Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | April 13, 2022, 12:09 p.m. | April 13, 2022, 12:12 p.m. |
-
EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE" C:\Users\test22\AppData\Local\Temp\REJ-507558316-Apr-12.xlsb
2208-
regsvr32.exe regsvr32 /s C:\ProgramData\Ulhdhrthdr.dll
2448 -
regsvr32.exe regsvr32 /s C:\ProgramData\Ulhdhrthdr1.dll
2464 -
regsvr32.exe regsvr32 /s C:\ProgramData\Ulhdhrthdr2.dll
1676
-
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
suspicious_features | Connection to IP address | suspicious_request | GET http://185.82.127.37/7790983516.dat | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://87.236.146.116/7790983516.dat | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://51.195.38.33/7790983516.dat |
request | GET http://185.82.127.37/7790983516.dat |
request | GET http://87.236.146.116/7790983516.dat |
request | GET http://51.195.38.33/7790983516.dat |
file | C:\ProgramData\Ulhdhrthdr2.dll |
file | C:\ProgramData\Ulhdhrthdr.dll |
file | C:\ProgramData\Ulhdhrthdr1.dll |
cmdline | regsvr32 /s C:\ProgramData\Ulhdhrthdr.dll |
cmdline | regsvr32 /s C:\ProgramData\Ulhdhrthdr1.dll |
cmdline | regsvr32 /s C:\ProgramData\Ulhdhrthdr2.dll |
Sangfor | Malware.Generic-XLM.Save.ma35 |
Cyren | XF/SneakyBin.E.gen!Eldorado |
Avast | VBS:Malware-gen |
Kaspersky | HEUR:Trojan.MSOffice.Generic |
Tencent | Trojan.MsOffice.Macro40.11003135 |
GData | Macro.Trojan-Downloader.Agent.BDH |
Ikarus | Trojan-Downloader.XLM.Agent |
Fortinet | MSOffice/Agent.92DD!tr |
AVG | VBS:Malware-gen |
host | 185.82.127.37 | |||
host | 51.195.38.33 | |||
host | 87.236.146.116 |
parent_process | excel.exe | martian_process | regsvr32 /s C:\ProgramData\Ulhdhrthdr.dll | ||||||
parent_process | excel.exe | martian_process | regsvr32 /s C:\ProgramData\Ulhdhrthdr1.dll | ||||||
parent_process | excel.exe | martian_process | regsvr32 /s C:\ProgramData\Ulhdhrthdr2.dll |