Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 29, 2021, 9:26 a.m. | Oct. 29, 2021, 9:42 a.m. |
-
-
loader2.exe "C:\Users\test22\AppData\Local\Temp\loader2.exe"
2240
-
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.cfaatampa.com/o2go/?Dxlpd=Pl/Ol+nOsw6/w/y+aU9P1RKojiUc7vyeNPaxTQPmfD352vP1/9QBqpNGE02dwnx78NU/bhk7&mnSh=TxlhkdU | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.canopuslector.com/o2go/?Dxlpd=ZAUpSgkpEDg8niFzuNKe6gEWnHhBWtidA2LwxNth08Qz4PbCXRD40C59E3bfaaHzXCIDtzc4&mnSh=TxlhkdU | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.expatriatecafe.com/o2go/?Dxlpd=+cW4o3L1nfvEkkPOkZGTjQfjWekF/hM2MaTEXDdcC09Onuz+XEMDyox0luu0PClFcWinXzsf&mnSh=TxlhkdU | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.daybydayneeds.com/o2go/?Dxlpd=/FrPOgiDhDip/ySNZI8OLKS5OxIhXPdMrfM/1s/okw0wECr+nAKcZ38irIHgJAMCO3WjHnMc&mnSh=TxlhkdU | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.fanaticscardgroup.com/o2go/?Dxlpd=8H0rDLcccfrSnzJo6xqaIh8cFRP5shFVfEo30ND+W3j0LJ9pYzmIPxBjjF03wuELOtv43EjU&mnSh=TxlhkdU | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.koltemp.com/o2go/?Dxlpd=d/I/y4E919y90/NgD6lGRdsG+efKLObNvHJeST29zYsXDGROtBHMrcb1ki8bN5CEtxKsUn6o&mnSh=TxlhkdU |
request | POST http://www.cfaatampa.com/o2go/ |
request | GET http://www.cfaatampa.com/o2go/?Dxlpd=Pl/Ol+nOsw6/w/y+aU9P1RKojiUc7vyeNPaxTQPmfD352vP1/9QBqpNGE02dwnx78NU/bhk7&mnSh=TxlhkdU |
request | POST http://www.canopuslector.com/o2go/ |
request | GET http://www.canopuslector.com/o2go/?Dxlpd=ZAUpSgkpEDg8niFzuNKe6gEWnHhBWtidA2LwxNth08Qz4PbCXRD40C59E3bfaaHzXCIDtzc4&mnSh=TxlhkdU |
request | POST http://www.expatriatecafe.com/o2go/ |
request | GET http://www.expatriatecafe.com/o2go/?Dxlpd=+cW4o3L1nfvEkkPOkZGTjQfjWekF/hM2MaTEXDdcC09Onuz+XEMDyox0luu0PClFcWinXzsf&mnSh=TxlhkdU |
request | POST http://www.daybydayneeds.com/o2go/ |
request | GET http://www.daybydayneeds.com/o2go/?Dxlpd=/FrPOgiDhDip/ySNZI8OLKS5OxIhXPdMrfM/1s/okw0wECr+nAKcZ38irIHgJAMCO3WjHnMc&mnSh=TxlhkdU |
request | POST http://www.fanaticscardgroup.com/o2go/ |
request | GET http://www.fanaticscardgroup.com/o2go/?Dxlpd=8H0rDLcccfrSnzJo6xqaIh8cFRP5shFVfEo30ND+W3j0LJ9pYzmIPxBjjF03wuELOtv43EjU&mnSh=TxlhkdU |
request | POST http://www.koltemp.com/o2go/ |
request | GET http://www.koltemp.com/o2go/?Dxlpd=d/I/y4E919y90/NgD6lGRdsG+efKLObNvHJeST29zYsXDGROtBHMrcb1ki8bN5CEtxKsUn6o&mnSh=TxlhkdU |
request | POST http://www.cfaatampa.com/o2go/ |
request | POST http://www.canopuslector.com/o2go/ |
request | POST http://www.expatriatecafe.com/o2go/ |
request | POST http://www.daybydayneeds.com/o2go/ |
request | POST http://www.fanaticscardgroup.com/o2go/ |
request | POST http://www.koltemp.com/o2go/ |
file | C:\Users\test22\AppData\Local\Temp\nsl657A.tmp\psdqz.dll |
file | C:\Users\test22\AppData\Local\Temp\nsl657A.tmp\psdqz.dll |
Elastic | malicious (high confidence) |
Cylance | Unsafe |
Sangfor | Suspicious.Win32.Save.a |
BitDefender | Trojan.NSISX.Spy.Gen.2 |
Arcabit | Trojan.NSISX.Spy.Gen.2 |
Cyren | W32/Injector.ANV.gen!Eldorado |
Symantec | ML.Attribute.HighConfidence |
ESET-NOD32 | a variant of Win32/Injector.EQKC |
APEX | Malicious |
Paloalto | generic.ml |
Cynet | Malicious (score: 100) |
Kaspersky | UDS:DangerousObject.Multi.Generic |
MicroWorld-eScan | Trojan.NSISX.Spy.Gen.2 |
Emsisoft | Trojan.NSISX.Spy.Gen.2 (B) |
McAfee-GW-Edition | BehavesLike.Win32.Vopak.dc |
FireEye | Generic.mg.25f27297055176dd |
Sophos | Generic ML PUA (PUA) |
Ikarus | Trojan.NSIS.Agent |
MAX | malware (ai score=89) |
Microsoft | Trojan:Win32/Sabsik.FL.B!ml |
GData | Zum.Androm.1 |
SentinelOne | Static AI - Malicious PE |
Fortinet | W32/Injector_AGen.AW!tr |
BitDefenderTheta | Gen:NN.ZedlaF.34236.bu4@aOwRvMki |
Cybereason | malicious.705517 |