Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | Oct. 8, 2021, 8:22 a.m. | Oct. 8, 2021, 8:24 a.m. |
-
msiexec.exe "C:\Windows\System32\msiexec.exe" /I C:\Users\test22\AppData\Local\Temp\trehjugdr4et6u.msi
1636 -
explorer.exe C:\Windows\Explorer.EXE
1236
Name | Response | Post-Analysis Lookup |
---|---|---|
feristoaul.com | 46.161.40.172 |
Suricata Alerts
Suricata TLS
No Suricata TLS
suspicious_features | HTTP version 1.0 used | suspicious_request | GET http://feristoaul.com/r?x=bmFtZT10ZXN0MjItUENcdGVzdDIyJm9zPTYuMSZhcmNoPXg4NiZidWlsZD0xLjAuMg== | ||||||
suspicious_features | HTTP version 1.0 used | suspicious_request | GET http://feristoaul.com/m?x=dXVpZD03NWJhYzA4My01MzFjLTQwM2QtYTgxMC02NWM1YjVmMjMxYmM= | ||||||
suspicious_features | HTTP version 1.0 used | suspicious_request | GET http://feristoaul.com/p?x=dXVpZD03NWJhYzA4My01MzFjLTQwM2QtYTgxMC02NWM1YjVmMjMxYmM= |
request | GET http://feristoaul.com/r?x=bmFtZT10ZXN0MjItUENcdGVzdDIyJm9zPTYuMSZhcmNoPXg4NiZidWlsZD0xLjAuMg== |
request | GET http://feristoaul.com/m?x=dXVpZD03NWJhYzA4My01MzFjLTQwM2QtYTgxMC02NWM1YjVmMjMxYmM= |
request | GET http://feristoaul.com/p?x=dXVpZD03NWJhYzA4My01MzFjLTQwM2QtYTgxMC02NWM1YjVmMjMxYmM= |
Lionic | Trojan.Ruby.Agent.a!c |
Kaspersky | Trojan-Downloader.Ruby.Agent.b |
DrWeb | Ruby.Downloader.2 |
McAfee | RDN/Generic Downloader.x |