Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 18, 2021, 6:10 p.m. | Oct. 18, 2021, 6:12 p.m. |
IP Address | Status | Action |
---|---|---|
1.32.254.106 | Active | Moloch |
108.186.180.79 | Active | Moloch |
158.69.52.184 | Active | Moloch |
164.124.101.2 | Active | Moloch |
172.247.0.172 | Active | Moloch |
184.168.131.241 | Active | Moloch |
192.185.131.238 | Active | Moloch |
208.113.163.16 | Active | Moloch |
3.223.115.185 | Active | Moloch |
34.102.136.180 | Active | Moloch |
5.79.70.98 | Active | Moloch |
52.58.78.16 | Active | Moloch |
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.877961.com/mxnu/?FF=aHYJt+cF3uKE/jjIR1o9yP3wzE0OqMGB2AjKuxgiPGP7v0vlkCnn7S+a/Vapc30Z99lnekHH&llsp=fTRHzt4pzn4XCX | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.insightmyhome.com/mxnu/?FF=/jfKiAqxBAHgqOulmGtRlW5n/Sqdafb78dllJBhjnK66Sxf6eS8KxZUn5zSBqfmdUZv1jy8Z&llsp=fTRHzt4pzn4XCX | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.digisor.com/mxnu/?FF=UVMBiiaCgBTVCfU1vNNEq08V9m7XAvZZglUNdI143I2X7Zl4GMtYquItbp7SrE/Ljcqvb/Ed&llsp=fTRHzt4pzn4XCX | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.desongli.com/mxnu/?FF=hZ80obWBB1Dtx9mJDJ/B6KhSbXm9N4IXZ9kDZpitpQpTEQWdqR+8a/o3g7qjE+O8VqYt5r7Y&llsp=fTRHzt4pzn4XCX | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.closetu.com/mxnu/?FF=rJ249TMVQMCwGwXS7eMNhvOWH4SbGXiKs4Vq1JHmstm/5V4DyV8c/XoA/4BgaERVtEbRuzyC&llsp=fTRHzt4pzn4XCX | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.verifiedpaypal.net/mxnu/?FF=9Cb2F83H4cu3Wi3E/V06Uw+puzMd5mOCrt6x5BN8Ai+3jQ1IwCanO4QWCELETp3SVj+UiXzw&llsp=fTRHzt4pzn4XCX | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.029atk.xyz/mxnu/?FF=6sRgvWVFBb3Q/xwRSmzppKeefWZYMhtu8mXrbS5z1U4Jv8b+WQjv+VljYqCaCxejjINp6HL4&llsp=fTRHzt4pzn4XCX | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.naplesconciergerealty.com/mxnu/?FF=hecv2sMFcvsyFIpzJOhZbtwMh1SG6St5/U1aPglBFWownzq2qPNpvMi/ho6Sg43JWpVw027R&llsp=fTRHzt4pzn4XCX | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.safebookkeeping.com/mxnu/?FF=Dinuu19hFboSFju1K0HZ6EbcdDMO+ZnQ9sDSjm9DAS1j/pnpew28zT8+4dAfvZHXXiVk+x1O&llsp=fTRHzt4pzn4XCX | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.procurovariedades.com/mxnu/?FF=e63Yw596e9MjmhIdNsSN67oqb96/kwQ/AvXQ3UsARMy+g2BaAqseTyVnaYCqY6LOFgU8MBS4&llsp=fTRHzt4pzn4XCX |
request | POST http://www.877961.com/mxnu/ |
request | GET http://www.877961.com/mxnu/?FF=aHYJt+cF3uKE/jjIR1o9yP3wzE0OqMGB2AjKuxgiPGP7v0vlkCnn7S+a/Vapc30Z99lnekHH&llsp=fTRHzt4pzn4XCX |
request | POST http://www.insightmyhome.com/mxnu/ |
request | GET http://www.insightmyhome.com/mxnu/?FF=/jfKiAqxBAHgqOulmGtRlW5n/Sqdafb78dllJBhjnK66Sxf6eS8KxZUn5zSBqfmdUZv1jy8Z&llsp=fTRHzt4pzn4XCX |
request | GET http://www.digisor.com/mxnu/?FF=UVMBiiaCgBTVCfU1vNNEq08V9m7XAvZZglUNdI143I2X7Zl4GMtYquItbp7SrE/Ljcqvb/Ed&llsp=fTRHzt4pzn4XCX |
request | POST http://www.desongli.com/mxnu/ |
request | GET http://www.desongli.com/mxnu/?FF=hZ80obWBB1Dtx9mJDJ/B6KhSbXm9N4IXZ9kDZpitpQpTEQWdqR+8a/o3g7qjE+O8VqYt5r7Y&llsp=fTRHzt4pzn4XCX |
request | POST http://www.closetu.com/mxnu/ |
request | GET http://www.closetu.com/mxnu/?FF=rJ249TMVQMCwGwXS7eMNhvOWH4SbGXiKs4Vq1JHmstm/5V4DyV8c/XoA/4BgaERVtEbRuzyC&llsp=fTRHzt4pzn4XCX |
request | POST http://www.verifiedpaypal.net/mxnu/ |
request | GET http://www.verifiedpaypal.net/mxnu/?FF=9Cb2F83H4cu3Wi3E/V06Uw+puzMd5mOCrt6x5BN8Ai+3jQ1IwCanO4QWCELETp3SVj+UiXzw&llsp=fTRHzt4pzn4XCX |
request | POST http://www.029atk.xyz/mxnu/ |
request | GET http://www.029atk.xyz/mxnu/?FF=6sRgvWVFBb3Q/xwRSmzppKeefWZYMhtu8mXrbS5z1U4Jv8b+WQjv+VljYqCaCxejjINp6HL4&llsp=fTRHzt4pzn4XCX |
request | POST http://www.naplesconciergerealty.com/mxnu/ |
request | GET http://www.naplesconciergerealty.com/mxnu/?FF=hecv2sMFcvsyFIpzJOhZbtwMh1SG6St5/U1aPglBFWownzq2qPNpvMi/ho6Sg43JWpVw027R&llsp=fTRHzt4pzn4XCX |
request | POST http://www.safebookkeeping.com/mxnu/ |
request | GET http://www.safebookkeeping.com/mxnu/?FF=Dinuu19hFboSFju1K0HZ6EbcdDMO+ZnQ9sDSjm9DAS1j/pnpew28zT8+4dAfvZHXXiVk+x1O&llsp=fTRHzt4pzn4XCX |
request | POST http://www.procurovariedades.com/mxnu/ |
request | GET http://www.procurovariedades.com/mxnu/?FF=e63Yw596e9MjmhIdNsSN67oqb96/kwQ/AvXQ3UsARMy+g2BaAqseTyVnaYCqY6LOFgU8MBS4&llsp=fTRHzt4pzn4XCX |
request | POST http://www.gatescres.com/mxnu/ |
request | POST http://www.877961.com/mxnu/ |
request | POST http://www.insightmyhome.com/mxnu/ |
request | POST http://www.desongli.com/mxnu/ |
request | POST http://www.closetu.com/mxnu/ |
request | POST http://www.verifiedpaypal.net/mxnu/ |
request | POST http://www.029atk.xyz/mxnu/ |
request | POST http://www.naplesconciergerealty.com/mxnu/ |
request | POST http://www.safebookkeeping.com/mxnu/ |
request | POST http://www.procurovariedades.com/mxnu/ |
request | POST http://www.gatescres.com/mxnu/ |
file | C:\Users\test22\AppData\Local\Temp\nsw6386.tmp\ftzcfimfl.dll |
file | C:\Users\test22\AppData\Local\Temp\nsw6386.tmp\ftzcfimfl.dll |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Trojan.NSISX.Spy.Gen.2 |
FireEye | Generic.mg.d5f480d1d4cf7902 |
McAfee | Artemis!D5F480D1D4CF |
Cylance | Unsafe |
Sangfor | Trojan.Win32.Save.a |
Symantec | ML.Attribute.HighConfidence |
APEX | Malicious |
Kaspersky | UDS:Trojan-Spy.Win32.Noon.gen |
BitDefender | Trojan.NSISX.Spy.Gen.2 |
Emsisoft | Trojan.NSISX.Spy.Gen.2 (B) |
McAfee-GW-Edition | BehavesLike.Win32.Vopak.dc |
Sophos | Generic ML PUA (PUA) |
SentinelOne | Static AI - Malicious PE |
MAX | malware (ai score=85) |
Microsoft | Trojan:Win32/Sabsik.FL.B!ml |
GData | Zum.Androm.1 |
Cynet | Malicious (score: 100) |
Ikarus | Trojan.MSIL.Inject |