Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | April 6, 2023, 10 a.m. | April 6, 2023, 10:02 a.m. |
-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -ExecutionPolicy unrestricted -File C:\Users\test22\AppData\Local\Temp\work.txt.ps1
3016-
replace.exe "C:\Windows\system32\replace.exe" "OEFpSleGvJLReEHDyCQdVRRvZddnYLfmOzaoMyfrleGvJnuIOcOyncGzVOkLzVOkL OEFpS w" leGvJ s
2184 -
replace.exe "C:\Windows\system32\replace.exe" "No files replaced" LReEH c
2276 -
replace.exe "C:\Windows\system32\replace.exe" "No files replaced" DyCQd r
2356 -
replace.exe "C:\Windows\system32\replace.exe" "No files replaced" VRRvZ i
2428 -
replace.exe "C:\Windows\system32\replace.exe" "No files replaced" ddnYL p
1620 -
replace.exe "C:\Windows\system32\replace.exe" "No files replaced" fmOza t
1568 -
replace.exe "C:\Windows\system32\replace.exe" "No files replaced" oMyfr .
2540 -
replace.exe "C:\Windows\system32\replace.exe" "No files replaced" nuIOc h
1720 -
replace.exe "C:\Windows\system32\replace.exe" "No files replaced" OyncG e
1472 -
replace.exe "C:\Windows\system32\replace.exe" "No files replaced" zVOkL l
2536 -
replace.exe "C:\Windows\system32\replace.exe" "No files replaced"
2660
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
MicroWorld-eScan | Heur.BZC.PZQ.Boxter.794.5D9AF6DB |
FireEye | Heur.BZC.PZQ.Boxter.794.5D9AF6DB |
ALYac | Heur.BZC.PZQ.Boxter.794.5D9AF6DB |
VIPRE | Heur.BZC.PZQ.Boxter.794.5D9AF6DB |
Symantec | ISB.Downloader!gen80 |
Avast | Script:SNH-gen [Drp] |
Kaspersky | HEUR:Trojan.Script.Generic |
BitDefender | Heur.BZC.PZQ.Boxter.794.5D9AF6DB |
Emsisoft | Heur.BZC.PZQ.Boxter.794.5D9AF6DB (B) |
Arcabit | Heur.BZC.PZQ.Boxter.794.5D9AF6DB |
ZoneAlarm | HEUR:Trojan.Script.Generic |
MAX | malware (ai score=85) |
AVG | Script:SNH-gen [Drp] |
parent_process | powershell.exe | martian_process | "C:\Windows\system32\replace.exe" "No files replaced" nuIOc h | ||||||
parent_process | powershell.exe | martian_process | "C:\Windows\system32\replace.exe" "No files replaced" OyncG e | ||||||
parent_process | powershell.exe | martian_process | "C:\Windows\system32\replace.exe" "No files replaced" LReEH c | ||||||
parent_process | powershell.exe | martian_process | "C:\Windows\system32\replace.exe" "No files replaced" fmOza t | ||||||
parent_process | powershell.exe | martian_process | "C:\Windows\system32\replace.exe" "No files replaced" ddnYL p | ||||||
parent_process | powershell.exe | martian_process | "C:\Windows\system32\replace.exe" "No files replaced" zVOkL l | ||||||
parent_process | powershell.exe | martian_process | "C:\Windows\system32\replace.exe" "No files replaced" oMyfr . | ||||||
parent_process | powershell.exe | martian_process | "C:\Windows\system32\replace.exe" "No files replaced" | ||||||
parent_process | powershell.exe | martian_process | "C:\Windows\system32\replace.exe" "No files replaced" DyCQd r | ||||||
parent_process | powershell.exe | martian_process | "C:\Windows\system32\replace.exe" "OEFpSleGvJLReEHDyCQdVRRvZddnYLfmOzaoMyfrleGvJnuIOcOyncGzVOkLzVOkL OEFpS w" leGvJ s | ||||||
parent_process | powershell.exe | martian_process | "C:\Windows\system32\replace.exe" "No files replaced" VRRvZ i |
file | C:\Windows\System32\replace.exe |