Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 21, 2021, 6:42 p.m. | Oct. 21, 2021, 6:44 p.m. |
IP Address | Status | Action |
---|---|---|
138.128.160.186 | Active | Moloch |
138.201.145.141 | Active | Moloch |
15.197.142.173 | Active | Moloch |
154.64.42.97 | Active | Moloch |
157.90.247.57 | Active | Moloch |
164.124.101.2 | Active | Moloch |
198.54.117.217 | Active | Moloch |
216.194.173.79 | Active | Moloch |
217.70.184.50 | Active | Moloch |
51.81.73.1 | Active | Moloch |
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.alifdanismanlik.com/kqna/?XPJPe4Q0=mQnobkOfgPtywstNWl93w92LClziyi9exAIAZ2dbJOdepP7Ogt31xGCBzTFokFA1igwL7X4B&EBZ=ZTFtdFihOjc0V | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.surfsolutions.info/kqna/?XPJPe4Q0=dcnZeOVVJSfvUaco8qQNZ9XrhbJ3we+xyEUMa9yoWpEuWq2eXXPIXA5TkXgJFjsZU/Pq8NER&EBZ=ZTFtdFihOjc0V | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.hautlescoeurscollection.com/kqna/?XPJPe4Q0=5D8+/NUJ6SHRwR8iDAR3xdQ85MKY3LVZxxY031ww84efqx2r1agFQuE5bYzBJbXYeHOEJ4PT&EBZ=ZTFtdFihOjc0V | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.tigerstarmatka.com/kqna/?XPJPe4Q0=WsqGZAQros6YqmWTBX4NfZ/s8YWhGwfZXTAI3K43qiDXPWL+08MoNe9ItI/4zkDRJBUw3EwW&EBZ=ZTFtdFihOjc0V | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.netkopat.com/kqna/?XPJPe4Q0=XCeMQl5kuZk/VAPz1x3NMFNaYm0TP5U/J5/9BEX1GnrVHj0GaV8zX9dSOYzSTsdbHQNQtFsF&EBZ=ZTFtdFihOjc0V | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.candypalette.com/kqna/?XPJPe4Q0=gfz7SykQtqnvqGHDVt9Sq/sQwFu3mmkE3P7hoh5mXhnlze04JbT/9GbgDzlkmDUFL9Oz3qhg&EBZ=ZTFtdFihOjc0V | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.globalmarineserv.com/kqna/?XPJPe4Q0=OcQswr2RSap8Tqs4oU4ZFsiLsHswYX19Q+tKNUlPXhjH/8KnGfVJ0KkYssvjpVDRe7cJzP2E&EBZ=ZTFtdFihOjc0V | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.fraserstephendop.com/kqna/?XPJPe4Q0=/ubmoBp65Okyuu3LQpd6BICjkbw0SXb2/UwCCZwJ/Fe1H/pHrLEpRm6qotblqBtYRSTWmjxF&EBZ=ZTFtdFihOjc0V | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.generationgirlnaturals.com/kqna/?XPJPe4Q0=y7M/lgAT23Oh1oltO5RaxlEy4Bz2jyK1luujiozG5pWU+I4JVxp3OS49isl7KGuf1hAvA74/&EBZ=ZTFtdFihOjc0V |
request | POST http://www.alifdanismanlik.com/kqna/ |
request | GET http://www.alifdanismanlik.com/kqna/?XPJPe4Q0=mQnobkOfgPtywstNWl93w92LClziyi9exAIAZ2dbJOdepP7Ogt31xGCBzTFokFA1igwL7X4B&EBZ=ZTFtdFihOjc0V |
request | POST http://www.surfsolutions.info/kqna/ |
request | GET http://www.surfsolutions.info/kqna/?XPJPe4Q0=dcnZeOVVJSfvUaco8qQNZ9XrhbJ3we+xyEUMa9yoWpEuWq2eXXPIXA5TkXgJFjsZU/Pq8NER&EBZ=ZTFtdFihOjc0V |
request | POST http://www.hautlescoeurscollection.com/kqna/ |
request | GET http://www.hautlescoeurscollection.com/kqna/?XPJPe4Q0=5D8+/NUJ6SHRwR8iDAR3xdQ85MKY3LVZxxY031ww84efqx2r1agFQuE5bYzBJbXYeHOEJ4PT&EBZ=ZTFtdFihOjc0V |
request | POST http://www.tigerstarmatka.com/kqna/ |
request | GET http://www.tigerstarmatka.com/kqna/?XPJPe4Q0=WsqGZAQros6YqmWTBX4NfZ/s8YWhGwfZXTAI3K43qiDXPWL+08MoNe9ItI/4zkDRJBUw3EwW&EBZ=ZTFtdFihOjc0V |
request | POST http://www.netkopat.com/kqna/ |
request | GET http://www.netkopat.com/kqna/?XPJPe4Q0=XCeMQl5kuZk/VAPz1x3NMFNaYm0TP5U/J5/9BEX1GnrVHj0GaV8zX9dSOYzSTsdbHQNQtFsF&EBZ=ZTFtdFihOjc0V |
request | POST http://www.candypalette.com/kqna/ |
request | GET http://www.candypalette.com/kqna/?XPJPe4Q0=gfz7SykQtqnvqGHDVt9Sq/sQwFu3mmkE3P7hoh5mXhnlze04JbT/9GbgDzlkmDUFL9Oz3qhg&EBZ=ZTFtdFihOjc0V |
request | POST http://www.globalmarineserv.com/kqna/ |
request | GET http://www.globalmarineserv.com/kqna/?XPJPe4Q0=OcQswr2RSap8Tqs4oU4ZFsiLsHswYX19Q+tKNUlPXhjH/8KnGfVJ0KkYssvjpVDRe7cJzP2E&EBZ=ZTFtdFihOjc0V |
request | POST http://www.fraserstephendop.com/kqna/ |
request | GET http://www.fraserstephendop.com/kqna/?XPJPe4Q0=/ubmoBp65Okyuu3LQpd6BICjkbw0SXb2/UwCCZwJ/Fe1H/pHrLEpRm6qotblqBtYRSTWmjxF&EBZ=ZTFtdFihOjc0V |
request | POST http://www.generationgirlnaturals.com/kqna/ |
request | GET http://www.generationgirlnaturals.com/kqna/?XPJPe4Q0=y7M/lgAT23Oh1oltO5RaxlEy4Bz2jyK1luujiozG5pWU+I4JVxp3OS49isl7KGuf1hAvA74/&EBZ=ZTFtdFihOjc0V |
request | POST http://www.alifdanismanlik.com/kqna/ |
request | POST http://www.surfsolutions.info/kqna/ |
request | POST http://www.hautlescoeurscollection.com/kqna/ |
request | POST http://www.tigerstarmatka.com/kqna/ |
request | POST http://www.netkopat.com/kqna/ |
request | POST http://www.candypalette.com/kqna/ |
request | POST http://www.globalmarineserv.com/kqna/ |
request | POST http://www.fraserstephendop.com/kqna/ |
request | POST http://www.generationgirlnaturals.com/kqna/ |
file | C:\Users\test22\AppData\Local\Temp\nsi649F.tmp\oirygpbyia.dll |
file | C:\Users\test22\AppData\Local\Temp\nsi649F.tmp\oirygpbyia.dll |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Trojan.NSISX.Spy.Gen.2 |
FireEye | Generic.mg.d0e4c13e6c8ba9fe |
Sangfor | Suspicious.Win32.Save.a |
Cybereason | malicious.e6c8ba |
Cyren | W32/Injector.ANS.gen!Eldorado |
Symantec | Trojan.Gen.MBT |
ESET-NOD32 | a variant of Win32/Injector.EQIX |
APEX | Malicious |
Paloalto | generic.ml |
Kaspersky | UDS:DangerousObject.Multi.Generic |
BitDefender | Trojan.NSISX.Spy.Gen.2 |
Emsisoft | Trojan.NSISX.Spy.Gen.2 (B) |
McAfee-GW-Edition | BehavesLike.Win32.Vopak.dc |
Sophos | Mal/Generic-R |
SentinelOne | Static AI - Malicious PE |
Avira | HEUR/AGEN.1138922 |
MAX | malware (ai score=89) |
Microsoft | Trojan:Win32/Sabsik.FL.B!ml |
ZoneAlarm | UDS:DangerousObject.Multi.Generic |
GData | Zum.Androm.1 |
Cynet | Malicious (score: 100) |
McAfee | Artemis!D0E4C13E6C8B |
Fortinet | W32/Injector.EQGK!tr |