Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | May 17, 2023, 9:31 a.m. | May 17, 2023, 9:33 a.m. |
-
-
-
schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\test22\AppData\Local\Temp\6fd2e6071d\oneetx.exe" /F
2380 -
cmd.exe "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "oneetx.exe" /P "test22:N"&&CACLS "oneetx.exe" /P "test22:R" /E&&echo Y|CACLS "..\6fd2e6071d" /P "test22:N"&&CACLS "..\6fd2e6071d" /P "test22:R" /E&&Exit
2424-
cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
1628 -
cacls.exe CACLS "oneetx.exe" /P "test22:N"
2524 -
cacls.exe CACLS "oneetx.exe" /P "test22:R" /E
508 -
cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
1968 -
cacls.exe CACLS "..\6fd2e6071d" /P "test22:N"
2548 -
cacls.exe CACLS "..\6fd2e6071d" /P "test22:R" /E
2660
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\27d75989acd3e0\cred64.dll, Main
996-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\27d75989acd3e0\cred64.dll, Main
2636
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\27d75989acd3e0\clip64.dll, Main
2484
-
-
-
explorer.exe C:\Windows\Explorer.EXE
1236
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49173 -> 95.214.26.53:80 | 2027700 | ET MALWARE Amadey CnC Check-In | Malware Command and Control Activity Detected |
TCP 192.168.56.102:49177 -> 95.214.26.53:80 | 2027250 | ET INFO Dotted Quad Host DLL Request | Potentially Bad Traffic |
TCP 95.214.26.53:80 -> 192.168.56.102:49177 | 2018959 | ET POLICY PE EXE or DLL Windows file download HTTP | Potential Corporate Privacy Violation |
TCP 95.214.26.53:80 -> 192.168.56.102:49177 | 2016538 | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download | Potentially Bad Traffic |
TCP 192.168.56.102:49177 -> 95.214.26.53:80 | 2027250 | ET INFO Dotted Quad Host DLL Request | Potentially Bad Traffic |
Suricata TLS
No Suricata TLS
pdb_path | D:\Mktmp\Amadey\Release\Amadey.pdb |
file | C:\Program Files\Mozilla Firefox\firefox.exe |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\firefox.exe |
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://95.214.26.53/J84hHFuefh2/index.php?scr=1 | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://95.214.26.53/J84hHFuefh2/index.php | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://95.214.26.53/J84hHFuefh2/Plugins/cred64.dll | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://95.214.26.53/J84hHFuefh2/Plugins/clip64.dll |
request | POST http://95.214.26.53/J84hHFuefh2/index.php?scr=1 |
request | POST http://95.214.26.53/J84hHFuefh2/index.php |
request | GET http://95.214.26.53/J84hHFuefh2/Plugins/cred64.dll |
request | GET http://95.214.26.53/J84hHFuefh2/Plugins/clip64.dll |
request | POST http://95.214.26.53/J84hHFuefh2/index.php?scr=1 |
request | POST http://95.214.26.53/J84hHFuefh2/index.php |
description | oneetx.exe tried to sleep 141 seconds, actually delayed analysis time by 141 seconds |
file | C:\Users\test22\AppData\Roaming\27d75989acd3e0\clip64.dll |
file | C:\Users\test22\AppData\Roaming\27d75989acd3e0\cred64.dll |
cmdline | "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "oneetx.exe" /P "test22:N"&&CACLS "oneetx.exe" /P "test22:R" /E&&echo Y|CACLS "..\6fd2e6071d" /P "test22:N"&&CACLS "..\6fd2e6071d" /P "test22:R" /E&&Exit |
cmdline | C:\Windows\system32\cmd.exe /S /D /c" echo Y" |
cmdline | SCHTASKS /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\test22\AppData\Local\Temp\6fd2e6071d\oneetx.exe" /F |
cmdline | "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\test22\AppData\Local\Temp\6fd2e6071d\oneetx.exe" /F |
file | C:\Users\test22\AppData\Local\Temp\6fd2e6071d\oneetx.exe |
file | C:\Users\test22\AppData\Local\Temp\6fd2e6071d\oneetx.exe |
file | C:\Users\test22\AppData\Roaming\27d75989acd3e0\clip64.dll |