Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Oct. 20, 2021, 3:45 p.m. | Oct. 20, 2021, 3:49 p.m. |
-
EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Office15\EXCEL.EXE" C:\Users\test22\AppData\Local\Temp\biz-1431840176.xls
2500-
regsvr32.exe "C:\Windows\System32\regsvr32.exe" C:\Datop\test.test
2172 -
regsvr32.exe "C:\Windows\System32\regsvr32.exe" C:\Datop\test1.test
2128 -
regsvr32.exe "C:\Windows\System32\regsvr32.exe" C:\Datop\test2.test
2764
-
Name | Response | Post-Analysis Lookup |
---|---|---|
meettrust.in | 192.185.129.109 | |
aqissarafood.com.my | 103.27.74.73 | |
radiocaca.top | 103.221.220.15 | |
x1.i.lencr.org | 104.74.211.103 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49168 208.91.197.91:443 |
C=US, ST=California, L=test, O=testexample, OU=testexample, CN=testexp | C=US, ST=California, L=test, O=testexample, OU=testexample, CN=testexp | 1a:42:b0:7f:5f:73:d2:53:5e:40:25:cc:97:6b:8e:88:ba:45:71:68 |
TLSv1 192.168.56.103:49169 103.27.74.73:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=*.anamuslimpreschool.com | 31:f5:04:25:4c:24:41:84:cf:0d:b6:1f:75:76:e9:8f:23:f0:c9:ea |
request | GET http://x1.i.lencr.org/ |
cmdline | regsvr32 C:\Datop\test.test |
cmdline | "C:\Windows\System32\regsvr32.exe" C:\Datop\test2.test |
cmdline | "C:\Windows\System32\regsvr32.exe" C:\Datop\test1.test |
cmdline | "C:\Windows\System32\regsvr32.exe" C:\Datop\test.test |
cmdline | regsvr32 C:\Datop\test1.test |
cmdline | regsvr32 C:\Datop\test2.test |
parent_process | excel.exe | martian_process | regsvr32 C:\Datop\test.test | ||||||
parent_process | excel.exe | martian_process | "C:\Windows\System32\regsvr32.exe" C:\Datop\test2.test | ||||||
parent_process | excel.exe | martian_process | "C:\Windows\System32\regsvr32.exe" C:\Datop\test1.test | ||||||
parent_process | excel.exe | martian_process | "C:\Windows\System32\regsvr32.exe" C:\Datop\test.test | ||||||
parent_process | excel.exe | martian_process | regsvr32 C:\Datop\test1.test | ||||||
parent_process | excel.exe | martian_process | regsvr32 C:\Datop\test2.test |
file | C:\Windows\System32\regsvr32.exe |