Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | March 29, 2023, 5:33 p.m. | March 29, 2023, 5:43 p.m. |
-
-
pee bin.exe "C:\Users\test22\AppData\Local\Temp\pee bin.exe"
2648
-
IP Address | Status | Action |
---|---|---|
104.253.54.44 | Active | Moloch |
164.124.101.2 | Active | Moloch |
172.67.213.169 | Active | Moloch |
18.140.6.45 | Active | Moloch |
194.58.112.174 | Active | Moloch |
198.54.117.218 | Active | Moloch |
216.40.34.41 | Active | Moloch |
23.231.72.112 | Active | Moloch |
34.117.168.233 | Active | Moloch |
45.33.6.223 | Active | Moloch |
66.96.162.138 | Active | Moloch |
Suricata Alerts
Suricata TLS
No Suricata TLS
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.csrvcars.com/udh1/?cUMMa5v=XEemPPOTV26sKXQzDYMsrkGsJokzxPFPbFpU+n9uCd2chnbXsi75dkjdHRd+i/N9AgC/cMMMBBk+slWuActf4QAZvLu0iyaFuJXVPTg=&GV=hSkJd_W | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.zhn.biz/udh1/?cUMMa5v=LfrgFpvSkJA2y41K7oV1vuuQyWHfo0uy5ufNO5HpKtxTTE0bBGpeg3SJ2RFsjNe1w4Pec63rxh4rwW+J1uIf4mhDhIMbmXY09bayaEE=&GV=hSkJd_W | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.special-order.online/udh1/?cUMMa5v=CwuBCJt94bxtc2gNtpoM3E+US0dkKMARx3Pvc7vf2LAtLU32691wJ0dQetaubb0PioG6wR7W5uX4+q4XU8z6LBF3Qfs1ipW/MdlZd78=&GV=hSkJd_W | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.azstoreatoderma.click/udh1/?cUMMa5v=R/kB4/0HM2tcwqvhXH4XIYj1eTxJXqndlHH19RjFed8ZhY1qAasVyZxg1ws7A7LtJYEr4634gz6I87tnmhAW+ys9K/jaGw++UPdFo8c=&GV=hSkJd_W | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.olympusmix.com/udh1/?cUMMa5v=lWZk+s3blMuiGWpXy6frpU4enEwBG5gJanUH8/6Evmw4nHtx+SdA/kN+9f5N/0KA2bk6RtFa0tH8PADjgLi95JHf+wn8BjREHXSWn6U=&GV=hSkJd_W | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.ghostdyes.net/udh1/?cUMMa5v=lj2vP+EAw0fELJNPJ5VtAcTjxQQz8hKi5d9v+h5W1hvMFJJN0lWMU8OkjsFxsGAkw0S50RNizKyMtcUDX4tgR0i1IahDyycai/CThP0=&GV=hSkJd_W | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.wearecatalyst.app/udh1/?cUMMa5v=tt9dYLtFsKfLIIIXMfpRfs924GbOuHLcMLKVMdaTOcJrEAGIFAHeQ5Ly9YOpmT4Rz3p2Jl5Xgzq6cAPtFXnDdyfQg2kRv5Z1dRZDL3M=&GV=hSkJd_W | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.centaura.community/udh1/?cUMMa5v=kMKsR5rTxSYNZgWncVUlGrpLkwsOTig3tGW39qhs19NQJLtwYtRkr4H+EIRE8MUOxMFfo6MP6730mq+L8n2Tmf9vKWCdpbnfDO0cF8Q=&GV=hSkJd_W |
request | GET http://www.csrvcars.com/udh1/?cUMMa5v=XEemPPOTV26sKXQzDYMsrkGsJokzxPFPbFpU+n9uCd2chnbXsi75dkjdHRd+i/N9AgC/cMMMBBk+slWuActf4QAZvLu0iyaFuJXVPTg=&GV=hSkJd_W |
request | GET http://www.sqlite.org/2020/sqlite-dll-win32-x86-3320000.zip |
request | POST http://www.zhn.biz/udh1/ |
request | GET http://www.zhn.biz/udh1/?cUMMa5v=LfrgFpvSkJA2y41K7oV1vuuQyWHfo0uy5ufNO5HpKtxTTE0bBGpeg3SJ2RFsjNe1w4Pec63rxh4rwW+J1uIf4mhDhIMbmXY09bayaEE=&GV=hSkJd_W |
request | POST http://www.special-order.online/udh1/ |
request | GET http://www.special-order.online/udh1/?cUMMa5v=CwuBCJt94bxtc2gNtpoM3E+US0dkKMARx3Pvc7vf2LAtLU32691wJ0dQetaubb0PioG6wR7W5uX4+q4XU8z6LBF3Qfs1ipW/MdlZd78=&GV=hSkJd_W |
request | POST http://www.azstoreatoderma.click/udh1/ |
request | GET http://www.azstoreatoderma.click/udh1/?cUMMa5v=R/kB4/0HM2tcwqvhXH4XIYj1eTxJXqndlHH19RjFed8ZhY1qAasVyZxg1ws7A7LtJYEr4634gz6I87tnmhAW+ys9K/jaGw++UPdFo8c=&GV=hSkJd_W |
request | POST http://www.olympusmix.com/udh1/ |
request | GET http://www.olympusmix.com/udh1/?cUMMa5v=lWZk+s3blMuiGWpXy6frpU4enEwBG5gJanUH8/6Evmw4nHtx+SdA/kN+9f5N/0KA2bk6RtFa0tH8PADjgLi95JHf+wn8BjREHXSWn6U=&GV=hSkJd_W |
request | POST http://www.ghostdyes.net/udh1/ |
request | GET http://www.ghostdyes.net/udh1/?cUMMa5v=lj2vP+EAw0fELJNPJ5VtAcTjxQQz8hKi5d9v+h5W1hvMFJJN0lWMU8OkjsFxsGAkw0S50RNizKyMtcUDX4tgR0i1IahDyycai/CThP0=&GV=hSkJd_W |
request | POST http://www.wearecatalyst.app/udh1/ |
request | GET http://www.wearecatalyst.app/udh1/?cUMMa5v=tt9dYLtFsKfLIIIXMfpRfs924GbOuHLcMLKVMdaTOcJrEAGIFAHeQ5Ly9YOpmT4Rz3p2Jl5Xgzq6cAPtFXnDdyfQg2kRv5Z1dRZDL3M=&GV=hSkJd_W |
request | POST http://www.centaura.community/udh1/ |
request | GET http://www.centaura.community/udh1/?cUMMa5v=kMKsR5rTxSYNZgWncVUlGrpLkwsOTig3tGW39qhs19NQJLtwYtRkr4H+EIRE8MUOxMFfo6MP6730mq+L8n2Tmf9vKWCdpbnfDO0cF8Q=&GV=hSkJd_W |
request | POST http://www.zhn.biz/udh1/ |
request | POST http://www.special-order.online/udh1/ |
request | POST http://www.azstoreatoderma.click/udh1/ |
request | POST http://www.olympusmix.com/udh1/ |
request | POST http://www.ghostdyes.net/udh1/ |
request | POST http://www.wearecatalyst.app/udh1/ |
request | POST http://www.centaura.community/udh1/ |
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 | ||||||||||||||||||
name | RT_VERSION | language | LANG_SERBIAN | filetype | data | sublanguage | SUBLANG_SERBIAN_CYRILLIC | offset | 0x00046310 | size | 0x00000308 |
file | C:\Users\test22\AppData\Local\Temp\pee bin.exe |
section | {u'size_of_data': u'0x00033600', u'virtual_address': u'0x00002000', u'entropy': 7.931602780518816, u'name': u'.text', u'virtual_size': u'0x000335d3'} | entropy | 7.93160278052 | description | A section with a high entropy has been found | |||||||||
entropy | 0.754128440367 | description | Overall entropy of this PE file is high |
dead_host | 104.253.54.44:80 |
Bkav | W32.AIDetectNet.01 |
Lionic | Trojan.Win32.Generic.mgtv |
DrWeb | Trojan.Siggen20.16305 |
MicroWorld-eScan | Gen:Heur.MSIL.Jalapeno.J.36 |
FireEye | Generic.mg.a82baff8213bd78f |
CAT-QuickHeal | Trojan.Agent |
McAfee | Artemis!A82BAFF8213B |
Malwarebytes | Malware.AI.4238811965 |
Zillya | Dropper.Jalapeno.Win32.1 |
Sangfor | Suspicious.Win32.Save.a |
Alibaba | TrojanSpy:MSIL/Jalapeno.c7f5f1e9 |
CrowdStrike | win/malicious_confidence_100% (W) |
Arcabit | Trojan.MSIL.Jalapeno.J.36 |
BitDefenderTheta | Gen:NN.ZemsilF.36344.rm0@aOj@u7DH |
Cyren | W32/ABRisk.OOTH-8942 |
Symantec | ML.Attribute.HighConfidence |
Elastic | malicious (high confidence) |
APEX | Malicious |
Paloalto | generic.ml |
Cynet | Malicious (score: 100) |
Kaspersky | HEUR:Trojan-Spy.MSIL.Noon.gen |
BitDefender | Gen:Heur.MSIL.Jalapeno.J.36 |
Avast | Win32:PWSX-gen [Trj] |
Tencent | Msil.Trojan-Spy.Noon.Rsmw |
Sophos | ML/PE-A |
VIPRE | Gen:Heur.MSIL.Jalapeno.J.36 |
McAfee-GW-Edition | Artemis!Trojan |
Trapmine | malicious.moderate.ml.score |
Emsisoft | Gen:Heur.MSIL.Jalapeno.J.36 (B) |
SentinelOne | Static AI - Malicious PE |
Avira | TR/Dropper.MSIL.Gen |
Antiy-AVL | Trojan/Win32.Wacatac |
Gridinsoft | Ransom.Win32.Wacatac.sa |
Microsoft | Trojan:Win32/Tiggre!rfn |
GData | MSIL.Malware.FakeGoogle.B |
Detected | |
AhnLab-V3 | Trojan/Win.Jalapeno.C5398063 |
Acronis | suspicious |
VBA32 | TScope.Trojan.MSIL |
ALYac | Gen:Heur.MSIL.Jalapeno.J.36 |
MAX | malware (ai score=89) |
Cylance | unsafe |
TrendMicro-HouseCall | TROJ_GEN.R002H09CK23 |
Rising | Malware.Obfus/MSIL@AI.83 (RDM.MSIL2:2wG+/e0QB3GzjiJwtjhdpg) |
Yandex | Trojan.DR.MSIL!RwFr7XWFA9s |
Ikarus | Trojan.MSIL.Crypt |
MaxSecure | Trojan.Malware.300983.susgen |
Fortinet | PossibleThreat |
AVG | Win32:PWSX-gen [Trj] |
Panda | Trj/Chgt.AD |