Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Dec. 10, 2022, 2:43 p.m. | Dec. 10, 2022, 2:58 p.m. |
Name | Response | Post-Analysis Lookup |
---|---|---|
www.coffeeforyou56.com | 104.21.69.166 | |
www.suratdimond.com | 163.197.224.28 | |
www.lesyeuxdanslespoches.com |
CNAME
balancer-ccm.wixdns.net
CNAME
gcdn0.wixdns.net
|
199.15.163.148 |
www.floridaindianrivergeoves.com | 185.53.179.174 |
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.coffeeforyou56.com/wh23/?u6Ad=+Z/9GnRooy4uMI/2ytyzBxmfIRzkEihmLnUbG9gon5BvVZqaawbrlsvFopSkMy8/ynATbtGm&9rQl7P=xPJtLXbP | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.lesyeuxdanslespoches.com/wh23/?u6Ad=2UBdbPyJ3BJ1PizOWtFy1nFuYMz29j0z90R/CygIgf7oXdu1OYqDC0mFcr3+ZljEfmCRWGcD&9rQl7P=xPJtLXbP | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.floridaindianrivergeoves.com/wh23/?u6Ad=HQs9sY6MfmjvG4BCT+S8X4weKQ3jHGmqz4mij5NJ3M2nb+7m/H8tNbVgpdoIwpufVMaXPBq3&9rQl7P=xPJtLXbP | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.suratdimond.com/wh23/?u6Ad=jUJ7bRHoxkHA5rahzGpJGSe+g9rlOc6E7RlDBgSrRJk0jchNThhp3wI7m3+F7bQyA0QFLd33&9rQl7P=xPJtLXbP |
request | GET http://www.coffeeforyou56.com/wh23/?u6Ad=+Z/9GnRooy4uMI/2ytyzBxmfIRzkEihmLnUbG9gon5BvVZqaawbrlsvFopSkMy8/ynATbtGm&9rQl7P=xPJtLXbP |
request | GET http://www.lesyeuxdanslespoches.com/wh23/?u6Ad=2UBdbPyJ3BJ1PizOWtFy1nFuYMz29j0z90R/CygIgf7oXdu1OYqDC0mFcr3+ZljEfmCRWGcD&9rQl7P=xPJtLXbP |
request | GET http://www.floridaindianrivergeoves.com/wh23/?u6Ad=HQs9sY6MfmjvG4BCT+S8X4weKQ3jHGmqz4mij5NJ3M2nb+7m/H8tNbVgpdoIwpufVMaXPBq3&9rQl7P=xPJtLXbP |
request | GET http://www.suratdimond.com/wh23/?u6Ad=jUJ7bRHoxkHA5rahzGpJGSe+g9rlOc6E7RlDBgSrRJk0jchNThhp3wI7m3+F7bQyA0QFLd33&9rQl7P=xPJtLXbP |
file | C:\Users\test22\AppData\Local\Temp\myxwn.exe |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Gen:Variant.Jaik.77520 |
FireEye | Gen:Variant.Jaik.77520 |
CrowdStrike | win/malicious_confidence_90% (D) |
Arcabit | Trojan.Jaik.D12ED0 |
Symantec | ML.Attribute.HighConfidence |
Cynet | Malicious (score: 100) |
APEX | Malicious |
Kaspersky | VHO:Trojan.Win32.FormBook.gen |
BitDefender | Gen:Variant.Jaik.77520 |
Ad-Aware | Gen:Variant.Jaik.77520 |
Emsisoft | Gen:Variant.Jaik.77520 (B) |
VIPRE | Gen:Variant.Jaik.77520 |
MAX | malware (ai score=81) |
Antiy-AVL | Trojan/NSIS.Formbook.a |
ZoneAlarm | VHO:Trojan.Win32.FormBook.gen |
GData | Gen:Variant.Jaik.77520 |
Detected | |
BitDefenderTheta | Gen:NN.ZexaF.36106.rqW@a4XKZKo |
Malwarebytes | Malware.AI.4239435998 |
Rising | Trojan.Injector!8.C4 (TFE:1:Gm8DD6ShD4R) |
Ikarus | Trojan.NSIS.Injector |
Fortinet | W32/Injector.ESIU!tr |
Cybereason | malicious.cf78e7 |