Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | May 18, 2023, 10:43 a.m. | May 18, 2023, 10:45 a.m. |
-
vbc.exe "C:\Users\test22\AppData\Local\Temp\vbc.exe"
2556
IP Address | Status | Action |
---|---|---|
104.21.34.8 | Active | Moloch |
137.220.202.242 | Active | Moloch |
154.94.121.119 | Active | Moloch |
164.124.101.2 | Active | Moloch |
185.27.134.115 | Active | Moloch |
208.113.186.56 | Active | Moloch |
45.130.230.191 | Active | Moloch |
45.33.6.223 | Active | Moloch |
5.157.87.204 | Active | Moloch |
54.196.16.164 | Active | Moloch |
67.223.117.160 | Active | Moloch |
Suricata Alerts
Suricata TLS
No Suricata TLS
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.smartinnoventions.com/f619/?E9W=Ek2xhbXtY1qXzB2JvbkcFvKbSmJm4K+Uyb5xsLYZ3zgsIlX7EFjcw6TuiLcQZ5KUivhxYJn0P8EizsHxKHQ+wy4OSt0bovGghjBDZDE=&NC=ptGp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.intake-tree.com/f619/?E9W=YCaZye8ndW5O5ejCJ7uN2558Y+97WERyr3klZ+XCKIlwv4gr+zruhmNXWBgIbED6mtP3DBYvR0gpojWOjcOh+ihVnCiMcphzPiGO29A=&NC=ptGp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.towfire.life/f619/?E9W=Ehbg4LlyVMHP0pAFmIQxhDDkp6Kxs477sF6nDv0EaT5K8/1GH5wf1bgzqSKTUaDZXTnW9d28cNYQDMZcc5x0F8aQqyCdRYlsL10lLoU=&NC=ptGp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.gospelfy.online/f619/?E9W=mqENKO6x6u0B1RhcdIeKlgDLrDi38FKwdcw4276gfXsD1t5r0KVruS6mnpdZvtzm+Q0xGOUHk2EA1TA3TL1CSm4H2R6TK8LtJrZ83YI=&NC=ptGp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.queenkidul.com/f619/?E9W=flPn1CpczsmcmsloYAj+WZ9tyIXCLn2BUp15WA9gR+pRAl39PMpr22E4uA5K3fGksCy6GKGUT/KR36S7pADHdFopIcR3oqkCWwUH3Bw=&NC=ptGp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.sockmomma.com/f619/?E9W=2xrbRaVqfFZAqlIaVxxROj1er0vApHth0WR1aJHeUhlKoHhTuPzXEzX44r40ys20rE4Ka7hzk9c+zV+d/czmBtVLQF0HWkNVVexiFz0=&NC=ptGp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.stephenwang.photography/f619/?E9W=u5f4p4qz7o/fTtDm3nSz6hiFO4aCCN2AsW/usgJw6zJdWxar6/CI5CJVoaMo1PtwYoo0+7BD2Z2qbjCMw+JlDyQ8u/oV4aU03sHkcSA=&NC=ptGp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.skillfulp10.buzz/f619/?E9W=35x6vbxblib5MVXL66MiYOFyCwyiW+WpCMCOaRW/LabtpXpMR316Gm+YR9yWJR7EH7/o0i+7abS9fGbf51xT5oPd3YLLmnWOCyaGRj8=&NC=ptGp | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.28588v.com/f619/?E9W=G3I5ds8dOpaKd+DH1ake2pRuUN+UMAJZaHOz+8NtztMbt4Q0fuIWaSpOJ5XO92YffYK2mOkzi8XK+GtmVritvfJB+FClpV7RO2AgtZU=&NC=ptGp |
request | POST http://www.smartinnoventions.com/f619/ |
request | GET http://www.smartinnoventions.com/f619/?E9W=Ek2xhbXtY1qXzB2JvbkcFvKbSmJm4K+Uyb5xsLYZ3zgsIlX7EFjcw6TuiLcQZ5KUivhxYJn0P8EizsHxKHQ+wy4OSt0bovGghjBDZDE=&NC=ptGp |
request | GET http://www.sqlite.org/2016/sqlite-dll-win32-x86-3100000.zip |
request | POST http://www.intake-tree.com/f619/ |
request | GET http://www.intake-tree.com/f619/?E9W=YCaZye8ndW5O5ejCJ7uN2558Y+97WERyr3klZ+XCKIlwv4gr+zruhmNXWBgIbED6mtP3DBYvR0gpojWOjcOh+ihVnCiMcphzPiGO29A=&NC=ptGp |
request | POST http://www.towfire.life/f619/ |
request | GET http://www.towfire.life/f619/?E9W=Ehbg4LlyVMHP0pAFmIQxhDDkp6Kxs477sF6nDv0EaT5K8/1GH5wf1bgzqSKTUaDZXTnW9d28cNYQDMZcc5x0F8aQqyCdRYlsL10lLoU=&NC=ptGp |
request | POST http://www.gospelfy.online/f619/ |
request | GET http://www.gospelfy.online/f619/?E9W=mqENKO6x6u0B1RhcdIeKlgDLrDi38FKwdcw4276gfXsD1t5r0KVruS6mnpdZvtzm+Q0xGOUHk2EA1TA3TL1CSm4H2R6TK8LtJrZ83YI=&NC=ptGp |
request | POST http://www.queenkidul.com/f619/ |
request | GET http://www.queenkidul.com/f619/?E9W=flPn1CpczsmcmsloYAj+WZ9tyIXCLn2BUp15WA9gR+pRAl39PMpr22E4uA5K3fGksCy6GKGUT/KR36S7pADHdFopIcR3oqkCWwUH3Bw=&NC=ptGp |
request | POST http://www.sockmomma.com/f619/ |
request | GET http://www.sockmomma.com/f619/?E9W=2xrbRaVqfFZAqlIaVxxROj1er0vApHth0WR1aJHeUhlKoHhTuPzXEzX44r40ys20rE4Ka7hzk9c+zV+d/czmBtVLQF0HWkNVVexiFz0=&NC=ptGp |
request | POST http://www.stephenwang.photography/f619/ |
request | GET http://www.stephenwang.photography/f619/?E9W=u5f4p4qz7o/fTtDm3nSz6hiFO4aCCN2AsW/usgJw6zJdWxar6/CI5CJVoaMo1PtwYoo0+7BD2Z2qbjCMw+JlDyQ8u/oV4aU03sHkcSA=&NC=ptGp |
request | POST http://www.skillfulp10.buzz/f619/ |
request | GET http://www.skillfulp10.buzz/f619/?E9W=35x6vbxblib5MVXL66MiYOFyCwyiW+WpCMCOaRW/LabtpXpMR316Gm+YR9yWJR7EH7/o0i+7abS9fGbf51xT5oPd3YLLmnWOCyaGRj8=&NC=ptGp |
request | POST http://www.28588v.com/f619/ |
request | GET http://www.28588v.com/f619/?E9W=G3I5ds8dOpaKd+DH1ake2pRuUN+UMAJZaHOz+8NtztMbt4Q0fuIWaSpOJ5XO92YffYK2mOkzi8XK+GtmVritvfJB+FClpV7RO2AgtZU=&NC=ptGp |
request | POST http://www.smartinnoventions.com/f619/ |
request | POST http://www.intake-tree.com/f619/ |
request | POST http://www.towfire.life/f619/ |
request | POST http://www.gospelfy.online/f619/ |
request | POST http://www.queenkidul.com/f619/ |
request | POST http://www.sockmomma.com/f619/ |
request | POST http://www.stephenwang.photography/f619/ |
request | POST http://www.skillfulp10.buzz/f619/ |
request | POST http://www.28588v.com/f619/ |
section | {u'size_of_data': u'0x0002d600', u'virtual_address': u'0x00001000', u'entropy': 7.99643845067576, u'name': u'.text', u'virtual_size': u'0x0002d4e4'} | entropy | 7.99643845068 | description | A section with a high entropy has been found | |||||||||
entropy | 1.0 | description | Overall entropy of this PE file is high |