Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | May 18, 2023, 9:32 a.m. | May 18, 2023, 9:55 a.m. |
-
WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Office15\WINWORD.EXE" C:\Users\test22\AppData\Local\Temp\jjjj%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23kk.doc
1984
IP Address | Status | Action |
---|---|---|
104.21.34.8 | Active | Moloch |
137.220.225.73 | Active | Moloch |
154.94.121.119 | Active | Moloch |
164.124.101.2 | Active | Moloch |
185.27.134.115 | Active | Moloch |
195.201.147.116 | Active | Moloch |
208.113.186.56 | Active | Moloch |
45.130.230.191 | Active | Moloch |
45.33.6.223 | Active | Moloch |
5.157.87.204 | Active | Moloch |
54.196.16.164 | Active | Moloch |
67.223.117.160 | Active | Moloch |
Suricata Alerts
Suricata TLS
No Suricata TLS
suspicious_features | Connection to IP address | suspicious_request | GET http://195.201.147.116/433/vbc.exe | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.smartinnoventions.com/f619/?O7pS=Ek2xhbXtY1qXzB2JvbkcFvKbSmJm4K+Uyb5xsLYZ3zgsIlX7EFjcw6TuiLcQZ5KUivhxYJn0P8EizsHxKHQ+wy4OSt0bovGghjBDZDE=&CP-m=8c92fQNKIzrCDRX | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.intake-tree.com/f619/?O7pS=YCaZye8ndW5O5ejCJ7uN2558Y+97WERyr3klZ+XCKIlwv4gr+zruhmNXWBgIbED6mtP3DBYvR0gpojWOjcOh+ihVnCiMcphzPiGO29A=&CP-m=8c92fQNKIzrCDRX | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.towfire.life/f619/?O7pS=Ehbg4LlyVMHP0pAFmIQxhDDkp6Kxs477sF6nDv0EaT5K8/1GH5wf1bgzqSKTUaDZXTnW9d28cNYQDMZcc5x0F8aQqyCdRYlsL10lLoU=&CP-m=8c92fQNKIzrCDRX | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.gospelfy.online/f619/?O7pS=mqENKO6x6u0B1RhcdIeKlgDLrDi38FKwdcw4276gfXsD1t5r0KVruS6mnpdZvtzm+Q0xGOUHk2EA1TA3TL1CSm4H2R6TK8LtJrZ83YI=&CP-m=8c92fQNKIzrCDRX | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.queenkidul.com/f619/?O7pS=flPn1CpczsmcmsloYAj+WZ9tyIXCLn2BUp15WA9gR+pRAl39PMpr22E4uA5K3fGksCy6GKGUT/KR36S7pADHdFopIcR3oqkCWwUH3Bw=&CP-m=8c92fQNKIzrCDRX | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.sockmomma.com/f619/?O7pS=2xrbRaVqfFZAqlIaVxxROj1er0vApHth0WR1aJHeUhlKoHhTuPzXEzX44r40ys20rE4Ka7hzk9c+zV+d/czmBtVLQF0HWkNVVexiFz0=&CP-m=8c92fQNKIzrCDRX | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.stephenwang.photography/f619/?O7pS=u5f4p4qz7o/fTtDm3nSz6hiFO4aCCN2AsW/usgJw6zJdWxar6/CI5CJVoaMo1PtwYoo0+7BD2Z2qbjCMw+JlDyQ8u/oV4aU03sHkcSA=&CP-m=8c92fQNKIzrCDRX | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.skillfulp10.buzz/f619/?O7pS=35x6vbxblib5MVXL66MiYOFyCwyiW+WpCMCOaRW/LabtpXpMR316Gm+YR9yWJR7EH7/o0i+7abS9fGbf51xT5oPd3YLLmnWOCyaGRj8=&CP-m=8c92fQNKIzrCDRX | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.28588v.com/f619/?O7pS=G3I5ds8dOpaKd+DH1ake2pRuUN+UMAJZaHOz+8NtztMbt4Q0fuIWaSpOJ5XO92YffYK2mOkzi8XK+GtmVritvfJB+FClpV7RO2AgtZU=&CP-m=8c92fQNKIzrCDRX |
request | GET http://195.201.147.116/433/vbc.exe |
request | POST http://www.smartinnoventions.com/f619/ |
request | GET http://www.smartinnoventions.com/f619/?O7pS=Ek2xhbXtY1qXzB2JvbkcFvKbSmJm4K+Uyb5xsLYZ3zgsIlX7EFjcw6TuiLcQZ5KUivhxYJn0P8EizsHxKHQ+wy4OSt0bovGghjBDZDE=&CP-m=8c92fQNKIzrCDRX |
request | GET http://www.sqlite.org/2020/sqlite-dll-win32-x86-3320000.zip |
request | POST http://www.intake-tree.com/f619/ |
request | GET http://www.intake-tree.com/f619/?O7pS=YCaZye8ndW5O5ejCJ7uN2558Y+97WERyr3klZ+XCKIlwv4gr+zruhmNXWBgIbED6mtP3DBYvR0gpojWOjcOh+ihVnCiMcphzPiGO29A=&CP-m=8c92fQNKIzrCDRX |
request | POST http://www.towfire.life/f619/ |
request | GET http://www.towfire.life/f619/?O7pS=Ehbg4LlyVMHP0pAFmIQxhDDkp6Kxs477sF6nDv0EaT5K8/1GH5wf1bgzqSKTUaDZXTnW9d28cNYQDMZcc5x0F8aQqyCdRYlsL10lLoU=&CP-m=8c92fQNKIzrCDRX |
request | POST http://www.gospelfy.online/f619/ |
request | GET http://www.gospelfy.online/f619/?O7pS=mqENKO6x6u0B1RhcdIeKlgDLrDi38FKwdcw4276gfXsD1t5r0KVruS6mnpdZvtzm+Q0xGOUHk2EA1TA3TL1CSm4H2R6TK8LtJrZ83YI=&CP-m=8c92fQNKIzrCDRX |
request | POST http://www.queenkidul.com/f619/ |
request | GET http://www.queenkidul.com/f619/?O7pS=flPn1CpczsmcmsloYAj+WZ9tyIXCLn2BUp15WA9gR+pRAl39PMpr22E4uA5K3fGksCy6GKGUT/KR36S7pADHdFopIcR3oqkCWwUH3Bw=&CP-m=8c92fQNKIzrCDRX |
request | POST http://www.sockmomma.com/f619/ |
request | GET http://www.sockmomma.com/f619/?O7pS=2xrbRaVqfFZAqlIaVxxROj1er0vApHth0WR1aJHeUhlKoHhTuPzXEzX44r40ys20rE4Ka7hzk9c+zV+d/czmBtVLQF0HWkNVVexiFz0=&CP-m=8c92fQNKIzrCDRX |
request | POST http://www.stephenwang.photography/f619/ |
request | GET http://www.stephenwang.photography/f619/?O7pS=u5f4p4qz7o/fTtDm3nSz6hiFO4aCCN2AsW/usgJw6zJdWxar6/CI5CJVoaMo1PtwYoo0+7BD2Z2qbjCMw+JlDyQ8u/oV4aU03sHkcSA=&CP-m=8c92fQNKIzrCDRX |
request | POST http://www.skillfulp10.buzz/f619/ |
request | GET http://www.skillfulp10.buzz/f619/?O7pS=35x6vbxblib5MVXL66MiYOFyCwyiW+WpCMCOaRW/LabtpXpMR316Gm+YR9yWJR7EH7/o0i+7abS9fGbf51xT5oPd3YLLmnWOCyaGRj8=&CP-m=8c92fQNKIzrCDRX |
request | POST http://www.28588v.com/f619/ |
request | GET http://www.28588v.com/f619/?O7pS=G3I5ds8dOpaKd+DH1ake2pRuUN+UMAJZaHOz+8NtztMbt4Q0fuIWaSpOJ5XO92YffYK2mOkzi8XK+GtmVritvfJB+FClpV7RO2AgtZU=&CP-m=8c92fQNKIzrCDRX |
request | POST http://www.smartinnoventions.com/f619/ |
request | POST http://www.intake-tree.com/f619/ |
request | POST http://www.towfire.life/f619/ |
request | POST http://www.gospelfy.online/f619/ |
request | POST http://www.queenkidul.com/f619/ |
request | POST http://www.sockmomma.com/f619/ |
request | POST http://www.stephenwang.photography/f619/ |
request | POST http://www.skillfulp10.buzz/f619/ |
request | POST http://www.28588v.com/f619/ |
file | C:\Users\test22\AppData\Local\Temp\~$jj#############################kk.doc |
filetype_details | Rich Text Format data, version 1, unknown character set | filename | jjjj%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23%23kk.doc |
host | 195.201.147.116 |