Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 27, 2021, 10:23 a.m. | Oct. 27, 2021, 10:27 a.m. |
Name | Response | Post-Analysis Lookup |
---|---|---|
www.rollingrallys.com | 66.96.162.132 | |
www.trustedfurnituretransport.net | 202.124.241.178 | |
www.gulfsidemorgageservices.com | 199.59.242.153 | |
www.thegunlogic.com |
CNAME
thegunlogic.com
|
34.102.136.180 |
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.thegunlogic.com/sl4w/?kfL4bD=QgR+mVZR/tCl+4LWlCJ+sOG5pCcKXvmBqZ02+TsfiNaO5znL7BBFK4fPMxE3wC0XtHd+7E0U&jBZx=DneXo | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.rollingrallys.com/sl4w/?kfL4bD=bxNqDo2FQwxq07tQVHEPYIPbWCvE1369cDnAJzUpNTpK4C/yo0zTvriAZc1F13aaZhCEhMwc&jBZx=DneXo | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.gulfsidemorgageservices.com/sl4w/?kfL4bD=7+0WVGGe/x3LX559cMkONJoyosZ/ZZUoMq8pBstyBBU5VO2caztg0u2E4IT74Mw0M9pmC6Ic&jBZx=DneXo | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.trustedfurnituretransport.net/sl4w/?kfL4bD=SU6djegnNokhXatHD0Zt/RgvM6Zh0SA/H/J8xjjIneGyQtz5eA+PvmJcxeEsuLxakaSqDUJr&jBZx=DneXo |
request | GET http://www.thegunlogic.com/sl4w/?kfL4bD=QgR+mVZR/tCl+4LWlCJ+sOG5pCcKXvmBqZ02+TsfiNaO5znL7BBFK4fPMxE3wC0XtHd+7E0U&jBZx=DneXo |
request | GET http://www.rollingrallys.com/sl4w/?kfL4bD=bxNqDo2FQwxq07tQVHEPYIPbWCvE1369cDnAJzUpNTpK4C/yo0zTvriAZc1F13aaZhCEhMwc&jBZx=DneXo |
request | GET http://www.gulfsidemorgageservices.com/sl4w/?kfL4bD=7+0WVGGe/x3LX559cMkONJoyosZ/ZZUoMq8pBstyBBU5VO2caztg0u2E4IT74Mw0M9pmC6Ic&jBZx=DneXo |
request | GET http://www.trustedfurnituretransport.net/sl4w/?kfL4bD=SU6djegnNokhXatHD0Zt/RgvM6Zh0SA/H/J8xjjIneGyQtz5eA+PvmJcxeEsuLxakaSqDUJr&jBZx=DneXo |
file | C:\Users\test22\AppData\Local\Temp\nsh65C8.tmp\juqiprw.dll |
file | C:\Users\test22\AppData\Local\Temp\nsh65C8.tmp\juqiprw.dll |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Trojan.NSISX.Spy.Gen.2 |
FireEye | Generic.mg.83a00ad620a30014 |
Cylance | Unsafe |
Cyren | W32/Injector.AOA.gen!Eldorado |
ESET-NOD32 | a variant of Win32/Injector.EQJT |
APEX | Malicious |
Paloalto | generic.ml |
Kaspersky | UDS:DangerousObject.Multi.Generic |
BitDefender | Trojan.NSISX.Spy.Gen.2 |
Emsisoft | Trojan.NSISX.Spy.Gen.2 (B) |
McAfee-GW-Edition | BehavesLike.Win32.Vopak.dc |
Sophos | Generic ML PUA (PUA) |
Ikarus | Trojan.NSIS.Agent |
Microsoft | Trojan:Win32/Sabsik.FL.B!ml |
GData | Zum.Androm.1 |
Cynet | Malicious (score: 100) |
MAX | malware (ai score=81) |
SentinelOne | Static AI - Malicious PE |
Cybereason | malicious.620a30 |