Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 28, 2022, 9:22 a.m. | Oct. 28, 2022, 9:25 a.m. |
-
-
-
lsdmzpuaiz.exe "C:\Users\test22\AppData\Local\Temp\lsdmzpuaiz.exe"
2832
-
-
-
explorer.exe C:\Windows\Explorer.EXE
1452
Name | Response | Post-Analysis Lookup |
---|---|---|
steam007.duckdns.org | 91.192.100.7 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.56.101:54148 -> 164.124.101.2:53 | 2022918 | ET INFO DYNAMIC_DNS Query to *.duckdns. Domain | Misc activity |
UDP 192.168.56.101:55146 -> 164.124.101.2:53 | 2022918 | ET INFO DYNAMIC_DNS Query to *.duckdns. Domain | Misc activity |
Suricata TLS
No Suricata TLS
section | .ndata |
domain | steam007.duckdns.org |
file | C:\Users\test22\AppData\Local\Temp\lsdmzpuaiz.exe |
file | C:\Users\test22\AppData\Roaming\ypvc\whfwofnovxc.exe |
file | C:\Users\test22\AppData\Roaming\ypvc\whfwofnovxc.exe |
reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\xbclrsbxlwqa | reg_value | C:\Users\test22\AppData\Roaming\ypvc\whfwofnovxc.exe "C:\Users\test22\AppData\Local\Temp\lsdmzpuaiz.exe" |