Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 18, 2021, 5:53 p.m. | Oct. 18, 2021, 5:56 p.m. |
-
WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE" C:\Users\test22\AppData\Local\Temp\invc_009030009.wbk
1108
IP Address | Status | Action |
---|---|---|
104.21.30.231 | Active | Moloch |
108.186.180.79 | Active | Moloch |
154.208.173.145 | Active | Moloch |
156.234.138.23 | Active | Moloch |
164.124.101.2 | Active | Moloch |
170.178.168.203 | Active | Moloch |
172.104.153.244 | Active | Moloch |
173.212.200.118 | Active | Moloch |
185.28.21.80 | Active | Moloch |
192.3.110.172 | Active | Moloch |
208.113.163.16 | Active | Moloch |
209.99.64.33 | Active | Moloch |
3.223.115.185 | Active | Moloch |
34.102.136.180 | Active | Moloch |
64.190.62.111 | Active | Moloch |
Suricata Alerts
Suricata TLS
No Suricata TLS
suspicious_features | Connection to IP address | suspicious_request | GET http://192.3.110.172/006600066/vbc.exe | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.desongli.com/mxnu/?ytsDIrP=hZ80obWBB1Dtx9mJDJ/B6KhSbXm9N4IXZ9kDZpitpQpTEQWdqR+8a/o3g7qjE+O8VqYt5r7Y&JlM=tnt48PpXYxvL | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.closetu.com/mxnu/?ytsDIrP=rJ249TMVQMCwGwXS7eMNhvOWH4SbGXiKs4Vq1JHmstm/5V4DyV8c/XoA/4BgaERVtEbRuzyC&JlM=tnt48PpXYxvL | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.tbrhc.com/mxnu/?ytsDIrP=dBbPwQ2utUd0Fk1uS+XSFkxz2YTUNCneFR1VLIh1vAwAXkSpHWWkzNznjyqcoekG5m5H1qts&JlM=tnt48PpXYxvL | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.naplesconciergerealty.com/mxnu/?ytsDIrP=hecv2sMFcvsyFIpzJOhZbtwMh1SG6St5/U1aPglBFWownzq2qPNpvMi/ho6Sg43JWpVw027R&JlM=tnt48PpXYxvL | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.whitebot.xyz/mxnu/?ytsDIrP=mJKlLoR4AxZK/RYIFKAo0UiVtoPyzBJ6SQAFXLfvSOBYEGo1cqGoAX7CRK1QxANrckFntybM&JlM=tnt48PpXYxvL | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.mortgagerates.solutions/mxnu/?ytsDIrP=e40TMWWr6xWVnQ1HwCqLobeJF4L/Z7xCu7/MTKlaRXTCRzwsua34O9neh9w9TPhFkJc6vnSR&JlM=tnt48PpXYxvL | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.brandonhistoryandinfo.com/mxnu/?ytsDIrP=TBa+b5mpCdI4y/h180Pl2gJXBklETz7DPBwfCQzHJDv5/wBYQn0JU1W1LmmZ4xHxKrhvcr9L&JlM=tnt48PpXYxvL | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.normandia.pro/mxnu/?ytsDIrP=kHN/hbjK4OzLmo333toUUHv3cKFKy5bivtfKIua2AYmutZDuFn6HD/HyblDUos2+bUTS6mEe&JlM=tnt48PpXYxvL | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.onehigh.club/mxnu/?ytsDIrP=52TJ8f0Vxw2BzXpbfWSfaWlDTRlua2mq3mQuHpcP7nL3PE2hO33OHCZ6ItQZVKuqvI9FSTzz&JlM=tnt48PpXYxvL | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.safebookkeeping.com/mxnu/?ytsDIrP=Dinuu19hFboSFju1K0HZ6EbcdDMO+ZnQ9sDSjm9DAS1j/pnpew28zT8+4dAfvZHXXiVk+x1O&JlM=tnt48PpXYxvL | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.sattaking-gaziabad.xyz/mxnu/?ytsDIrP=UvUEtIev0LW0Fj9rimgEuaxF8o8Q3PSD9GE10acJUnczNTSiUTsn1kpqflxWWG28G9vjgVED&JlM=tnt48PpXYxvL | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.ingdalynnia.xyz/mxnu/?ytsDIrP=pfZfepvuuXd3YdzLhx74JhtQE2ZsQUx19b2XlYunhcRs71ErzSq2ECWFO+pn1SXrM1L87AtC&JlM=tnt48PpXYxvL | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.historyofcambridge.com/mxnu/?ytsDIrP=83rAwycDMUEJxLGVulxgJoLHCAQKcanhrm8XweUEKHeaWBLa77jLvzg0UgbAuk5RNaMObh69&JlM=tnt48PpXYxvL | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.revgeek.com/mxnu/?ytsDIrP=LFHT7yJDHTG5j2x991585jkXyYBkZkjzIUaPFc8bTKfmXG7pnxx1T4PiHIQyjDj8X+wed1XV&JlM=tnt48PpXYxvL | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.jellyice-tr.com/mxnu/?ytsDIrP=2jYCrBsbpe7TX9aPhZM9pCxr75im0gQU84tPJTFdoXWJ8jmtmSvNbVsQgFqr9XIl+R+lpCoE&JlM=tnt48PpXYxvL |
request | GET http://192.3.110.172/006600066/vbc.exe |
request | POST http://www.desongli.com/mxnu/ |
request | GET http://www.desongli.com/mxnu/?ytsDIrP=hZ80obWBB1Dtx9mJDJ/B6KhSbXm9N4IXZ9kDZpitpQpTEQWdqR+8a/o3g7qjE+O8VqYt5r7Y&JlM=tnt48PpXYxvL |
request | POST http://www.closetu.com/mxnu/ |
request | GET http://www.closetu.com/mxnu/?ytsDIrP=rJ249TMVQMCwGwXS7eMNhvOWH4SbGXiKs4Vq1JHmstm/5V4DyV8c/XoA/4BgaERVtEbRuzyC&JlM=tnt48PpXYxvL |
request | POST http://www.tbrhc.com/mxnu/ |
request | GET http://www.tbrhc.com/mxnu/?ytsDIrP=dBbPwQ2utUd0Fk1uS+XSFkxz2YTUNCneFR1VLIh1vAwAXkSpHWWkzNznjyqcoekG5m5H1qts&JlM=tnt48PpXYxvL |
request | POST http://www.naplesconciergerealty.com/mxnu/ |
request | GET http://www.naplesconciergerealty.com/mxnu/?ytsDIrP=hecv2sMFcvsyFIpzJOhZbtwMh1SG6St5/U1aPglBFWownzq2qPNpvMi/ho6Sg43JWpVw027R&JlM=tnt48PpXYxvL |
request | POST http://www.whitebot.xyz/mxnu/ |
request | GET http://www.whitebot.xyz/mxnu/?ytsDIrP=mJKlLoR4AxZK/RYIFKAo0UiVtoPyzBJ6SQAFXLfvSOBYEGo1cqGoAX7CRK1QxANrckFntybM&JlM=tnt48PpXYxvL |
request | POST http://www.mortgagerates.solutions/mxnu/ |
request | GET http://www.mortgagerates.solutions/mxnu/?ytsDIrP=e40TMWWr6xWVnQ1HwCqLobeJF4L/Z7xCu7/MTKlaRXTCRzwsua34O9neh9w9TPhFkJc6vnSR&JlM=tnt48PpXYxvL |
request | POST http://www.brandonhistoryandinfo.com/mxnu/ |
request | GET http://www.brandonhistoryandinfo.com/mxnu/?ytsDIrP=TBa+b5mpCdI4y/h180Pl2gJXBklETz7DPBwfCQzHJDv5/wBYQn0JU1W1LmmZ4xHxKrhvcr9L&JlM=tnt48PpXYxvL |
request | POST http://www.normandia.pro/mxnu/ |
request | GET http://www.normandia.pro/mxnu/?ytsDIrP=kHN/hbjK4OzLmo333toUUHv3cKFKy5bivtfKIua2AYmutZDuFn6HD/HyblDUos2+bUTS6mEe&JlM=tnt48PpXYxvL |
request | POST http://www.onehigh.club/mxnu/ |
request | GET http://www.onehigh.club/mxnu/?ytsDIrP=52TJ8f0Vxw2BzXpbfWSfaWlDTRlua2mq3mQuHpcP7nL3PE2hO33OHCZ6ItQZVKuqvI9FSTzz&JlM=tnt48PpXYxvL |
request | POST http://www.safebookkeeping.com/mxnu/ |
request | GET http://www.safebookkeeping.com/mxnu/?ytsDIrP=Dinuu19hFboSFju1K0HZ6EbcdDMO+ZnQ9sDSjm9DAS1j/pnpew28zT8+4dAfvZHXXiVk+x1O&JlM=tnt48PpXYxvL |
request | POST http://www.sattaking-gaziabad.xyz/mxnu/ |
request | GET http://www.sattaking-gaziabad.xyz/mxnu/?ytsDIrP=UvUEtIev0LW0Fj9rimgEuaxF8o8Q3PSD9GE10acJUnczNTSiUTsn1kpqflxWWG28G9vjgVED&JlM=tnt48PpXYxvL |
request | POST http://www.ingdalynnia.xyz/mxnu/ |
request | GET http://www.ingdalynnia.xyz/mxnu/?ytsDIrP=pfZfepvuuXd3YdzLhx74JhtQE2ZsQUx19b2XlYunhcRs71ErzSq2ECWFO+pn1SXrM1L87AtC&JlM=tnt48PpXYxvL |
request | POST http://www.historyofcambridge.com/mxnu/ |
request | GET http://www.historyofcambridge.com/mxnu/?ytsDIrP=83rAwycDMUEJxLGVulxgJoLHCAQKcanhrm8XweUEKHeaWBLa77jLvzg0UgbAuk5RNaMObh69&JlM=tnt48PpXYxvL |
request | POST http://www.revgeek.com/mxnu/ |
request | GET http://www.revgeek.com/mxnu/?ytsDIrP=LFHT7yJDHTG5j2x991585jkXyYBkZkjzIUaPFc8bTKfmXG7pnxx1T4PiHIQyjDj8X+wed1XV&JlM=tnt48PpXYxvL |
request | POST http://www.jellyice-tr.com/mxnu/ |
request | GET http://www.jellyice-tr.com/mxnu/?ytsDIrP=2jYCrBsbpe7TX9aPhZM9pCxr75im0gQU84tPJTFdoXWJ8jmtmSvNbVsQgFqr9XIl+R+lpCoE&JlM=tnt48PpXYxvL |
request | POST http://www.desongli.com/mxnu/ |
request | POST http://www.closetu.com/mxnu/ |
request | POST http://www.tbrhc.com/mxnu/ |
request | POST http://www.naplesconciergerealty.com/mxnu/ |
request | POST http://www.whitebot.xyz/mxnu/ |
request | POST http://www.mortgagerates.solutions/mxnu/ |
request | POST http://www.brandonhistoryandinfo.com/mxnu/ |
request | POST http://www.normandia.pro/mxnu/ |
request | POST http://www.onehigh.club/mxnu/ |
request | POST http://www.safebookkeeping.com/mxnu/ |
request | POST http://www.sattaking-gaziabad.xyz/mxnu/ |
request | POST http://www.ingdalynnia.xyz/mxnu/ |
request | POST http://www.historyofcambridge.com/mxnu/ |
request | POST http://www.revgeek.com/mxnu/ |
request | POST http://www.jellyice-tr.com/mxnu/ |
filetype_details | Rich Text Format data, unknown version | filename | invc_009030009.wbk |
host | 192.3.110.172 |