Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 20, 2021, 3:47 p.m. | Oct. 20, 2021, 3:49 p.m. |
IP Address | Status | Action |
---|---|---|
118.27.122.218 | Active | Moloch |
164.124.101.2 | Active | Moloch |
164.90.156.79 | Active | Moloch |
198.54.117.211 | Active | Moloch |
23.224.179.3 | Active | Moloch |
23.227.38.74 | Active | Moloch |
3.223.115.185 | Active | Moloch |
34.102.136.180 | Active | Moloch |
5.79.70.98 | Active | Moloch |
51.77.52.109 | Active | Moloch |
64.190.62.111 | Active | Moloch |
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.scottjasonfowler.com/mxnu/?XPc=bxnsXBk3/zFzprLliJ6DLuiWEz+4gG+eISCnZHlxGigaq53fO8LGUUflcVDMmN9mi3cjEVdh&Hpq=V6ALd0O0q6LdXt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.mortgagerates.solutions/mxnu/?XPc=e40TMWWr6xWVnQ1HwCqLobeJF4L/Z7xCu7/MTKlaRXTCRzwsua34O9neh9w9TPhFkJc6vnSR&Hpq=V6ALd0O0q6LdXt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.marshconstructions.com/mxnu/?XPc=uB6FNWC1vglbwwU+7YteY23vBejkvhe7mk/RqFXU3Cya7UnEdrryWwDyi3W4l929SCCXGUg+&Hpq=V6ALd0O0q6LdXt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.insightmyhome.com/mxnu/?XPc=/jfKiAqxBAHgqOulmGtRlW5n/Sqdafb78dllJBhjnK66Sxf6eS8KxZUn5zSBqfmdUZv1jy8Z&Hpq=V6ALd0O0q6LdXt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.yama-nkok.com/mxnu/?XPc=WYJTyQzBI/Nfv2zZ2IpqJP889AEH3D6sBeTTWnIrEjDNSTb8YjAN+mBSNE5Irdq8z4aXa8oH&Hpq=V6ALd0O0q6LdXt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.historyofcambridge.com/mxnu/?XPc=83rAwycDMUEJxLGVulxgJoLHCAQKcanhrm8XweUEKHeaWBLa77jLvzg0UgbAuk5RNaMObh69&Hpq=V6ALd0O0q6LdXt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.029atk.xyz/mxnu/?XPc=6sRgvWVFBb3Q/xwRSmzppKeefWZYMhtu8mXrbS5z1U4Jv8b+WQjv+VljYqCaCxejjINp6HL4&Hpq=V6ALd0O0q6LdXt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.clarityflux.com/mxnu/?XPc=F/DQFsF8RrKr1Us+nbLEKgHaq+2wJ3tNOSMfcadHp0CfgflqiGoqX7CzLYRNT9boMuwgDpVY&Hpq=V6ALd0O0q6LdXt | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.naplesconciergerealty.com/mxnu/?XPc=hecv2sMFcvsyFIpzJOhZbtwMh1SG6St5/U1aPglBFWownzq2qPNpvMi/ho6Sg43JWpVw027R&Hpq=V6ALd0O0q6LdXt |
request | POST http://www.scottjasonfowler.com/mxnu/ |
request | GET http://www.scottjasonfowler.com/mxnu/?XPc=bxnsXBk3/zFzprLliJ6DLuiWEz+4gG+eISCnZHlxGigaq53fO8LGUUflcVDMmN9mi3cjEVdh&Hpq=V6ALd0O0q6LdXt |
request | POST http://www.mortgagerates.solutions/mxnu/ |
request | GET http://www.mortgagerates.solutions/mxnu/?XPc=e40TMWWr6xWVnQ1HwCqLobeJF4L/Z7xCu7/MTKlaRXTCRzwsua34O9neh9w9TPhFkJc6vnSR&Hpq=V6ALd0O0q6LdXt |
request | POST http://www.marshconstructions.com/mxnu/ |
request | GET http://www.marshconstructions.com/mxnu/?XPc=uB6FNWC1vglbwwU+7YteY23vBejkvhe7mk/RqFXU3Cya7UnEdrryWwDyi3W4l929SCCXGUg+&Hpq=V6ALd0O0q6LdXt |
request | POST http://www.insightmyhome.com/mxnu/ |
request | GET http://www.insightmyhome.com/mxnu/?XPc=/jfKiAqxBAHgqOulmGtRlW5n/Sqdafb78dllJBhjnK66Sxf6eS8KxZUn5zSBqfmdUZv1jy8Z&Hpq=V6ALd0O0q6LdXt |
request | POST http://www.yama-nkok.com/mxnu/ |
request | GET http://www.yama-nkok.com/mxnu/?XPc=WYJTyQzBI/Nfv2zZ2IpqJP889AEH3D6sBeTTWnIrEjDNSTb8YjAN+mBSNE5Irdq8z4aXa8oH&Hpq=V6ALd0O0q6LdXt |
request | POST http://www.historyofcambridge.com/mxnu/ |
request | GET http://www.historyofcambridge.com/mxnu/?XPc=83rAwycDMUEJxLGVulxgJoLHCAQKcanhrm8XweUEKHeaWBLa77jLvzg0UgbAuk5RNaMObh69&Hpq=V6ALd0O0q6LdXt |
request | POST http://www.029atk.xyz/mxnu/ |
request | GET http://www.029atk.xyz/mxnu/?XPc=6sRgvWVFBb3Q/xwRSmzppKeefWZYMhtu8mXrbS5z1U4Jv8b+WQjv+VljYqCaCxejjINp6HL4&Hpq=V6ALd0O0q6LdXt |
request | POST http://www.clarityflux.com/mxnu/ |
request | GET http://www.clarityflux.com/mxnu/?XPc=F/DQFsF8RrKr1Us+nbLEKgHaq+2wJ3tNOSMfcadHp0CfgflqiGoqX7CzLYRNT9boMuwgDpVY&Hpq=V6ALd0O0q6LdXt |
request | POST http://www.naplesconciergerealty.com/mxnu/ |
request | GET http://www.naplesconciergerealty.com/mxnu/?XPc=hecv2sMFcvsyFIpzJOhZbtwMh1SG6St5/U1aPglBFWownzq2qPNpvMi/ho6Sg43JWpVw027R&Hpq=V6ALd0O0q6LdXt |
request | POST http://www.scottjasonfowler.com/mxnu/ |
request | POST http://www.mortgagerates.solutions/mxnu/ |
request | POST http://www.marshconstructions.com/mxnu/ |
request | POST http://www.insightmyhome.com/mxnu/ |
request | POST http://www.yama-nkok.com/mxnu/ |
request | POST http://www.historyofcambridge.com/mxnu/ |
request | POST http://www.029atk.xyz/mxnu/ |
request | POST http://www.clarityflux.com/mxnu/ |
request | POST http://www.naplesconciergerealty.com/mxnu/ |
file | C:\Users\test22\AppData\Local\Temp\nsk6471.tmp\evpz.dll |
file | C:\Users\test22\AppData\Local\Temp\nsk6471.tmp\evpz.dll |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Zum.Androm.1 |
FireEye | Generic.mg.b1e98b432deb4196 |
Cylance | Unsafe |
Sangfor | Suspicious.Win32.Save.a |
Cybereason | malicious.32deb4 |
Arcabit | Zum.Androm.1 |
BitDefenderTheta | Gen:NN.ZedlaF.34218.cq4@ai6kbFoi |
Symantec | ML.Attribute.HighConfidence |
APEX | Malicious |
Paloalto | generic.ml |
Kaspersky | UDS:Trojan-Spy.Win32.Noon.gen |
BitDefender | Zum.Androm.1 |
Emsisoft | Zum.Androm.1 (B) |
McAfee-GW-Edition | BehavesLike.Win32.Vopak.dc |
Sophos | Generic ML PUA (PUA) |
SentinelOne | Static AI - Malicious PE |
Microsoft | Trojan:Win32/Sabsik.FL.B!ml |
GData | Zum.Androm.1 |
Cynet | Malicious (score: 100) |
MAX | malware (ai score=86) |
Malwarebytes | Trojan.Injector |
Rising | Trojan.Generic@ML.80 (RDML:QW8Y8enbHY/J+uwL0cqL1Q) |
Ikarus | Trojan.NSIS.Agent |
Fortinet | W32/Injector_AGen.AW!tr |
dead_host | 164.90.156.79:80 |