Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Oct. 14, 2021, 4:09 p.m. | Oct. 14, 2021, 4:11 p.m. |
-
EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Office15\EXCEL.EXE" C:\Users\test22\AppData\Local\Temp\art-717340505.xls
2600-
regsvr32.exe "C:\Windows\System32\regsvr32.exe" C:\Datop\test.test
2820 -
regsvr32.exe "C:\Windows\System32\regsvr32.exe" C:\Datop\test2.test
3060 -
regsvr32.exe "C:\Windows\System32\regsvr32.exe" C:\Datop\test1.test
2868
-
Name | Response | Post-Analysis Lookup |
---|---|---|
pmqdermatology.com.au | 101.0.119.207 | |
bostonavenue.org | 216.172.187.35 | |
funzy.id | 194.233.72.245 | |
x1.i.lencr.org | 104.74.211.103 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49172 101.0.119.207:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pmqdermatology.com.au | 2a:97:18:3e:9b:72:60:41:c7:40:31:30:3f:d1:14:c6:01:79:a0:73 |
request | GET http://x1.i.lencr.org/ |
cmdline | regsvr32 C:\Datop\test.test |
cmdline | "C:\Windows\System32\regsvr32.exe" C:\Datop\test2.test |
cmdline | "C:\Windows\System32\regsvr32.exe" C:\Datop\test1.test |
cmdline | "C:\Windows\System32\regsvr32.exe" C:\Datop\test.test |
cmdline | regsvr32 C:\Datop\test1.test |
cmdline | regsvr32 C:\Datop\test2.test |
parent_process | excel.exe | martian_process | regsvr32 C:\Datop\test.test | ||||||
parent_process | excel.exe | martian_process | "C:\Windows\System32\regsvr32.exe" C:\Datop\test2.test | ||||||
parent_process | excel.exe | martian_process | "C:\Windows\System32\regsvr32.exe" C:\Datop\test1.test | ||||||
parent_process | excel.exe | martian_process | "C:\Windows\System32\regsvr32.exe" C:\Datop\test.test | ||||||
parent_process | excel.exe | martian_process | regsvr32 C:\Datop\test1.test | ||||||
parent_process | excel.exe | martian_process | regsvr32 C:\Datop\test2.test |
file | C:\Windows\System32\regsvr32.exe |