Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 6, 2021, 1:30 p.m. | Oct. 6, 2021, 1:37 p.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\zadyx2.dll,DllRegisterServer
1080-
wermgr.exe C:\Windows\system32\wermgr.exe
2888
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\zadyx2.dll,
2216
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49203 36.91.117.231:443 |
ST=none | ST=none | 51:f6:96:68:b9:85:de:2e:cb:f1:2d:04:93:c2:c2:e9:5b:d8:87:93 |
TLSv1 192.168.56.101:49205 202.65.119.162:443 |
ST=none | ST=none | 79:8d:be:e6:74:09:12:d6:a9:b1:03:9f:dd:70:b2:3e:be:89:56:b5 |
TLSv1 192.168.56.101:49202 36.95.23.89:443 |
C=TT, ST=Sjælland, L=Odense, O=Avila, Schmidt and Perez, CN=perkins.com/emailAddress=cspears@middleton-miles.net | C=TT, ST=Sjælland, L=Odense, O=Avila, Schmidt and Perez, CN=perkins.com/emailAddress=cspears@middleton-miles.net | aa:be:5c:4b:00:f1:7b:31:6d:25:f1:5b:1e:83:10:f5:ee:62:7a:01 |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
suspicious_features | Connection to IP address | suspicious_request | GET https://36.95.23.89/zvs1/TEST22-PC_W617601.723BB372D71E9EB776C1B15A8BB34EF1/5/kps/ | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET https://36.91.117.231/zvs1/TEST22-PC_W617601.723BB372D71E9EB776C1B15A8BB34EF1/5/kps/ | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET https://202.65.119.162/zvs1/TEST22-PC_W617601.723BB372D71E9EB776C1B15A8BB34EF1/5/kps/ |
request | GET https://36.95.23.89/zvs1/TEST22-PC_W617601.723BB372D71E9EB776C1B15A8BB34EF1/5/kps/ |
request | GET https://36.91.117.231/zvs1/TEST22-PC_W617601.723BB372D71E9EB776C1B15A8BB34EF1/5/kps/ |
request | GET https://202.65.119.162/zvs1/TEST22-PC_W617601.723BB372D71E9EB776C1B15A8BB34EF1/5/kps/ |
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00037324 | size | 0x00000128 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00037324 | size | 0x00000128 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00039004 | size | 0x00000022 | ||||||||||||||||||
name | RT_HTML | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0003933c | size | 0x00038333 |
section | {u'size_of_data': u'0x0003d000', u'virtual_address': u'0x00035000', u'entropy': 7.904513834501354, u'name': u'.rsrc', u'virtual_size': u'0x0003c6c8'} | entropy | 7.9045138345 | description | A section with a high entropy has been found | |||||||||
entropy | 0.516949152542 | description | Overall entropy of this PE file is high |
host | 117.222.57.92 | |||
host | 202.65.119.162 | |||
host | 36.91.117.231 | |||
host | 36.95.23.89 |
dead_host | 192.168.56.101:49204 |
dead_host | 117.222.57.92:443 |