Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | March 29, 2023, 11:04 a.m. | March 29, 2023, 11:06 a.m. |
Name | Response | Post-Analysis Lookup |
---|---|---|
www.ndyc.africa | ||
www.rahilprakash.com |
CNAME
rahilprakash.com
|
13.248.243.5 |
www.cloud-spartan.co.uk | 35.227.197.36 | |
www.oliviahodges04.uk |
CNAME
oliviahodges04.uk
|
192.0.78.24 |
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.oliviahodges04.uk/sa79/?T8kD=3HmUkRFWstZ/xsvvXCVgYJLRrrcnJmgiwegIDeQwZYyLk7GSagwRMPBNdLuE3jtARa50r64A&Vnw0Z=-Z2hTbdPQ2dhN4y | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.rahilprakash.com/sa79/?T8kD=FQxM/LfEtsdNPd9lcQ3fHhWjGCP7SrZqu0I9GJfO6cOgbFH11N56o5A937py/xwkq6yJtR1f&Vnw0Z=-Z2hTbdPQ2dhN4y | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.cloud-spartan.co.uk/sa79/?T8kD=jkxHAd9GAbQei4M5qdOAezShFl0g6rfkBT3I54TzQtwvhmYtcfZekS4RyxImys3XUoylJySQ&Vnw0Z=-Z2hTbdPQ2dhN4y |
request | GET http://www.oliviahodges04.uk/sa79/?T8kD=3HmUkRFWstZ/xsvvXCVgYJLRrrcnJmgiwegIDeQwZYyLk7GSagwRMPBNdLuE3jtARa50r64A&Vnw0Z=-Z2hTbdPQ2dhN4y |
request | GET http://www.rahilprakash.com/sa79/?T8kD=FQxM/LfEtsdNPd9lcQ3fHhWjGCP7SrZqu0I9GJfO6cOgbFH11N56o5A937py/xwkq6yJtR1f&Vnw0Z=-Z2hTbdPQ2dhN4y |
request | GET http://www.cloud-spartan.co.uk/sa79/?T8kD=jkxHAd9GAbQei4M5qdOAezShFl0g6rfkBT3I54TzQtwvhmYtcfZekS4RyxImys3XUoylJySQ&Vnw0Z=-Z2hTbdPQ2dhN4y |
file | C:\Users\test22\AppData\Local\Temp\omrjw.exe |
file | C:\Users\test22\AppData\Local\Temp\omrjw.exe |
file | C:\Users\test22\AppData\Local\Temp\omrjw.exe |
cmdline | /c del "C:\Users\test22\AppData\Local\Temp\omrjw.exe" |
cmdline | C:\Windows\SysWOW64\ipconfig.exe |
Lionic | Trojan.Win32.Agent.tshg |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Trojan.GenericKD.66137738 |
FireEye | Generic.mg.542ef4a811e2fa45 |
ALYac | Trojan.NSISX.Spy.Gen.24 |
Cylance | unsafe |
VIPRE | Trojan.NSISX.Spy.Gen.24 |
Sangfor | Suspicious.Win32.Save.ins |
CrowdStrike | win/malicious_confidence_100% (W) |
Arcabit | Trojan.NSISX.Spy.Gen.24 |
BitDefenderTheta | Gen:NN.ZexaCO.36344.jmW@au11rJh |
Cyren | W32/Injector.BKZ.gen!Eldorado |
Symantec | Packed.NSISPacker!g14 |
ESET-NOD32 | a variant of Win32/Injector.ESVB |
Cynet | Malicious (score: 100) |
APEX | Malicious |
Avast | Win32:InjectorX-gen [Trj] |
Kaspersky | HEUR:Trojan.Win32.Strab.gen |
BitDefender | Trojan.GenericKD.66137738 |
Sophos | Generic ML PUA (PUA) |
McAfee-GW-Edition | BehavesLike.Win32.VTFlooder.fc |
Trapmine | malicious.moderate.ml.score |
Emsisoft | Trojan.GenericKD.66137738 (B) |
Paloalto | generic.ml |
Webroot | W32.Trojan.NSISX.Spy |
Avira | HEUR/AGEN.1337962 |
MAX | malware (ai score=83) |
Xcitium | ApplicUnwnt@#1m580nr7uaobf |
Microsoft | Trojan:Win32/Sabsik.FL.B!ml |
ViRobot | Trojan.Win.Z.Spy.308685 |
GData | Win32.Trojan.Agent.F7HCGB |
Detected | |
AhnLab-V3 | Trojan/Win.NsisInject.R566577 |
McAfee | RDN/Formbook |
TrendMicro-HouseCall | TROJ_GEN.R002H07CS23 |
Rising | Trojan.Nsisinject!8.11178 (TFE:5:FggQ3JtuFLB) |
SentinelOne | Static AI - Suspicious PE |
Fortinet | W32/ShellcodeRunner.CA!tr |
AVG | Win32:InjectorX-gen [Trj] |