Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | May 24, 2023, 6:49 p.m. | May 24, 2023, 6:51 p.m. |
-
po-docs-may24.exe "C:\Users\test22\AppData\Local\Temp\po-docs-may24.exe"
3032
Name | Response | Post-Analysis Lookup |
---|---|---|
cacerts.digicert.com |
CNAME
fp2e7a.wpc.phicdn.net
|
152.195.38.76 |
onedrive.live.com |
CNAME
l-0004.l-msedge.net
CNAME
web.fe.1drv.com
|
13.107.42.13 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49163 -> 13.107.42.13:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.102:49163 13.107.42.13:443 |
C=US, O=Microsoft Corporation, CN=Microsoft Azure TLS Issuing CA 05 | C=US, ST=WA, L=Redmond, O=Microsoft Corporation, CN=onedrive.com | 4e:11:98:32:9d:ab:e8:3b:be:4e:e9:05:86:88:8d:67:16:9b:c0:9b |
section | CODE |
section | DATA |
section | BSS |
packer | BobSoft Mini Delphi -> BoB / BobSoft |
request | GET http://onedrive.live.com/download?cid=4FE79169F14FE906&resid=4FE79169F14FE906%21197&authkey=AJx2lN6RUxuMay0 |
request | GET http://cacerts.digicert.com/DigiCertGlobalRootG2.crt |
section | {u'size_of_data': u'0x0003d000', u'virtual_address': u'0x00079000', u'entropy': 7.102832232599013, u'name': u'DATA', u'virtual_size': u'0x0003ce98'} | entropy | 7.1028322326 | description | A section with a high entropy has been found | |||||||||
entropy | 0.302917442582 | description | Overall entropy of this PE file is high |
Bkav | W32.AIDetectMalware |
Elastic | malicious (high confidence) |
FireEye | Generic.mg.14d2501921d7cf94 |
Cybereason | malicious.bf99b8 |
BitDefenderTheta | Gen:NN.ZelphiCO.36196.YG0@aasFMLki |
Symantec | Downloader |
ESET-NOD32 | Win32/TrojanDownloader.ModiLoader.C |
APEX | Malicious |
Cynet | Malicious (score: 99) |
Kaspersky | VHO:Backdoor.Win32.Androm.gen |
Avast | Win32:Evo-gen [Trj] |
F-Secure | Heuristic.HEUR/AGEN.1331058 |
Sophos | Generic ML PUA (PUA) |
Avira | HEUR/AGEN.1331058 |
ZoneAlarm | VHO:Backdoor.Win32.Androm.gen |
Detected | |
Cylance | unsafe |
Ikarus | Trojan.Inject |
MaxSecure | Trojan.Malware.300983.susgen |
Fortinet | W32/Formbook.AA!tr |
AVG | Win32:Evo-gen [Trj] |
DeepInstinct | MALICIOUS |
CrowdStrike | win/malicious_confidence_90% (D) |