Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | March 27, 2023, 10:45 a.m. | March 27, 2023, 10:52 a.m. |
-
msiexec.exe "C:\Windows\System32\msiexec.exe" /I C:\Users\test22\AppData\Local\Temp\t.msi
2556 -
explorer.exe C:\Windows\Explorer.EXE
1452
Name | Response | Post-Analysis Lookup |
---|---|---|
www.teramind.co | 104.22.19.138 | |
ocsp.digicert.com |
CNAME
ocsp.edge.digicert.com
CNAME
fp2e7a.wpc.phicdn.net
|
152.195.38.76 |
rt.teramind.co | 132.226.193.252 |
Suricata Alerts
No Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.101:49167 104.22.18.138:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.teramind.co | 9b:5e:3b:90:71:6a:2a:ca:24:29:25:70:35:a4:61:ed:26:fc:6c:b6 |
TLS 1.2 192.168.56.101:49170 104.22.18.138:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.teramind.co | 9b:5e:3b:90:71:6a:2a:ca:24:29:25:70:35:a4:61:ed:26:fc:6c:b6 |
TLS 1.2 192.168.56.101:49168 132.226.193.252:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.teramind.co | 9b:5e:3b:90:71:6a:2a:ca:24:29:25:70:35:a4:61:ed:26:fc:6c:b6 |
TLS 1.2 192.168.56.101:49162 132.226.193.252:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.teramind.co | 9b:5e:3b:90:71:6a:2a:ca:24:29:25:70:35:a4:61:ed:26:fc:6c:b6 |
TLS 1.2 192.168.56.101:49169 132.226.193.252:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.teramind.co | 9b:5e:3b:90:71:6a:2a:ca:24:29:25:70:35:a4:61:ed:26:fc:6c:b6 |
TLS 1.2 192.168.56.101:49175 132.226.193.252:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.teramind.co | 9b:5e:3b:90:71:6a:2a:ca:24:29:25:70:35:a4:61:ed:26:fc:6c:b6 |
TLS 1.2 192.168.56.101:49158 132.226.193.252:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.teramind.co | 9b:5e:3b:90:71:6a:2a:ca:24:29:25:70:35:a4:61:ed:26:fc:6c:b6 |
TLS 1.2 192.168.56.101:49168 132.226.193.252:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.teramind.co | 9b:5e:3b:90:71:6a:2a:ca:24:29:25:70:35:a4:61:ed:26:fc:6c:b6 |
TLS 1.2 192.168.56.101:49166 132.226.193.252:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.teramind.co | 9b:5e:3b:90:71:6a:2a:ca:24:29:25:70:35:a4:61:ed:26:fc:6c:b6 |
TLS 1.2 192.168.56.101:49169 132.226.193.252:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.teramind.co | 9b:5e:3b:90:71:6a:2a:ca:24:29:25:70:35:a4:61:ed:26:fc:6c:b6 |
TLS 1.2 192.168.56.101:49166 104.22.18.138:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.teramind.co | 9b:5e:3b:90:71:6a:2a:ca:24:29:25:70:35:a4:61:ed:26:fc:6c:b6 |
TLS 1.2 192.168.56.101:49171 104.22.18.138:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.teramind.co | 9b:5e:3b:90:71:6a:2a:ca:24:29:25:70:35:a4:61:ed:26:fc:6c:b6 |
TLS 1.2 192.168.56.101:49160 132.226.193.252:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.teramind.co | 9b:5e:3b:90:71:6a:2a:ca:24:29:25:70:35:a4:61:ed:26:fc:6c:b6 |
TLS 1.2 192.168.56.101:49173 132.226.193.252:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.teramind.co | 9b:5e:3b:90:71:6a:2a:ca:24:29:25:70:35:a4:61:ed:26:fc:6c:b6 |
TLS 1.2 192.168.56.101:49171 132.226.193.252:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.teramind.co | 9b:5e:3b:90:71:6a:2a:ca:24:29:25:70:35:a4:61:ed:26:fc:6c:b6 |
TLS 1.2 192.168.56.101:49164 132.226.193.252:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.teramind.co | 9b:5e:3b:90:71:6a:2a:ca:24:29:25:70:35:a4:61:ed:26:fc:6c:b6 |
TLS 1.2 192.168.56.101:49177 132.226.193.252:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.teramind.co | 9b:5e:3b:90:71:6a:2a:ca:24:29:25:70:35:a4:61:ed:26:fc:6c:b6 |
TLS 1.2 192.168.56.101:49178 132.226.193.252:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.teramind.co | 9b:5e:3b:90:71:6a:2a:ca:24:29:25:70:35:a4:61:ed:26:fc:6c:b6 |
request | GET http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAewQY2lHhSMMxu83rcTgyM%3D |
request | GET http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDZGCsCkDHH%2BXwJVKt4ohdOTWBUQQUy1yTroib%2FkNvVlBSAm14%2FKzhsVoCEA1e%2BQMDwigDd9%2FgTXTiCGE%3D |
request | GET http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D |
request | GET http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAP7r%2BFw4Evn1FZeRLt68uo%3D |
file | C:\Users\test22\AppData\Local\Temp\MSIF397.tmp |
ESET-NOD32 | a variant of Win32/NetFilter.A potentially unsafe |
Rising | PUF.NetFilter!8.1F0 (TFE:6:ZJJwIJgT9j) |
McAfee-GW-Edition | Artemis!9D5915FDB756 |
Ikarus | PUA.RiskWare.Teramind |
Xcitium | Malware@#2v55sd6wgpsq7 |
McAfee | Artemis!1BE54864AE1D |
Fortinet | Riskware/NetFilter |
buffer | Buffer with sha1: 0dc4583de426bc4a782d3351a0e89987d9511420 |
buffer | Buffer with sha1: 1d402b73d681cc8b203e595076ec59428827b726 |
buffer | Buffer with sha1: 4c1bcdb66e130c1ad1ef52e85b4cd1f2d7a9f5c4 |
buffer | Buffer with sha1: 73e0a81707960cc3ccb5dccef4cbb6cd51ee3710 |
buffer | Buffer with sha1: 495490531395940a70b977fa383866e157d67a30 |
host | 141.144.250.131 |
dead_host | 192.168.56.101:49159 |
dead_host | 192.168.56.101:49161 |
dead_host | 172.67.26.154:443 |
dead_host | 192.168.56.101:49179 |
dead_host | 141.144.250.131:42760 |
dead_host | 192.168.56.101:49174 |
dead_host | 192.168.56.101:49176 |
dead_host | 192.168.56.101:49172 |
dead_host | 192.168.56.101:49163 |