Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | June 20, 2023, 5:27 p.m. | June 20, 2023, 5:36 p.m. |
IP Address | Status | Action |
---|---|---|
104.21.12.203 | Active | Moloch |
154.39.174.239 | Active | Moloch |
162.0.231.6 | Active | Moloch |
164.124.101.2 | Active | Moloch |
172.67.185.242 | Active | Moloch |
172.67.203.63 | Active | Moloch |
195.161.62.100 | Active | Moloch |
198.185.159.145 | Active | Moloch |
20.255.200.185 | Active | Moloch |
45.33.6.223 | Active | Moloch |
84.32.84.32 | Active | Moloch |
91.195.240.123 | Active | Moloch |
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.ketocanadmqy.cloud/ogeb/?STILiOsC=JCW7LwLHnn7ptjGjE5oXohZmdFlQQ26ARwAmaoNxO6ijvQN7ubUT60jiWusc3p3YeBdlnORuW+NtBTBOf6MBl7CRUR/NRW0MRl+FZL4=&kvoc=Jnm0rJMacH | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.gnhxxiazai03.com/ogeb/?STILiOsC=wBih4ktWfPNsySsqn3uI1HmQOkxE78XnlLTDvxJFz8Ksfyo9cnxjh72KIWiVUUXAXHwdyJ5YpLQGYf4Z+A02Vjn9hAcAu81BvwPbwlI=&kvoc=Jnm0rJMacH | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.r1146.xyz/ogeb/?STILiOsC=hQC9FzST15eBXJ4J4T0DlrZN3V4nndOGJI8rCOq0KQaVihaPabvY2aUaE4N/PK/Cku54qUwIUhcWHwQfhhinhH5BJGjDnxoo3iDp4OU=&kvoc=Jnm0rJMacH | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.drstephaniebest.com/ogeb/?STILiOsC=+v0OuBHGG6cw5ZwrQCjmtsYbU4xaGL5HoMfXaXw9oSi2F/e6KL+7wkfrHW9mkq7nBIGbSiwCyL8lMMQd9mW+kFWaqBx5WK5Isw5ml80=&kvoc=Jnm0rJMacH | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.nicejunq.com/ogeb/?STILiOsC=61GncP3LZGSS1NuGOhw0w9YAjVqrgaXoImnMpoqiHfpClz+VkHF1OaSSbCiQjyR+WlMAeIDV0LjpJ/XsdXKhboCqPvNVkna3o/MBoBk=&kvoc=Jnm0rJMacH | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.fb99vn.com/ogeb/?STILiOsC=OXN+k+OlhXjl96bKh2NTgPCFs15ire34/TTevHac9SK8WXddN+80UbpDpODSd5z2qlIY7v82+nyluTO39li1mIxMKX8Jb/R8tbta/VI=&kvoc=Jnm0rJMacH | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.poshkits.info/ogeb/?STILiOsC=AqRXXMRheGbbuzNJ7gUd3ELHirevyxJNjMj6aH1i+QGnsBV8j36ZsXkdOVofclXLXJuwnJ0etyY1DKNGveWcGaTGb3YRrubSnMygGeg=&kvoc=Jnm0rJMacH | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.fstrainingllc.com/ogeb/?STILiOsC=3AILmDJPkAUUrpOG/VIeUrZXgpOSZo6R/tiWoTcNtPioWsJTZGZ4drzV2BWU9NJm5Ofj96iGCfDOoWGqNQZdTpxyILTH4aD/oQaBOA8=&kvoc=Jnm0rJMacH | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.visitel.shop/ogeb/?STILiOsC=JmLU2mTBWsrOHDUrIsVZgtVQRaelVRuf6+I2Xs1ZEo8rZrv8bAAW18MTALrdbAN3gfqX7mOUKpSKY+XC5VOAaGGHACr1P6ttQJNqQi0=&kvoc=Jnm0rJMacH | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.cracksoftwaresite.com/ogeb/?STILiOsC=KHI+YMON8GDkJzoILZCxgp2k0vA8qk8w1nm3Hzfxt5cieIBSKAQj/mHyTxk04gzaD6SR3s2U41jQ75g96W4nWpYWemp5ZS7oMYAdX5g=&kvoc=Jnm0rJMacH |
request | POST http://www.ketocanadmqy.cloud/ogeb/ |
request | GET http://www.ketocanadmqy.cloud/ogeb/?STILiOsC=JCW7LwLHnn7ptjGjE5oXohZmdFlQQ26ARwAmaoNxO6ijvQN7ubUT60jiWusc3p3YeBdlnORuW+NtBTBOf6MBl7CRUR/NRW0MRl+FZL4=&kvoc=Jnm0rJMacH |
request | GET http://www.sqlite.org/2016/sqlite-dll-win32-x86-3130000.zip |
request | POST http://www.gnhxxiazai03.com/ogeb/ |
request | GET http://www.gnhxxiazai03.com/ogeb/?STILiOsC=wBih4ktWfPNsySsqn3uI1HmQOkxE78XnlLTDvxJFz8Ksfyo9cnxjh72KIWiVUUXAXHwdyJ5YpLQGYf4Z+A02Vjn9hAcAu81BvwPbwlI=&kvoc=Jnm0rJMacH |
request | POST http://www.r1146.xyz/ogeb/ |
request | GET http://www.r1146.xyz/ogeb/?STILiOsC=hQC9FzST15eBXJ4J4T0DlrZN3V4nndOGJI8rCOq0KQaVihaPabvY2aUaE4N/PK/Cku54qUwIUhcWHwQfhhinhH5BJGjDnxoo3iDp4OU=&kvoc=Jnm0rJMacH |
request | POST http://www.drstephaniebest.com/ogeb/ |
request | GET http://www.drstephaniebest.com/ogeb/?STILiOsC=+v0OuBHGG6cw5ZwrQCjmtsYbU4xaGL5HoMfXaXw9oSi2F/e6KL+7wkfrHW9mkq7nBIGbSiwCyL8lMMQd9mW+kFWaqBx5WK5Isw5ml80=&kvoc=Jnm0rJMacH |
request | POST http://www.nicejunq.com/ogeb/ |
request | GET http://www.nicejunq.com/ogeb/?STILiOsC=61GncP3LZGSS1NuGOhw0w9YAjVqrgaXoImnMpoqiHfpClz+VkHF1OaSSbCiQjyR+WlMAeIDV0LjpJ/XsdXKhboCqPvNVkna3o/MBoBk=&kvoc=Jnm0rJMacH |
request | POST http://www.fb99vn.com/ogeb/ |
request | GET http://www.fb99vn.com/ogeb/?STILiOsC=OXN+k+OlhXjl96bKh2NTgPCFs15ire34/TTevHac9SK8WXddN+80UbpDpODSd5z2qlIY7v82+nyluTO39li1mIxMKX8Jb/R8tbta/VI=&kvoc=Jnm0rJMacH |
request | POST http://www.poshkits.info/ogeb/ |
request | GET http://www.poshkits.info/ogeb/?STILiOsC=AqRXXMRheGbbuzNJ7gUd3ELHirevyxJNjMj6aH1i+QGnsBV8j36ZsXkdOVofclXLXJuwnJ0etyY1DKNGveWcGaTGb3YRrubSnMygGeg=&kvoc=Jnm0rJMacH |
request | POST http://www.fstrainingllc.com/ogeb/ |
request | GET http://www.fstrainingllc.com/ogeb/?STILiOsC=3AILmDJPkAUUrpOG/VIeUrZXgpOSZo6R/tiWoTcNtPioWsJTZGZ4drzV2BWU9NJm5Ofj96iGCfDOoWGqNQZdTpxyILTH4aD/oQaBOA8=&kvoc=Jnm0rJMacH |
request | POST http://www.visitel.shop/ogeb/ |
request | GET http://www.visitel.shop/ogeb/?STILiOsC=JmLU2mTBWsrOHDUrIsVZgtVQRaelVRuf6+I2Xs1ZEo8rZrv8bAAW18MTALrdbAN3gfqX7mOUKpSKY+XC5VOAaGGHACr1P6ttQJNqQi0=&kvoc=Jnm0rJMacH |
request | POST http://www.cracksoftwaresite.com/ogeb/ |
request | GET http://www.cracksoftwaresite.com/ogeb/?STILiOsC=KHI+YMON8GDkJzoILZCxgp2k0vA8qk8w1nm3Hzfxt5cieIBSKAQj/mHyTxk04gzaD6SR3s2U41jQ75g96W4nWpYWemp5ZS7oMYAdX5g=&kvoc=Jnm0rJMacH |
request | POST http://www.ketocanadmqy.cloud/ogeb/ |
request | POST http://www.gnhxxiazai03.com/ogeb/ |
request | POST http://www.r1146.xyz/ogeb/ |
request | POST http://www.drstephaniebest.com/ogeb/ |
request | POST http://www.nicejunq.com/ogeb/ |
request | POST http://www.fb99vn.com/ogeb/ |
request | POST http://www.poshkits.info/ogeb/ |
request | POST http://www.fstrainingllc.com/ogeb/ |
request | POST http://www.visitel.shop/ogeb/ |
request | POST http://www.cracksoftwaresite.com/ogeb/ |
file | C:\Users\test22\AppData\Local\Temp\nsnF34B.tmp\xrlrshqq.dll |
file | C:\Users\test22\AppData\Local\Temp\nsnF34B.tmp\xrlrshqq.dll |
Bkav | W32.AIDetectMalware |
Lionic | Trojan.Win32.Agent.tshg |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Gen:Variant.Nemesis.22774 |
FireEye | Generic.mg.fa24b7c4c3dc0c6d |
CAT-QuickHeal | Trojan.Avemariarat |
McAfee | Artemis!FA24B7C4C3DC |
Malwarebytes | Trojan.Loader |
Sangfor | Suspicious.Win32.Save.ins |
K7AntiVirus | Trojan ( 005a6c251 ) |
Alibaba | Trojan:Application/Generic.acb3471c |
K7GW | Trojan ( 005a6c251 ) |
Cybereason | malicious.4c3dc0 |
Arcabit | Trojan.Nemesis.D58F6 [many] |
VirIT | Trojan.Win32.Genus.RHT |
Cyren | W32/ABRisk.QHLS-5482 |
Symantec | ML.Attribute.HighConfidence |
ESET-NOD32 | a variant of Win32/Injector.ETAW |
APEX | Malicious |
Cynet | Malicious (score: 100) |
Kaspersky | HEUR:Trojan-Spy.Win32.Noon.gen |
BitDefender | Gen:Variant.Nemesis.22774 |
Avast | Win32:InjectorX-gen [Trj] |
Tencent | Win32.Trojan-Spy.Noon.Anhl |
Sophos | Mal/Generic-S |
F-Secure | Trojan.TR/Redcap.jxawb |
VIPRE | Gen:Variant.Nemesis.22774 |
TrendMicro | TROJ_GEN.R002C0DFJ23 |
McAfee-GW-Edition | BehavesLike.Win32.Generic.dc |
Trapmine | malicious.moderate.ml.score |
Emsisoft | Gen:Variant.Nemesis.22774 (B) |
SentinelOne | Static AI - Suspicious PE |
Avira | TR/AD.GenShell.hswgb |
MAX | malware (ai score=85) |
Antiy-AVL | Trojan/Win32.Injector |
Microsoft | Trojan:Win32/Leonem |
ZoneAlarm | HEUR:Trojan-Spy.Win32.Noon.gen |
GData | Zum.Androm.1 |
Detected | |
AhnLab-V3 | Trojan/Win.Generic.R585815 |
Cylance | unsafe |
Panda | Trj/GdSda.A |
TrendMicro-HouseCall | TROJ_GEN.R002C0DFJ23 |
Rising | Trojan.Injector!8.C4 (TFE:6:I3RwG4Ux51M) |
Yandex | Trojan.Injector!CMkfvt0VUfA |
Ikarus | Trojan.Win32.Injector |
Fortinet | NSIS/Agent.DCAC!tr |
AVG | Win32:InjectorX-gen [Trj] |
DeepInstinct | MALICIOUS |
CrowdStrike | win/malicious_confidence_100% (W) |