Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | April 7, 2022, 5:29 p.m. | April 7, 2022, 5:32 p.m. |
-
EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" C:\Users\test22\AppData\Local\Temp\SNC-66168115-Apr-6.xlsb
2200-
regsvr32.exe regsvr32 /s C:\ProgramData\Frister.ocx
196 -
regsvr32.exe regsvr32 /s C:\ProgramData\Frister1.ocx
1620 -
regsvr32.exe regsvr32 /s C:\ProgramData\Frister2.ocx
1604
-
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
suspicious_features | Connection to IP address | suspicious_request | GET http://212.46.38.179/7790983516.dat | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://91.234.254.131/7790983516.dat |
request | GET http://212.46.38.179/7790983516.dat |
request | GET http://91.234.254.131/7790983516.dat |
file | C:\ProgramData\Frister.ocx |
file | C:\ProgramData\Frister1.ocx |
file | C:\ProgramData\Frister2.ocx |
cmdline | regsvr32 /s C:\ProgramData\Frister.ocx |
cmdline | regsvr32 /s C:\ProgramData\Frister2.ocx |
cmdline | regsvr32 /s C:\ProgramData\Frister1.ocx |
host | 104.225.129.111 | |||
host | 212.46.38.179 | |||
host | 91.234.254.131 |
parent_process | excel.exe | martian_process | regsvr32 /s C:\ProgramData\Frister.ocx | ||||||
parent_process | excel.exe | martian_process | regsvr32 /s C:\ProgramData\Frister2.ocx | ||||||
parent_process | excel.exe | martian_process | regsvr32 /s C:\ProgramData\Frister1.ocx |
dead_host | 104.225.129.111:80 |