Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | June 7, 2023, 10:28 a.m. | June 7, 2023, 10:30 a.m. |
-
-
003737.exe "C:\Users\test22\AppData\Local\Temp\003737.exe"
2212
-
Name | Response | Post-Analysis Lookup |
---|---|---|
www.brick2theatercompany.org |
CNAME
brick2theatercompany.org
|
184.154.216.162 |
www.dwcmy.icu | 107.148.132.109 | |
www.sqlite.org | 45.33.6.223 |
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.brick2theatercompany.org/jaux/?RA2Ffnn=icakqaRty6vlYpraZuLZDt8iqw6TAXaANP93WqO2tXnG28cx2yzbZzs/HE+K7qwLPazhHRQPHP7+Ft+vCQAGl34EUMiC/bZO7D7RKMw=&gLB=QULU5 | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.dwcmy.icu/jaux/?RA2Ffnn=dXzChEviWThMepFS/xxtUmXNQtBwn4KvgZ5ardr6ndysj8KT1gjetGIPwrBptW+hnPwvo+gRGgTDVleeJCFvAYnj9Conz55LaaEoVKU=&gLB=QULU5 |
request | GET http://www.brick2theatercompany.org/jaux/?RA2Ffnn=icakqaRty6vlYpraZuLZDt8iqw6TAXaANP93WqO2tXnG28cx2yzbZzs/HE+K7qwLPazhHRQPHP7+Ft+vCQAGl34EUMiC/bZO7D7RKMw=&gLB=QULU5 |
request | GET http://www.sqlite.org/2017/sqlite-dll-win32-x86-3210000.zip |
request | POST http://www.dwcmy.icu/jaux/ |
request | GET http://www.dwcmy.icu/jaux/?RA2Ffnn=dXzChEviWThMepFS/xxtUmXNQtBwn4KvgZ5ardr6ndysj8KT1gjetGIPwrBptW+hnPwvo+gRGgTDVleeJCFvAYnj9Conz55LaaEoVKU=&gLB=QULU5 |
request | POST http://www.dwcmy.icu/jaux/ |
file | C:\Users\test22\AppData\Local\Temp\nsh276B.tmp\rnthgfcoj.dll |
file | C:\Users\test22\AppData\Local\Temp\nsh276B.tmp\rnthgfcoj.dll |
Bkav | W32.AIDetectMalware |
Lionic | Trojan.Win32.Agent.tshg |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Trojan.GenericKD.67401925 |
FireEye | Generic.mg.d93dd4200d1997c9 |
McAfee | Artemis!D93DD4200D19 |
Malwarebytes | Malware.AI.2287091883 |
VIPRE | Gen:Variant.Nemesis.22835 |
Sangfor | Trojan.Win32.Agent.Vdgb |
CrowdStrike | win/malicious_confidence_100% (W) |
K7GW | Trojan ( 005a63941 ) |
K7AntiVirus | Trojan ( 005a63941 ) |
Arcabit | Trojan.Nemesis.D5933 [many] |
Cyren | W32/Injector.BNP.gen!Eldorado |
Symantec | Trojan Horse |
ESET-NOD32 | Win32/Formbook.AK |
Cynet | Malicious (score: 100) |
APEX | Malicious |
Kaspersky | HEUR:Trojan-Spy.Win32.Noon.gen |
BitDefender | Trojan.GenericKD.67401925 |
Avast | Win32:PWSX-gen [Trj] |
Emsisoft | Trojan.GenericKD.67401925 (B) |
F-Secure | Trojan.TR/AD.GenShell.cgaxh |
DrWeb | Trojan.Siggen20.59355 |
TrendMicro | TrojanSpy.Win32.NOON.USPAXF623 |
McAfee-GW-Edition | BehavesLike.Win32.Generic.fc |
Sophos | Mal/Generic-S |
Ikarus | Trojan-Spy.Agent |
Webroot | W32.Noon.Gen |
Avira | TR/AD.GenShell.cgaxh |
Antiy-AVL | Trojan/Win32.NSISInject |
Microsoft | Trojan:Win32/FormBook.TG!MTB |
ZoneAlarm | HEUR:Trojan-Spy.Win32.Noon.gen |
GData | Trojan.GenericKD.67401925 |
Detected | |
AhnLab-V3 | Trojan/Win.Bazarloader.R584928 |
MAX | malware (ai score=89) |
Panda | Trj/Chgt.AD |
TrendMicro-HouseCall | TrojanSpy.Win32.NOON.USPAXF623 |
Rising | Trojan.Nsisinject!8.11178 (TFE:5:8iPUQb4QmBF) |
Fortinet | NSIS/Agent.DCAC!tr |
AVG | Win32:PWSX-gen [Trj] |
Cybereason | malicious.00d199 |
DeepInstinct | MALICIOUS |