Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | March 13, 2023, 9:55 a.m. | March 13, 2023, 9:57 a.m. |
-
qbittorrent.exe "C:\Users\test22\AppData\Local\Temp\qbittorrent.exe"
2656
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
pdb_path | qbittorrent.pdb |
section | _RDATA |
section | .qtmetad |
section | .qtmimed |
Paloalto | generic.ml |
section | {u'size_of_data': u'0x00b06800', u'virtual_address': u'0x00f96000', u'entropy': 7.463488289899328, u'name': u'.rdata', u'virtual_size': u'0x00b067a6'} | entropy | 7.4634882899 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x0004ee00', u'virtual_address': u'0x01be3000', u'entropy': 7.998000978505574, u'name': u'.qtmimed', u'virtual_size': u'0x0004ece5'} | entropy | 7.99800097851 | description | A section with a high entropy has been found | |||||||||
entropy | 0.400168956778 | description | Overall entropy of this PE file is high |
file | C:\Users\test22\AppData\Roaming\qBittorrent\qBittorrent_new.ini.lock |