Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Oct. 20, 2021, 5:34 p.m. | Oct. 20, 2021, 5:36 p.m. |
IP Address | Status | Action |
---|---|---|
109.68.33.25 | Active | Moloch |
138.128.160.186 | Active | Moloch |
138.201.145.141 | Active | Moloch |
154.210.71.198 | Active | Moloch |
156.67.73.75 | Active | Moloch |
162.241.24.110 | Active | Moloch |
164.124.101.2 | Active | Moloch |
172.217.31.243 | Active | Moloch |
208.91.197.27 | Active | Moloch |
216.194.173.79 | Active | Moloch |
45.138.216.23 | Active | Moloch |
51.81.73.1 | Active | Moloch |
52.58.78.16 | Active | Moloch |
94.138.198.5 | Active | Moloch |
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.tigerstarmatka.com/kqna/?GFNl=WsqGZAQros6YqmWTBX4NfZ/s8YWhGwfZXTAI3K43qiDXPWL+08MoNe9ItI/4zkDRJBUw3EwW&OH2LRV=YVIXx4dp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.candypalette.com/kqna/?GFNl=gfz7SykQtqnvqGHDVt9Sq/sQwFu3mmkE3P7hoh5mXhnlze04JbT/9GbgDzlkmDUFL9Oz3qhg&OH2LRV=YVIXx4dp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.midatlanticbath.com/kqna/?GFNl=ggB/CL/KYRtKG6XlF3MzMphhLgqrG506l6vnNW5K6bJVc8waEANRFYYD3RhOV4cBkcToPXaa&OH2LRV=YVIXx4dp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.globalmarineserv.com/kqna/?GFNl=OcQswr2RSap8Tqs4oU4ZFsiLsHswYX19Q+tKNUlPXhjH/8KnGfVJ0KkYssvjpVDRe7cJzP2E&OH2LRV=YVIXx4dp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.meggisiegert.com/kqna/?GFNl=hfZ862mxRIeJidQqdd8aIL9GgrYgW2e5BMIURab2fcg5ookX2qmzIsDvlSNuYbByVPhkgpDv&OH2LRV=YVIXx4dp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.facetofacewith.com/kqna/?GFNl=PeXUNRBzWcryXXSI2NVMVXg+mLiheTzLRpyqlDxU843yly7wQ7gwUXyhf0XDvNpMpT2dSlCe&OH2LRV=YVIXx4dp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.surfsolutions.info/kqna/?GFNl=dcnZeOVVJSfvUaco8qQNZ9XrhbJ3we+xyEUMa9yoWpEuWq2eXXPIXA5TkXgJFjsZU/Pq8NER&OH2LRV=YVIXx4dp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.companyintelcloud.com/kqna/?GFNl=i87PhLMCdOyavfe8oe3DoVk+8hYSao8t8gBpFSFV3/RERuMX7oVU6SWWtdnlVjPYz2f2GpRC&OH2LRV=YVIXx4dp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.publicyazilim.com/kqna/?GFNl=dFrlS2l6Li5DGfafNkfe9QOrXwTG+WFHgmJ24ihxQTN3FrlEXBXr0CXukKrPa6aNFySxrST0&OH2LRV=YVIXx4dp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.caffeiny.com/kqna/?GFNl=/STjzQyNMBearyUbGha0kbvlvZ+XKPyeS+XuwOFlk5E7OzqCtoQRiHyTBU0aBvHeRKpACBp2&OH2LRV=YVIXx4dp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.unlimitedrehab.com/kqna/?GFNl=cFNgKBTbA1svsN6cC8/+W5UTP+1BdxdtTipUKJnf15V+/a8Yee6hrfZJvGg98qTC6E/a5FqG&OH2LRV=YVIXx4dp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.gratitudeland.com/kqna/?GFNl=IVdY3CvIYo9KzjpPCV4V1YKYcmgBkczyN/XlE7carAyFA9E+23LHf6/wDJYA6pWe4zRkRj1R&OH2LRV=YVIXx4dp |
request | GET http://www.tigerstarmatka.com/kqna/?GFNl=WsqGZAQros6YqmWTBX4NfZ/s8YWhGwfZXTAI3K43qiDXPWL+08MoNe9ItI/4zkDRJBUw3EwW&OH2LRV=YVIXx4dp |
request | GET http://www.candypalette.com/kqna/?GFNl=gfz7SykQtqnvqGHDVt9Sq/sQwFu3mmkE3P7hoh5mXhnlze04JbT/9GbgDzlkmDUFL9Oz3qhg&OH2LRV=YVIXx4dp |
request | GET http://www.midatlanticbath.com/kqna/?GFNl=ggB/CL/KYRtKG6XlF3MzMphhLgqrG506l6vnNW5K6bJVc8waEANRFYYD3RhOV4cBkcToPXaa&OH2LRV=YVIXx4dp |
request | GET http://www.globalmarineserv.com/kqna/?GFNl=OcQswr2RSap8Tqs4oU4ZFsiLsHswYX19Q+tKNUlPXhjH/8KnGfVJ0KkYssvjpVDRe7cJzP2E&OH2LRV=YVIXx4dp |
request | GET http://www.meggisiegert.com/kqna/?GFNl=hfZ862mxRIeJidQqdd8aIL9GgrYgW2e5BMIURab2fcg5ookX2qmzIsDvlSNuYbByVPhkgpDv&OH2LRV=YVIXx4dp |
request | GET http://www.facetofacewith.com/kqna/?GFNl=PeXUNRBzWcryXXSI2NVMVXg+mLiheTzLRpyqlDxU843yly7wQ7gwUXyhf0XDvNpMpT2dSlCe&OH2LRV=YVIXx4dp |
request | GET http://www.surfsolutions.info/kqna/?GFNl=dcnZeOVVJSfvUaco8qQNZ9XrhbJ3we+xyEUMa9yoWpEuWq2eXXPIXA5TkXgJFjsZU/Pq8NER&OH2LRV=YVIXx4dp |
request | GET http://www.companyintelcloud.com/kqna/?GFNl=i87PhLMCdOyavfe8oe3DoVk+8hYSao8t8gBpFSFV3/RERuMX7oVU6SWWtdnlVjPYz2f2GpRC&OH2LRV=YVIXx4dp |
request | GET http://www.publicyazilim.com/kqna/?GFNl=dFrlS2l6Li5DGfafNkfe9QOrXwTG+WFHgmJ24ihxQTN3FrlEXBXr0CXukKrPa6aNFySxrST0&OH2LRV=YVIXx4dp |
request | GET http://www.caffeiny.com/kqna/?GFNl=/STjzQyNMBearyUbGha0kbvlvZ+XKPyeS+XuwOFlk5E7OzqCtoQRiHyTBU0aBvHeRKpACBp2&OH2LRV=YVIXx4dp |
request | GET http://www.unlimitedrehab.com/kqna/?GFNl=cFNgKBTbA1svsN6cC8/+W5UTP+1BdxdtTipUKJnf15V+/a8Yee6hrfZJvGg98qTC6E/a5FqG&OH2LRV=YVIXx4dp |
request | GET http://www.gratitudeland.com/kqna/?GFNl=IVdY3CvIYo9KzjpPCV4V1YKYcmgBkczyN/XlE7carAyFA9E+23LHf6/wDJYA6pWe4zRkRj1R&OH2LRV=YVIXx4dp |
file | C:\Users\test22\AppData\Local\Temp\nsxC60.tmp\yhjjbtf.dll |
file | C:\Users\test22\AppData\Local\Temp\nsxC60.tmp\yhjjbtf.dll |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Trojan.NSISX.Spy.Gen.2 |
FireEye | Generic.mg.73fe142254abec3a |
Malwarebytes | Trojan.Injector |
Sangfor | Suspicious.Win32.Save.a |
Cybereason | malicious.254abe |
Symantec | ML.Attribute.HighConfidence |
APEX | Malicious |
Paloalto | generic.ml |
Kaspersky | UDS:Trojan-Spy.Win32.Noon.gen |
BitDefender | Trojan.NSISX.Spy.Gen.2 |
Emsisoft | Trojan.NSISX.Spy.Gen.2 (B) |
McAfee-GW-Edition | BehavesLike.Win32.Vopak.dc |
Sophos | Generic ML PUA (PUA) |
Ikarus | Trojan.NSIS.Agent.S |
Avira | TR/Crypt.ZPACK.Gen |
ZoneAlarm | UDS:DangerousObject.Multi.Generic |
GData | Zum.Androm.1 |
Cynet | Malicious (score: 100) |
MAX | malware (ai score=89) |
SentinelOne | Static AI - Malicious PE |
Fortinet | W32/Injector_AGen.AW!tr |