Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Oct. 27, 2021, 10:22 a.m. | Oct. 27, 2021, 10:30 a.m. |
-
EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Office15\EXCEL.EXE" C:\Users\test22\AppData\Local\Temp\guide-1763962901.xls
2496-
regsvr32.exe "C:\Windows\System32\regsvr32.exe" C:\Datop\test.test
2164 -
regsvr32.exe "C:\Windows\System32\regsvr32.exe" C:\Datop\test1.test
2128 -
regsvr32.exe "C:\Windows\System32\regsvr32.exe" C:\Datop\test2.test
2860
-
Name | Response | Post-Analysis Lookup |
---|---|---|
specialistedu.com.hk | 103.27.32.22 | |
x1.i.lencr.org | 104.74.211.103 | |
giversherbalproducts.com | 198.38.82.168 | |
denkyiraman.co.uk | 198.38.82.168 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49169 198.38.82.168:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=*.giversherbalproducts.com | 23:3b:89:a4:b8:b7:80:a5:bd:4b:5a:9e:b1:7b:1c:e9:82:57:a2:87 |
TLSv1 192.168.56.103:49176 198.38.82.168:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=denkyiraman.co.uk | dc:ee:f4:0d:91:7f:f8:e9:35:0f:f7:e9:dc:0e:2d:e3:c5:4f:a1:e6 |
request | GET http://x1.i.lencr.org/ |
cmdline | regsvr32 C:\Datop\test.test |
cmdline | "C:\Windows\System32\regsvr32.exe" C:\Datop\test2.test |
cmdline | "C:\Windows\System32\regsvr32.exe" C:\Datop\test1.test |
cmdline | "C:\Windows\System32\regsvr32.exe" C:\Datop\test.test |
cmdline | regsvr32 C:\Datop\test1.test |
cmdline | regsvr32 C:\Datop\test2.test |
parent_process | excel.exe | martian_process | regsvr32 C:\Datop\test.test | ||||||
parent_process | excel.exe | martian_process | "C:\Windows\System32\regsvr32.exe" C:\Datop\test2.test | ||||||
parent_process | excel.exe | martian_process | "C:\Windows\System32\regsvr32.exe" C:\Datop\test1.test | ||||||
parent_process | excel.exe | martian_process | "C:\Windows\System32\regsvr32.exe" C:\Datop\test.test | ||||||
parent_process | excel.exe | martian_process | regsvr32 C:\Datop\test1.test | ||||||
parent_process | excel.exe | martian_process | regsvr32 C:\Datop\test2.test |
file | C:\Windows\System32\regsvr32.exe |