Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | May 11, 2023, 6:35 p.m. | May 11, 2023, 6:39 p.m. |
-
tst2.exe "C:\Users\test22\AppData\Local\Temp\tst2.exe"
2548
Name | Response | Post-Analysis Lookup |
---|---|---|
xmr.2miners.com | 162.19.139.184 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49164 -> 162.19.139.184:2222 | 2024792 | ET POLICY Cryptocurrency Miner Checkin | Potential Corporate Privacy Violation |
UDP 192.168.56.101:59002 -> 164.124.101.2:53 | 2040353 | ET INFO Observed DNS Query to Cryptocurrency Mining Pool Domain (xmr .2miners .com) | Crypto Currency Mining Activity Detected |
Suricata TLS
No Suricata TLS
section | {u'size_of_data': u'0x001fb800', u'virtual_address': u'0x0000c000', u'entropy': 7.966346741668619, u'name': u'.data', u'virtual_size': u'0x001fb720'} | entropy | 7.96634674167 | description | A section with a high entropy has been found | |||||||||
entropy | 0.973154362416 | description | Overall entropy of this PE file is high |