Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | April 11, 2022, 10:51 a.m. | April 11, 2022, 10:53 a.m. |
-
EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" C:\Users\test22\AppData\Local\Temp\R-1690355177.xlsb
2188-
regsvr32.exe regsvr32 C:\Uduw\coit1.dll
2436 -
regsvr32.exe regsvr32 C:\Uduw\coit2.dll
1676 -
regsvr32.exe regsvr32 C:\Uduw\coit3.dll
2564
-
Name | Response | Post-Analysis Lookup |
---|---|---|
rangopurnews.com | 107.167.95.30 | |
sankalpnurshinghome.com | 162.241.148.33 | |
cruzandsons.co.za | 192.185.16.131 |
Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Uduw\coit2.dll |
file | C:\Uduw\coit3.dll |
file | C:\Uduw\coit1.dll |
cmdline | regsvr32 C:\Uduw\coit2.dll |
cmdline | regsvr32 C:\Uduw\coit3.dll |
cmdline | regsvr32 C:\Uduw\coit1.dll |
parent_process | excel.exe | martian_process | regsvr32 C:\Uduw\coit2.dll | ||||||
parent_process | excel.exe | martian_process | regsvr32 C:\Uduw\coit3.dll | ||||||
parent_process | excel.exe | martian_process | regsvr32 C:\Uduw\coit1.dll |