://www.consumersvoice.net/p08r/ |
request | POST http://www.clarysvillemotel.online/p08r/ |
request | POST http://www.flintandfern.com/p08r/ |
file | C:\Users\test22\AppData\Local\Temp\nsb63D4.tmp\xkbzkendk.dll |
file | C:\Users\test22\AppData\Local\Temp\nsb63D4.tmp\xkbzkendk.dll |
Bkav | W32.AIDetect.malware2 |
Lionic | Trojan.Win32.Malicious.4!c |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Zum.Androm.1 |
FireEye | Generic.mg.d41f65d9b8b141d4 |
Cylance | Unsafe |
Sangfor | Trojan.Win32.Save.a |
Cybereason | malicious.9b8b14 |
Arcabit | Zum.Androm.1 |
BitDefenderTheta | Gen:NN.ZedlaF.34170.gu4@amcldrai |
Paloalto | generic.ml |
Kaspersky | UDS:Trojan-Spy.Win32.Noon.gen |
BitDefender | Zum.Androm.1 |
APEX | Malicious |
Emsisoft | Zum.Androm.1 (B) |
McAfee-GW-Edition | BehavesLike.Win32.BadFile.dc |
Sophos | Mal/Generic-R |
Microsoft | Trojan:Script/Phonzy.B!ml |
GData | Zum.Androm.1 |
Cynet | Malicious (score: 100) |
McAfee | Artemis!D41F65D9B8B1 |
MAX | malware (ai score=86) |
Avast | FileRepMalware |
SentinelOne | Static AI - Malicious PE |
Fortinet | W32/Injector.EQFJ!tr |
AVG | FileRepMalware |