Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | May 30, 2023, 1:37 p.m. | May 30, 2023, 1:39 p.m. |
-
-
-
-
o3829852.exe C:\Users\test22\AppData\Local\Temp\IXP002.TMP\o3829852.exe
2252 -
p7220078.exe C:\Users\test22\AppData\Local\Temp\IXP002.TMP\p7220078.exe
2340
-
-
r2486584.exe C:\Users\test22\AppData\Local\Temp\IXP001.TMP\r2486584.exe
1196
-
-
-
-
-
-
schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN legends.exe /TR "C:\Users\test22\AppData\Local\Temp\41bde21dc7\legends.exe" /F
2164 -
cmd.exe "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "legends.exe" /P "test22:N"&&CACLS "legends.exe" /P "test22:R" /E&&echo Y|CACLS "..\41bde21dc7" /P "test22:N"&&CACLS "..\41bde21dc7" /P "test22:R" /E&&Exit
1588-
cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2396 -
cacls.exe CACLS "legends.exe" /P "test22:N"
1164 -
cacls.exe CACLS "legends.exe" /P "test22:R" /E
1728 -
cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2988 -
cacls.exe CACLS "..\41bde21dc7" /P "test22:N"
996 -
cacls.exe CACLS "..\41bde21dc7" /P "test22:R" /E
2716
-
-
-
RegSvcs.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"
1944
-
-
-
RegSvcs.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"
2084
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\a091ec0a6e2227\clip64.dll, Main
1376
-
-
-
-
-
-
explorer.exe C:\Windows\Explorer.EXE
1236
Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | wextract.pdb |
file | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
file | C:\Program Files\Mozilla Firefox\firefox.exe |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
resource name | AVI |
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://95.214.27.98/cronus/index.php | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://95.214.27.98/lend/kds7uq5kknv.exe | ||||||
suspicious_features | POST method with no referer header, Connection to IP address | suspicious_request | POST http://185.99.133.246/c2sock | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://95.214.27.98/cronus/Plugins/cred64.dll | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://95.214.27.98/cronus/Plugins/clip64.dll |
request | POST http://95.214.27.98/cronus/index.php |
request | GET http://95.214.27.98/lend/kds7uq5kknv.exe |
request | POST http://185.99.133.246/c2sock |
request | GET http://95.214.27.98/cronus/Plugins/cred64.dll |
request | GET http://95.214.27.98/cronus/Plugins/clip64.dll |
request | POST http://95.214.27.98/cronus/index.php |
request | POST http://185.99.133.246/c2sock |
description | legends.exe tried to sleep 150 seconds, actually delayed analysis time by 150 seconds |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cphhlgmgameodnhkjdmkpanlelnlohao |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kncchdigobghenbbaddojjnnaogfppfj |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cnmamaachppnkjgnildpdmkaakejnhae |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bfnaelmomeimhlpmgjnjophhpkkoljpa |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nhnkbkgjikgcigadomkphalanndcapjk |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\klnaejjgbibmhlephnhpmaofohgkpgkd |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ffnbelfdoeiohenkjibnmadjiehjhajb |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\oeljdldpnmdbchonielidgobddffflal |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jojhfeoedkpkglbfimdfabpdfjaoolaf |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ijmpgkjfkbfhoebgogflfebnmejmfbml |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\imloifkgjagghnncjkhggdhalmcnfklk |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fhmfendgdocmcbmfikdcogofphimnkno |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkbihfbeogaeaoehlefnkodbefgpgknn |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nlbmnnijcnlegkjjpcfjclmcfggfefdm |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\blnieiiffboillknjnepogjhkgnoapac |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mnfifefkajgofkcjkemidiaecocnkjeh |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hnfanknocfeofbddgcijnmhnfnkdnaad |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fnjhmkhhmkbjkkabndcnnogagogbneec |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fhbohimaelbohpjbbldcngcnapndodjp |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\amkmjjmmflddogmhpjloimipbofnfjih |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fihkakfobkmkjojpchpfgcmhfjnmnfpi |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aeachknmefphepccionboohckonoeemg |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data For Account |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bhghoamapcdpbohphigoooaddinpkbai |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkddgncdjgjfcddamfgcmfnlhccnimig |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lodccjjbdhfakaekdiahmedfbieldgik |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jbdaocneiiinmjbjlgalhcelgbejmnid |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ilgcnhelpchnceeipipijaljkblbcobl |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hcflpincpppdclinealmandijcmnkbgn |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kkpllkodjeloidieedojogacfhpaihoh |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dmkamcknogkgcdfhhbddcghachkejeap |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lkcjlnjfpbikmcmbachjpdbijejflpcm |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gaedmjdfmmahhbjefcbgaolhhanlaolb |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nknhiehlklippafakaeklbeglecifhad |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aiifbnbfobpmeekipheeijimdpnlpgpp |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\flpiciilemghbmfalicajoolhkkenfel |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ppbibelpcjmhbdihakflkdcoccbgbkpo |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ibnejdfjmmkpcnlpebklmnkoeoihofec |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hpglfhgfnhbgpjdenjgmdgoeiappafln |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cjelfplplebdjjenllpjcblmjkfcffne |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nanjmdknhkinifnkgdcggcfnhdaammmj |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\afbcbjpbpfadlkmhmclhkeeodmamcflc |
file | C:\Users\test22\AppData\Roaming\a091ec0a6e2227\clip64.dll |
file | C:\Users\test22\AppData\Local\Temp\IXP001.TMP\r2486584.exe |
file | C:\Users\test22\AppData\Local\Temp\1000028001\kds7uq5kknv.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP002.TMP\o3829852.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP002.TMP\p7220078.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP001.TMP\z4553979.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP000.TMP\z1392128.exe |
file | C:\Users\test22\AppData\Roaming\a091ec0a6e2227\cred64.dll |
file | C:\Users\test22\AppData\Local\Temp\IXP000.TMP\s8328851.exe |
file | C:\Users\test22\AppData\Local\Temp\1000029001\kds7uq5kknv.exe |
cmdline | C:\Windows\system32\cmd.exe /S /D /c" echo Y" |
cmdline | "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "legends.exe" /P "test22:N"&&CACLS "legends.exe" /P "test22:R" /E&&echo Y|CACLS "..\41bde21dc7" /P "test22:N"&&CACLS "..\41bde21dc7" /P "test22:R" /E&&Exit |
cmdline | SCHTASKS /Create /SC MINUTE /MO 1 /TN legends.exe /TR "C:\Users\test22\AppData\Local\Temp\41bde21dc7\legends.exe" /F |
cmdline | "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN legends.exe /TR "C:\Users\test22\AppData\Local\Temp\41bde21dc7\legends.exe" /F |
file | C:\Users\test22\AppData\Local\Temp\41bde21dc7\legends.exe |
file | C:\Users\test22\AppData\Local\Temp\1000028001\kds7uq5kknv.exe |
file | C:\Users\test22\AppData\Roaming\a091ec0a6e2227\clip64.dll |
file | C:\Users\test22\AppData\Local\Temp\1000028001\kds7uq5kknv.exe |
file | C:\Users\test22\AppData\Local\Temp\41bde21dc7\legends.exe |