Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | April 6, 2022, 5:19 p.m. | April 6, 2022, 5:22 p.m. |
-
EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" C:\Users\test22\AppData\Local\Temp\ATTR-147470270-Apr-4.xlsb
2100-
regsvr32.exe regsvr32 /s C:\ProgramData\Frister.ocx
2172 -
regsvr32.exe regsvr32 /s C:\ProgramData\Frister1.ocx
2428 -
regsvr32.exe regsvr32 /s C:\ProgramData\Frister2.ocx
2464
-
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
suspicious_features | Connection to IP address | suspicious_request | GET http://185.82.126.17/44651,6679619213.dat | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://149.255.36.223/44651,6679619213.dat | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://185.33.86.42/44651,6679619213.dat |
request | GET http://185.82.126.17/44651,6679619213.dat |
request | GET http://149.255.36.223/44651,6679619213.dat |
request | GET http://185.33.86.42/44651,6679619213.dat |
file | C:\ProgramData\Frister.ocx |
file | C:\ProgramData\Frister1.ocx |
file | C:\ProgramData\Frister2.ocx |
cmdline | regsvr32 /s C:\ProgramData\Frister.ocx |
cmdline | regsvr32 /s C:\ProgramData\Frister2.ocx |
cmdline | regsvr32 /s C:\ProgramData\Frister1.ocx |
host | 149.255.36.223 | |||
host | 185.33.86.42 | |||
host | 185.82.126.17 |
Sangfor | Malware.Generic-XLM.Save.ma35 |
Cyren | XF/SneakyBin.E.gen!Eldorado |
Avast | VBS:Malware-gen |
ClamAV | Xls.Downloader.GreenOffice12210-9918618-0 |
Kaspersky | HEUR:Trojan.MSOffice.Generic |
Tencent | Trojan.MsOffice.Macro40.11003135 |
McAfee-GW-Edition | Artemis |
Ikarus | Trojan-Downloader.XLM.Agent |
Microsoft | TrojanDownloader:O97M/Qakbot.AMDG!MTB |
ZoneAlarm | HEUR:Trojan.MSOffice.Generic |
GData | Macro.Trojan-Downloader.Agent.BDH |
Fortinet | MSExcel/Agent.IF!tr.dldr |
AVG | VBS:Malware-gen |
parent_process | excel.exe | martian_process | regsvr32 /s C:\ProgramData\Frister.ocx | ||||||
parent_process | excel.exe | martian_process | regsvr32 /s C:\ProgramData\Frister2.ocx | ||||||
parent_process | excel.exe | martian_process | regsvr32 /s C:\ProgramData\Frister1.ocx |