Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 21, 2021, 6:22 p.m. | Oct. 21, 2021, 6:29 p.m. |
-
-
loader3.exe "C:\Users\test22\AppData\Local\Temp\loader3.exe"
2260
-
IP Address | Status | Action |
---|---|---|
103.224.212.221 | Active | Moloch |
104.21.75.74 | Active | Moloch |
162.241.203.56 | Active | Moloch |
162.255.119.57 | Active | Moloch |
164.124.101.2 | Active | Moloch |
172.217.175.51 | Active | Moloch |
172.67.179.65 | Active | Moloch |
185.68.16.23 | Active | Moloch |
209.99.40.222 | Active | Moloch |
34.102.136.180 | Active | Moloch |
72.247.211.17 | Active | Moloch |
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.ilkermulla.com/ons6/?t8rL=htUh7pgQwNNfonrnVODaoHFM/ntRzGt2NReYjs2/5acpPEiDUC1M6/iirndOWmVYqwPaQDzl&1bVHT=mzrd | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.advertising.land/ons6/?t8rL=5atXNRmUx37mOBRWSYjO7P9m1FhF1iu6rr12G6zuRSfmWlt8qfmLuUoCi3zjZJe340qI9kJw&1bVHT=mzrd | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.zitzies.xyz/ons6/?t8rL=hZn+h4i3qdjTvlrFTGBuGCKYeL7fx9ifE9FggzQ92Zn9lbpv8mLmxbTq9s8XLHOhsR7FCksw&1bVHT=mzrd | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.ancditalia.com/ons6/?t8rL=FqNY8GtcjD33AatuGxZVeLNAL7NCMjzFx4DR/EkfIuUI1nBdJ29F87IFN/JOzYZj2heFFPtj&1bVHT=mzrd | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.parasitevhs.net/ons6/?t8rL=K3/O5qStXw91cEZafq/vhJilaUZh0YJN+5nekOno/0bdfp1j2HTF92oxwv5f7cu06ufW7UgY&1bVHT=mzrd | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.nikurei.com/ons6/?t8rL=p66laJGF/T/0GpXxDd5hPjZubfTol0Lr3IwBrqBRPCvhxhKDrtw9PJ387dQ2b+OE0rZGfG2l&1bVHT=mzrd | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.algoescrow.com/ons6/?t8rL=UZGepyMrR79POtZQLeB3ajJI81oFbK1boHubTc9HwB4nkf80NE7aBFqbJaYFAd0yFJ1izkfv&1bVHT=mzrd | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.miltonjorge.net/ons6/?t8rL=ion/dvzazzRROQ/XthjQyoKaw08WdXBcQebFYFFZYCISD6I22k/rL6VDxVsOJE+QY/yDsfb+&1bVHT=mzrd | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.regencyimperial.com/ons6/?t8rL=pLcPY8DfVC4nF6nImpsYDslgQTm8hb6zaSbefXYfTYcwDwG8RZYyRprx0kRJ8HTy9l/fsGrp&1bVHT=mzrd | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.ktndetermine.xyz/ons6/?t8rL=hsISH4OHQbwAzFD8sw5R8ibBoXqjnq3rD9DL1tZnwnB9Hd1+cJwfc431OSdC7X2Zl5JwC7n9&1bVHT=mzrd | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.pinnap.online/ons6/?t8rL=T6IzNIefCt9asoM7wwl9vJHvNA8mHbVSIT7fQPN9khiXvHagvcAS0QXryNsRvv6cCNHi/hH2&1bVHT=mzrd | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.nagukoohatomo.xyz/ons6/?t8rL=AU+/5gjjPw5Dm7aO9w7wHS0YBjsv8vB0MKtvFyQe5P/L/nwKZqqTHP+wSIlGIao5xIcO+W/k&1bVHT=mzrd | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.tinturas-espagiricas.com/ons6/?t8rL=iIzayoLE23mGgxynHjOYRl9PYUP2qm5VdNCSkLZw3/FXI9XjUQBaDfeomXYvjIDjuyHUqn+8&RRm=rzrxPvVXEt3h1V |
request | POST http://www.ilkermulla.com/ons6/ |
request | GET http://www.ilkermulla.com/ons6/?t8rL=htUh7pgQwNNfonrnVODaoHFM/ntRzGt2NReYjs2/5acpPEiDUC1M6/iirndOWmVYqwPaQDzl&1bVHT=mzrd |
request | POST http://www.advertising.land/ons6/ |
request | GET http://www.advertising.land/ons6/?t8rL=5atXNRmUx37mOBRWSYjO7P9m1FhF1iu6rr12G6zuRSfmWlt8qfmLuUoCi3zjZJe340qI9kJw&1bVHT=mzrd |
request | POST http://www.zitzies.xyz/ons6/ |
request | GET http://www.zitzies.xyz/ons6/?t8rL=hZn+h4i3qdjTvlrFTGBuGCKYeL7fx9ifE9FggzQ92Zn9lbpv8mLmxbTq9s8XLHOhsR7FCksw&1bVHT=mzrd |
request | POST http://www.ancditalia.com/ons6/ |
request | GET http://www.ancditalia.com/ons6/?t8rL=FqNY8GtcjD33AatuGxZVeLNAL7NCMjzFx4DR/EkfIuUI1nBdJ29F87IFN/JOzYZj2heFFPtj&1bVHT=mzrd |
request | POST http://www.parasitevhs.net/ons6/ |
request | GET http://www.parasitevhs.net/ons6/?t8rL=K3/O5qStXw91cEZafq/vhJilaUZh0YJN+5nekOno/0bdfp1j2HTF92oxwv5f7cu06ufW7UgY&1bVHT=mzrd |
request | POST http://www.nikurei.com/ons6/ |
request | GET http://www.nikurei.com/ons6/?t8rL=p66laJGF/T/0GpXxDd5hPjZubfTol0Lr3IwBrqBRPCvhxhKDrtw9PJ387dQ2b+OE0rZGfG2l&1bVHT=mzrd |
request | POST http://www.algoescrow.com/ons6/ |
request | GET http://www.algoescrow.com/ons6/?t8rL=UZGepyMrR79POtZQLeB3ajJI81oFbK1boHubTc9HwB4nkf80NE7aBFqbJaYFAd0yFJ1izkfv&1bVHT=mzrd |
request | POST http://www.miltonjorge.net/ons6/ |
request | GET http://www.miltonjorge.net/ons6/?t8rL=ion/dvzazzRROQ/XthjQyoKaw08WdXBcQebFYFFZYCISD6I22k/rL6VDxVsOJE+QY/yDsfb+&1bVHT=mzrd |
request | POST http://www.regencyimperial.com/ons6/ |
request | GET http://www.regencyimperial.com/ons6/?t8rL=pLcPY8DfVC4nF6nImpsYDslgQTm8hb6zaSbefXYfTYcwDwG8RZYyRprx0kRJ8HTy9l/fsGrp&1bVHT=mzrd |
request | POST http://www.ktndetermine.xyz/ons6/ |
request | GET http://www.ktndetermine.xyz/ons6/?t8rL=hsISH4OHQbwAzFD8sw5R8ibBoXqjnq3rD9DL1tZnwnB9Hd1+cJwfc431OSdC7X2Zl5JwC7n9&1bVHT=mzrd |
request | POST http://www.pinnap.online/ons6/ |
request | GET http://www.pinnap.online/ons6/?t8rL=T6IzNIefCt9asoM7wwl9vJHvNA8mHbVSIT7fQPN9khiXvHagvcAS0QXryNsRvv6cCNHi/hH2&1bVHT=mzrd |
request | POST http://www.nagukoohatomo.xyz/ons6/ |
request | GET http://www.nagukoohatomo.xyz/ons6/?t8rL=AU+/5gjjPw5Dm7aO9w7wHS0YBjsv8vB0MKtvFyQe5P/L/nwKZqqTHP+wSIlGIao5xIcO+W/k&1bVHT=mzrd |
request | GET http://www.tinturas-espagiricas.com/ons6/?t8rL=iIzayoLE23mGgxynHjOYRl9PYUP2qm5VdNCSkLZw3/FXI9XjUQBaDfeomXYvjIDjuyHUqn+8&RRm=rzrxPvVXEt3h1V |
request | POST http://www.ilkermulla.com/ons6/ |
request | POST http://www.advertising.land/ons6/ |
request | POST http://www.zitzies.xyz/ons6/ |
request | POST http://www.ancditalia.com/ons6/ |
request | POST http://www.parasitevhs.net/ons6/ |
request | POST http://www.nikurei.com/ons6/ |
request | POST http://www.algoescrow.com/ons6/ |
request | POST http://www.miltonjorge.net/ons6/ |
request | POST http://www.regencyimperial.com/ons6/ |
request | POST http://www.ktndetermine.xyz/ons6/ |
request | POST http://www.pinnap.online/ons6/ |
request | POST http://www.nagukoohatomo.xyz/ons6/ |
file | C:\Users\test22\AppData\Local\Temp\nsy655B.tmp\rnzyao.dll |
file | C:\Users\test22\AppData\Local\Temp\nsy655B.tmp\rnzyao.dll |
Lionic | Trojan.Win32.Malicious.4!c |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Gen:Variant.Nemesis.1798 |
FireEye | Generic.mg.5e9c6466f89089a7 |
McAfee | Artemis!5E9C6466F890 |
Cylance | Unsafe |
Cybereason | malicious.6f8908 |
BitDefenderTheta | Gen:NN.ZedlaF.34218.cq4@aW979Cli |
Symantec | ML.Attribute.HighConfidence |
APEX | Malicious |
Kaspersky | UDS:Trojan-Spy.Win32.Noon.gen |
BitDefender | Gen:Variant.Nemesis.1798 |
Sophos | Mal/Generic-S |
McAfee-GW-Edition | BehavesLike.Win32.Vopak.dc |
Emsisoft | Gen:Variant.Nemesis.1798 (B) |
Ikarus | Trojan.NSIS.Agent |
GData | Zum.Androm.1 |
Avira | TR/Crypt.ZPACK.Gen |
Arcabit | Trojan.Nemesis.D706 |
Microsoft | Trojan:Win32/Sabsik.FL.B!ml |
Cynet | Malicious (score: 100) |
MAX | malware (ai score=85) |
SentinelOne | Static AI - Malicious PE |
Fortinet | W32/Injector_AGen.AW!tr |