Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Jan. 26, 2023, 10:45 a.m. | Jan. 26, 2023, 11 a.m. |
-
-
xnozsgld.exe "C:\Users\test22\AppData\Local\Temp\xnozsgld.exe" C:\Users\test22\AppData\Local\Temp\ucpha.v
2684-
xnozsgld.exe "C:\Users\test22\AppData\Local\Temp\xnozsgld.exe"
2748
-
-
IP Address | Status | Action |
---|---|---|
104.21.35.28 | Active | Moloch |
142.250.206.243 | Active | Moloch |
153.127.67.174 | Active | Moloch |
164.124.101.2 | Active | Moloch |
172.247.35.173 | Active | Moloch |
172.255.33.179 | Active | Moloch |
192.64.115.133 | Active | Moloch |
212.192.29.71 | Active | Moloch |
45.33.6.223 | Active | Moloch |
67.21.71.208 | Active | Moloch |
85.159.66.93 | Active | Moloch |
77.73.134.27 | Active | Moloch |
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.drzjup.space/poub/?J48=40Bx8EyWv8P+i1Jftv0PhY/pDmItvHshlkY6DW3zkQKyS/2JCbpjIli9ng3IcYNCUXNlH95B&EhU4Nv=gdM0vL4huV | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.agence-dragonne.com/poub/?J48=AJ1lnItlOBOMu4VTxug+YhiyjjMIB0X6igB7b1gQ1/FyMjSiMMj6SiFHodYf6/xohFqvUB4/&EhU4Nv=gdM0vL4huV | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.peiphitan.com/poub/?J48=ATAcuLZUC31KidgcYb19mFWjhNBYfyBOUVVLHyPrp+l/4SglTnRQ0k7NA0aYiC9nx29Ko6aV&EhU4Nv=gdM0vL4huV | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.soldbylena.com/poub/?J48=Yx1Go82kz3quMGBdMT8MTkTpwx2C2fKFreghtdDiaVm/DdA3lQSzkCq363BA4rx6egegMd3w&EhU4Nv=gdM0vL4huV | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.cheapboden.com/poub/?J48=uMC/GsanvNpPbNcCVsDObBSsNNWRYBZ6HNwnYtWwxIAICQHEP8X1B519TLgsyoj5ym3DSXfy&EhU4Nv=gdM0vL4huV | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.midundao.net/poub/?J48=BeQSaNCZ8Cc+ObDJRvydEORS/RePR8oKq7xoUj49pHjj3eul8epkA9+9TFgjCI7880YVFtR7&EhU4Nv=gdM0vL4huV |
request | GET http://www.drzjup.space/poub/?J48=40Bx8EyWv8P+i1Jftv0PhY/pDmItvHshlkY6DW3zkQKyS/2JCbpjIli9ng3IcYNCUXNlH95B&EhU4Nv=gdM0vL4huV |
request | GET http://www.agence-dragonne.com/poub/?J48=AJ1lnItlOBOMu4VTxug+YhiyjjMIB0X6igB7b1gQ1/FyMjSiMMj6SiFHodYf6/xohFqvUB4/&EhU4Nv=gdM0vL4huV |
request | GET http://www.peiphitan.com/poub/?J48=ATAcuLZUC31KidgcYb19mFWjhNBYfyBOUVVLHyPrp+l/4SglTnRQ0k7NA0aYiC9nx29Ko6aV&EhU4Nv=gdM0vL4huV |
request | GET http://www.sqlite.org/2014/sqlite-dll-win32-x86-3080500.zip |
request | GET http://www.soldbylena.com/poub/?J48=Yx1Go82kz3quMGBdMT8MTkTpwx2C2fKFreghtdDiaVm/DdA3lQSzkCq363BA4rx6egegMd3w&EhU4Nv=gdM0vL4huV |
request | GET http://www.cheapboden.com/poub/?J48=uMC/GsanvNpPbNcCVsDObBSsNNWRYBZ6HNwnYtWwxIAICQHEP8X1B519TLgsyoj5ym3DSXfy&EhU4Nv=gdM0vL4huV |
request | GET http://www.midundao.net/poub/?J48=BeQSaNCZ8Cc+ObDJRvydEORS/RePR8oKq7xoUj49pHjj3eul8epkA9+9TFgjCI7880YVFtR7&EhU4Nv=gdM0vL4huV |
file | C:\Users\test22\AppData\Local\Temp\xnozsgld.exe |
host | 77.73.134.27 |
dead_host | 67.21.71.208:80 |
Lionic | Trojan.Win32.Noon.4!c |
FireEye | Generic.mg.58a93d1d064b9e82 |
McAfee | Artemis!58A93D1D064B |
Cylance | Unsafe |
Sangfor | Suspicious.Win32.Save.ins |
Cyren | W32/Injector.BJL.gen!Eldorado |
Symantec | Packed.NSISPacker!g14 |
Elastic | malicious (high confidence) |
ESET-NOD32 | a variant of Win32/Injector.ESPG |
Cynet | Malicious (score: 100) |
APEX | Malicious |
Kaspersky | UDS:DangerousObject.Multi.Generic |
Avast | Win32:InjectorX-gen [Trj] |
DrWeb | Trojan.Siggen19.32851 |
McAfee-GW-Edition | BehavesLike.Win32.Downloader.fc |
Trapmine | malicious.moderate.ml.score |
Sophos | Mal/Generic-S |
SentinelOne | Static AI - Suspicious PE |
Webroot | W32.Infostealer.Formbook |
Avira | TR/AD.GenShell.kxkjx |
Antiy-AVL | Trojan/Win32.Sabsik |
Gridinsoft | Ransom.Win32.Wacatac.sa |
Microsoft | Trojan:Win32/Casdet!rfn |
GData | Win32.Trojan-Stealer.FormBook.UVFAG0 |
Detected | |
Malwarebytes | Trojan.MalPack.GS |
Rising | Trojan.Injector!8.C4 (CLOUD) |
Ikarus | Trojan.Inject |
Fortinet | W32/Injector.NSAY!tr |
AVG | Win32:InjectorX-gen [Trj] |