Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | May 26, 2023, 9:13 a.m. | May 26, 2023, 9:29 a.m. |
-
-
-
-
f4460186.exe C:\Users\test22\AppData\Local\Temp\IXP002.TMP\f4460186.exe
2192 -
g0733861.exe C:\Users\test22\AppData\Local\Temp\IXP002.TMP\g0733861.exe
2708
-
-
-
-
schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN metado.exe /TR "C:\Users\test22\AppData\Local\Temp\a9e2a16078\metado.exe" /F
3016 -
cmd.exe "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "metado.exe" /P "test22:N"&&CACLS "metado.exe" /P "test22:R" /E&&echo Y|CACLS "..\a9e2a16078" /P "test22:N"&&CACLS "..\a9e2a16078" /P "test22:R" /E&&Exit
2076-
cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2204 -
cacls.exe CACLS "metado.exe" /P "test22:N"
508 -
cacls.exe CACLS "metado.exe" /P "test22:R" /E
2368 -
cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2456 -
cacls.exe CACLS "..\a9e2a16078" /P "test22:N"
2652 -
cacls.exe CACLS "..\a9e2a16078" /P "test22:R" /E
2720
-
-
-
-
-
f2875527.exe C:\Users\test22\AppData\Local\Temp\IXP002.TMP\f2875527.exe
3032 -
g1501587.exe C:\Users\test22\AppData\Local\Temp\IXP002.TMP\g1501587.exe
1836
-
-
h6702152.exe C:\Users\test22\AppData\Local\Temp\IXP001.TMP\h6702152.exe
2280
-
-
i6381953.exe C:\Users\test22\AppData\Local\Temp\IXP000.TMP\i6381953.exe
1688
-
-
-
-
-
k5867848.exe C:\Users\test22\AppData\Local\Temp\IXP005.TMP\k5867848.exe
2704 -
l0217723.exe C:\Users\test22\AppData\Local\Temp\IXP005.TMP\l0217723.exe
2784
-
-
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\006700e5a2ab05\clip64.dll, Main
1972
-
-
-
-
i2855260.exe C:\Users\test22\AppData\Local\Temp\IXP000.TMP\i2855260.exe
2932
-
-
explorer.exe C:\Windows\Explorer.EXE
1236
Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | wextract.pdb |
file | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
file | C:\Program Files\Mozilla Firefox\firefox.exe |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
resource name | AVI |
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://77.91.68.62/wings/game/index.php | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://77.91.68.62/DSC01491/foto495.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://77.91.68.62/DSC01491/fotocr05.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://77.91.68.62/wings/game/Plugins/cred64.dll | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://77.91.68.62/wings/game/Plugins/clip64.dll |
request | POST http://77.91.68.62/wings/game/index.php |
request | GET http://77.91.68.62/DSC01491/foto495.exe |
request | GET http://77.91.68.62/DSC01491/fotocr05.exe |
request | GET http://77.91.68.62/wings/game/Plugins/cred64.dll |
request | GET http://77.91.68.62/wings/game/Plugins/clip64.dll |
request | POST http://77.91.68.62/wings/game/index.php |
description | metado.exe tried to sleep 142 seconds, actually delayed analysis time by 142 seconds |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extension Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State |
file | C:\Users\test22\AppData\Local\Temp\IXP002.TMP\g1501587.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP005.TMP\l0217723.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP004.TMP\y3504266.exe |
file | C:\Users\test22\AppData\Local\Temp\1000001051\foto495.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP005.TMP\k5867848.exe |
file | C:\Users\test22\AppData\Roaming\006700e5a2ab05\cred64.dll |
file | C:\Users\test22\AppData\Local\Temp\IXP001.TMP\h6702152.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP003.TMP\n5288998.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP001.TMP\x8557428.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP000.TMP\i6381953.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP001.TMP\x3068393.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP003.TMP\y5687732.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP000.TMP\i2855260.exe |
file | C:\Users\test22\AppData\Local\Temp\1000003051\fotocr05.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP000.TMP\x5337802.exe |
file | C:\Users\test22\AppData\Roaming\006700e5a2ab05\clip64.dll |
file | C:\Users\test22\AppData\Local\Temp\IXP002.TMP\g0733861.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP004.TMP\m6301749.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP002.TMP\f4460186.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP001.TMP\h3936292.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP000.TMP\x2745298.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP002.TMP\f2875527.exe |
cmdline | SCHTASKS /Create /SC MINUTE /MO 1 /TN metado.exe /TR "C:\Users\test22\AppData\Local\Temp\a9e2a16078\metado.exe" /F |
cmdline | C:\Windows\system32\cmd.exe /S /D /c" echo Y" |
cmdline | "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN metado.exe /TR "C:\Users\test22\AppData\Local\Temp\a9e2a16078\metado.exe" /F |
cmdline | "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "metado.exe" /P "test22:N"&&CACLS "metado.exe" /P "test22:R" /E&&echo Y|CACLS "..\a9e2a16078" /P "test22:N"&&CACLS "..\a9e2a16078" /P "test22:R" /E&&Exit |
file | C:\Users\test22\AppData\Local\Temp\a9e2a16078\metado.exe |
file | C:\Users\test22\AppData\Local\Temp\1000001051\foto495.exe |
file | C:\Users\test22\AppData\Local\Temp\1000003051\fotocr05.exe |
file | C:\Users\test22\AppData\Roaming\006700e5a2ab05\clip64.dll |
file | C:\Users\test22\AppData\Local\Temp\1000003051\fotocr05.exe |
file | C:\Users\test22\AppData\Local\Temp\a9e2a16078\metado.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP004.TMP\m6301749.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP003.TMP\y5687732.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP004.TMP\y3504266.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP005.TMP\l0217723.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP005.TMP\k5867848.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP003.TMP\n5288998.exe |
file | C:\Users\test22\AppData\Local\Temp\1000001051\foto495.exe |