Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Nov. 18, 2021, 12:53 p.m. | Nov. 18, 2021, 12:53 p.m. |
-
octafx4setup.exe "C:\Users\test22\AppData\Local\Temp\octafx4setup.exe"
2796
Name | Response | Post-Analysis Lookup |
---|---|---|
download.mql5.com | 27.111.161.152 | |
content.mql5.com | 27.111.161.150 | |
api9.mql5.net | 147.75.92.40 | |
api14.mql5.net |
A
0.0.0.0
|
0.0.0.0 |
crt.usertrust.com |
CNAME
crt.comodoca.com
|
91.199.212.52 |
IP Address | Status | Action |
---|---|---|
102.68.85.100 | Active | Moloch |
103.26.205.122 | Active | Moloch |
117.20.41.198 | Active | Moloch |
142.215.208.235 | Active | Moloch |
147.139.41.121 | Active | Moloch |
147.75.48.214 | Active | Moloch |
147.75.92.40 | Active | Moloch |
156.38.206.18 | Active | Moloch |
156.38.206.21 | Active | Moloch |
164.124.101.2 | Active | Moloch |
177.154.156.125 | Active | Moloch |
195.201.80.82 | Active | Moloch |
27.111.161.150 | Active | Moloch |
27.111.161.152 | Active | Moloch |
47.74.84.54 | Active | Moloch |
47.91.24.164 | Active | Moloch |
78.140.180.43 | Active | Moloch |
88.212.232.132 | Active | Moloch |
91.199.212.52 | Active | Moloch |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.101:49223 78.140.180.43:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Domain Validation Secure Server CA | CN=*.mql5.net | 2b:27:bf:69:5f:ae:13:cd:07:b9:0a:d1:5a:b0:51:f3:7b:ab:69:0d |
TLS 1.2 192.168.56.101:49170 27.111.161.152:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Domain Validation Secure Server CA | CN=*.mql5.com | 11:c6:6f:e9:03:73:a1:89:6a:e8:05:1b:7a:8a:e2:f6:bc:94:09:61 |
TLS 1.2 192.168.56.101:49224 117.20.41.198:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Domain Validation Secure Server CA | CN=*.mql5.net | 2b:27:bf:69:5f:ae:13:cd:07:b9:0a:d1:5a:b0:51:f3:7b:ab:69:0d |
TLS 1.2 192.168.56.101:49233 102.68.85.100:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Domain Validation Secure Server CA | CN=*.mql5.net | 2b:27:bf:69:5f:ae:13:cd:07:b9:0a:d1:5a:b0:51:f3:7b:ab:69:0d |
TLS 1.2 192.168.56.101:49231 195.201.80.82:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Domain Validation Secure Server CA | CN=*.mql5.net | 2b:27:bf:69:5f:ae:13:cd:07:b9:0a:d1:5a:b0:51:f3:7b:ab:69:0d |
TLS 1.2 192.168.56.101:49248 147.75.92.40:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Domain Validation Secure Server CA | CN=*.mql5.net | 2b:27:bf:69:5f:ae:13:cd:07:b9:0a:d1:5a:b0:51:f3:7b:ab:69:0d |
TLS 1.2 192.168.56.101:49245 147.75.48.214:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Domain Validation Secure Server CA | CN=*.mql5.net | 2b:27:bf:69:5f:ae:13:cd:07:b9:0a:d1:5a:b0:51:f3:7b:ab:69:0d |
TLS 1.2 192.168.56.101:49234 27.111.161.152:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Domain Validation Secure Server CA | CN=*.mql5.net | 2b:27:bf:69:5f:ae:13:cd:07:b9:0a:d1:5a:b0:51:f3:7b:ab:69:0d |
TLS 1.2 192.168.56.101:49240 147.75.92.40:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Domain Validation Secure Server CA | CN=*.mql5.net | 2b:27:bf:69:5f:ae:13:cd:07:b9:0a:d1:5a:b0:51:f3:7b:ab:69:0d |
TLS 1.2 192.168.56.101:49228 142.215.208.235:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Domain Validation Secure Server CA | CN=*.mql5.net | 2b:27:bf:69:5f:ae:13:cd:07:b9:0a:d1:5a:b0:51:f3:7b:ab:69:0d |
TLS 1.2 192.168.56.101:49226 88.212.232.132:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Domain Validation Secure Server CA | CN=*.mql5.net | 2b:27:bf:69:5f:ae:13:cd:07:b9:0a:d1:5a:b0:51:f3:7b:ab:69:0d |
TLS 1.2 192.168.56.101:49244 103.26.205.122:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Domain Validation Secure Server CA | CN=*.mql5.net | 2b:27:bf:69:5f:ae:13:cd:07:b9:0a:d1:5a:b0:51:f3:7b:ab:69:0d |
TLS 1.2 192.168.56.101:49162 27.111.161.150:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Domain Validation Secure Server CA | CN=*.mql5.com | 11:c6:6f:e9:03:73:a1:89:6a:e8:05:1b:7a:8a:e2:f6:bc:94:09:61 |
TLS 1.2 192.168.56.101:49251 147.75.92.40:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Domain Validation Secure Server CA | CN=*.mql5.net | 2b:27:bf:69:5f:ae:13:cd:07:b9:0a:d1:5a:b0:51:f3:7b:ab:69:0d |
TLS 1.2 192.168.56.101:49247 156.38.206.18:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Domain Validation Secure Server CA | CN=*.mql5.net | 2b:27:bf:69:5f:ae:13:cd:07:b9:0a:d1:5a:b0:51:f3:7b:ab:69:0d |
TLS 1.2 192.168.56.101:49232 177.154.156.125:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Domain Validation Secure Server CA | CN=*.mql5.net | 2b:27:bf:69:5f:ae:13:cd:07:b9:0a:d1:5a:b0:51:f3:7b:ab:69:0d |
TLS 1.2 192.168.56.101:49250 156.38.206.18:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo ECC Domain Validation Secure Server CA | CN=*.mql5.net | 2b:27:bf:69:5f:ae:13:cd:07:b9:0a:d1:5a:b0:51:f3:7b:ab:69:0d |
resource name | AFX_DIALOG_LAYOUT |
resource name | FILE |
resource name | LNG |
request | GET http://crt.usertrust.com/USERTrustECCAddTrustCA.crt |
description | octafx4setup.exe tried to sleep 309 seconds, actually delayed analysis time by 9 seconds |
file | C:\Users\test22\AppData\Local\Temp\SandboxieInstall.exe |
file | C:\Users\test22\AppData\Local\Temp\202005191702_6d173b9549ce4fe1e5ada5ab9ce0bfff5d9569f19e7fa916db5c8d4f0dace63b_setup_nwc275a_demo.exe |
file | C:\Users\test22\AppData\Local\Temp\octafx4setup.exe |
wmi | SELECT * FROM Win32_VideoController |
Jiangmin | Trojan.PSW.Stelega.gu |
section | {u'size_of_data': u'0x000f7c00', u'virtual_address': u'0x00233000', u'entropy': 7.849635161794706, u'name': u'UPX1', u'virtual_size': u'0x000f8000'} | entropy | 7.84963516179 | description | A section with a high entropy has been found | |||||||||
entropy | 0.863616557734 | description | Overall entropy of this PE file is high |
section | UPX0 | description | Section name indicates UPX | ||||||
section | UPX1 | description | Section name indicates UPX |
host | 102.68.85.100 | |||
host | 103.26.205.122 | |||
host | 117.20.41.198 | |||
host | 142.215.208.235 | |||
host | 147.139.41.121 | |||
host | 147.75.48.214 | |||
host | 156.38.206.18 | |||
host | 156.38.206.21 | |||
host | 177.154.156.125 | |||
host | 195.201.80.82 | |||
host | 47.74.84.54 | |||
host | 47.91.24.164 | |||
host | 78.140.180.43 | |||
host | 88.212.232.132 |
file | C:\Users\test22\AppData\Local\Temp\octafx4setup.exe:Zone.Identifier:$DATA |
file | C:\Users\test22\AppData\Local\Temp\SandboxieInstall.exe |
registry | HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ProcessorNameString |