Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Nov. 18, 2021, 7:44 a.m. | Nov. 18, 2021, 8:13 a.m. |
-
-
-
-
net1.exe C:\Windows\system32\net1 stop MiningeService
2976
-
-
-
-
sc.exe Sc delete MiningeService
2060
-
-
cmd.exe C:\Windows\system32\cmd.exe /C Sc create MiningeService binpath= C:\Windows\Client.exe start= auto DisplayName= MiningeService
1112-
sc.exe Sc create MiningeService binpath= C:\Windows\Client.exe start= auto DisplayName= MiningeService
1304
-
-
-
sc.exe sc description MiningeService ServiceManagerForMiner
2296
-
-
-
-
net1.exe C:\Windows\system32\net1 start MiningeService
2496
-
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
91.243.59.61 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
file | C:\Users\test22\AppData\Local\Temp\nsbE11A.tmp\nsExec.dll |
file | C:\Windows\Client.exe |
file | C:\Users\test22\AppData\Local\Temp\nsbE11A.tmp\nsProcess.dll |
cmdline | C:\Windows\system32\cmd.exe /C sc description MiningeService ServiceManagerForMiner |
cmdline | C:\Windows\system32\cmd.exe /C Sc delete MiningeService |
cmdline | C:\Windows\system32\cmd.exe /C net stop MiningeService |
cmdline | C:\Windows\system32\cmd.exe /C net start MiningeService |
cmdline | C:\Windows\system32\cmd.exe /C Sc create MiningeService binpath= C:\Windows\Client.exe start= auto DisplayName= MiningeService |
file | C:\Users\test22\AppData\Local\Temp\nsbE11A.tmp\nsExec.dll |
file | C:\Users\test22\AppData\Local\Temp\nsbE11A.tmp\nsProcess.dll |
cmdline | net start MiningeService |
cmdline | C:\Windows\system32\cmd.exe /C sc description MiningeService ServiceManagerForMiner |
cmdline | Sc delete MiningeService |
cmdline | Sc create MiningeService binpath= C:\Windows\Client.exe start= auto DisplayName= MiningeService |
cmdline | net stop MiningeService |
cmdline | sc description MiningeService ServiceManagerForMiner |
cmdline | C:\Windows\system32\cmd.exe /C Sc delete MiningeService |
cmdline | C:\Windows\system32\cmd.exe /C net stop MiningeService |
cmdline | C:\Windows\system32\cmd.exe /C net start MiningeService |
cmdline | C:\Windows\system32\cmd.exe /C Sc create MiningeService binpath= C:\Windows\Client.exe start= auto DisplayName= MiningeService |
host | 91.243.59.61 |
service_name | MiningeService | service_path | C:\Windows\Client.exe |