Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Jan. 26, 2023, 10:45 a.m. | Jan. 26, 2023, 10:58 a.m. |
Name | Response | Post-Analysis Lookup |
---|---|---|
www.dailyhoroscope4you.space |
CNAME
dailyhoroscope4you.space
|
64.20.34.151 |
www.mybestfurend.com |
CNAME
shops.myshopify.com
|
23.227.38.74 |
www.precisionradiologyin.com |
CNAME
precisionradiologyin.com
|
34.102.136.180 |
www.moapulsa.com |
CNAME
moapulsa.com
|
162.0.232.224 |
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.precisionradiologyin.com/nes8/?tXU4=6NRM34jc+vx38/mfPogWJwFe/HjyXK0Ji/xFefKXSMuFdvzjgtsT/eqi9nwNkBLUKkmM2y4J&UlSpj=GTgP1nY8x6nLDr | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.moapulsa.com/nes8/?tXU4=py8vGRMZr9OTSTWstmwdIuRsGvWpk1bvMH9gd03rQ1QhqDUh/2V2C90NIaafZcqUrqdaT5G2&UlSpj=GTgP1nY8x6nLDr | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.dailyhoroscope4you.space/nes8/?tXU4=3PKzed4jsIaTQKd+wFYKFs0yZsxnNY1mkdl0hGhoMN1fqOsvNJiiqt8SDs2DNBiTtt2/R1aE&UlSpj=GTgP1nY8x6nLDr | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.mybestfurend.com/nes8/?tXU4=B88o+VQfd+uza1ucZPXDb4VegO964fw0oRUI8ak/LbvCN6sanJKzONrKEndi1iCjS7HG2HaV&UlSpj=GTgP1nY8x6nLDr |
request | GET http://www.precisionradiologyin.com/nes8/?tXU4=6NRM34jc+vx38/mfPogWJwFe/HjyXK0Ji/xFefKXSMuFdvzjgtsT/eqi9nwNkBLUKkmM2y4J&UlSpj=GTgP1nY8x6nLDr |
request | GET http://www.moapulsa.com/nes8/?tXU4=py8vGRMZr9OTSTWstmwdIuRsGvWpk1bvMH9gd03rQ1QhqDUh/2V2C90NIaafZcqUrqdaT5G2&UlSpj=GTgP1nY8x6nLDr |
request | GET http://www.dailyhoroscope4you.space/nes8/?tXU4=3PKzed4jsIaTQKd+wFYKFs0yZsxnNY1mkdl0hGhoMN1fqOsvNJiiqt8SDs2DNBiTtt2/R1aE&UlSpj=GTgP1nY8x6nLDr |
request | GET http://www.mybestfurend.com/nes8/?tXU4=B88o+VQfd+uza1ucZPXDb4VegO964fw0oRUI8ak/LbvCN6sanJKzONrKEndi1iCjS7HG2HaV&UlSpj=GTgP1nY8x6nLDr |
file | C:\Users\test22\AppData\Local\Temp\njzrk.exe |