Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | April 19, 2023, 5:47 p.m. | April 19, 2023, 5:50 p.m. |
-
-
wmweglq.exe "C:\Users\test22\AppData\Local\Temp\wmweglq.exe" C:\Users\test22\AppData\Local\Temp\qicbf.ggy
2644-
wmweglq.exe "C:\Users\test22\AppData\Local\Temp\wmweglq.exe"
2700
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
www.mszsora.com | ||
www.creativeavenueinc.com |
CNAME
creativeavenueinc.com
|
34.102.136.180 |
www.worsall.com | 198.54.117.210 | |
www.barefootrestaurantil.com |
CNAME
barefootrestaurantil.com
|
34.102.136.180 |
www.sbratchik.ru |
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.worsall.com/htqs/?Wz=eTBOdLg8O8WfPsi/aMZVIrp4p0K8YKCelaR89QpKBJlnv2Ndq6qGVsr5f6/0LBJihsjVfF3N&vB=chrxU | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.barefootrestaurantil.com/htqs/?Wz=ICAmXkpg8yDUPQRUvyQOYOmftFyS4aTUj531dBtgwJBSVqZ9sI20XgQnE7PS7zFEssN/PDGq&vB=chrxU | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.creativeavenueinc.com/htqs/?Wz=ffnFIYSrRTpd7MPzyCwe2L1JbBI6t6tjdC5GdL2BJumhS+yYJbcINhXRfRXQoojP5e7kf28Y&vB=chrxU |
request | GET http://www.worsall.com/htqs/?Wz=eTBOdLg8O8WfPsi/aMZVIrp4p0K8YKCelaR89QpKBJlnv2Ndq6qGVsr5f6/0LBJihsjVfF3N&vB=chrxU |
request | GET http://www.barefootrestaurantil.com/htqs/?Wz=ICAmXkpg8yDUPQRUvyQOYOmftFyS4aTUj531dBtgwJBSVqZ9sI20XgQnE7PS7zFEssN/PDGq&vB=chrxU |
request | GET http://www.creativeavenueinc.com/htqs/?Wz=ffnFIYSrRTpd7MPzyCwe2L1JbBI6t6tjdC5GdL2BJumhS+yYJbcINhXRfRXQoojP5e7kf28Y&vB=chrxU |
domain | www.sbratchik.ru | description | Russian Federation domain TLD |
file | C:\Users\test22\AppData\Local\Temp\wmweglq.exe |
MicroWorld-eScan | Trojan.Garf.Gen.7 |
FireEye | Generic.mg.724ad0f724d2aba1 |
ALYac | Trojan.NSISX.Spy.Gen.24 |
CrowdStrike | win/malicious_confidence_100% (D) |
Arcabit | Trojan.Garf.Gen.7 [many] |
Symantec | Packed.NSISPacker!g14 |
Elastic | malicious (high confidence) |
Cynet | Malicious (score: 100) |
APEX | Malicious |
Kaspersky | UDS:DangerousObject.Multi.Generic |
BitDefender | Trojan.Garf.Gen.7 |
NANO-Antivirus | Riskware.Nsis.Adw.dqabkg |
Emsisoft | Trojan.Garf.Gen.7 (B) |
VIPRE | Trojan.Garf.Gen.7 |
McAfee-GW-Edition | BehavesLike.Win32.Generic.fc |
Trapmine | suspicious.low.ml.score |
Sophos | Generic ML PUA (PUA) |
SentinelOne | Static AI - Suspicious PE |
Microsoft | Trojan:Win32/Formbook!MTB |
ZoneAlarm | UDS:DangerousObject.Multi.Generic |
GData | Trojan.NSISX.Spy.Gen.24 |
Detected | |
AhnLab-V3 | Trojan/Win.NSISInject.R496549 |
MAX | malware (ai score=84) |
VBA32 | BScope.Trojan.Wacatac |
Ikarus | Trojan-Spy.FormBook |
Fortinet | W32/Injector.ESWG!tr |
DeepInstinct | MALICIOUS |