Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | June 21, 2023, 5:36 a.m. | June 21, 2023, 5:40 a.m. |
-
-
Log_me.exe "C:\Users\test22\AppData\Local\Temp\Log_me.exe"
2860
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | _RDATA |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\imageformats\qtiff.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5Widgets.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-datetime-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-debug-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-process-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-file-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\generic\qtuiotouchplugin.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\libssl-1_1.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\styles\qwindowsvistastyle.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-memory-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5Svg.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\opengl32sw.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-console-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-synch-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\VCRUNTIME140_1.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5Gui.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-math-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-namedpipe-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\python311.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-convert-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-errorhandling-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-environment-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\platforms\qwindows.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\imageformats\qjpeg.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-file-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\iconengines\qsvgicon.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-handle-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\platforms\qminimal.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\libGLESv2.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-conio-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5Network.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-string-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5Core.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-util-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-time-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\libffi-8.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\MSVCP140.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\imageformats\qwebp.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5Qml.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\imageformats\qico.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\MSVCP140_1.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\platforms\qoffscreen.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-runtime-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5WebSockets.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\VCRUNTIME140.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-timezone-l1-1-0.dll |
Elastic | malicious (moderate confidence) |
section | {u'size_of_data': u'0x0000f600', u'virtual_address': u'0x00052000', u'entropy': 7.555587253339539, u'name': u'.rsrc', u'virtual_size': u'0x0000f498'} | entropy | 7.55558725334 | description | A section with a high entropy has been found |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-process-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-file-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\generic\qtuiotouchplugin.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\translations\qtbase_ja.qm |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\cryptography-40.0.2.dist-info\LICENSE.APACHE |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\platforms\qwindows.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\translations\qtbase_gd.qm |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\cryptography-40.0.2.dist-info\LICENSE.PSF |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\translations\qtbase_pl.qm |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-conio-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5Network.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\cryptography-40.0.2.dist-info\INSTALLER |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-util-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-string-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\_cffi_backend.cp311-win_amd64.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\translations\qtbase_cs.qm |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\platforms\qoffscreen.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\VCRUNTIME140.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\base_library.zip |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5Quick.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\charset_normalizer\md.cp311-win_amd64.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-processthreads-l1-1-1.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\VCRUNTIME140_1.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\_ctypes.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-locale-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-handle-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\QtWidgets.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-console-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-debug-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\translations\qtbase_ar.qm |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\styles\qwindowsvistastyle.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-memory-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-synch-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\psutil\_psutil_windows.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-math-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-namedpipe-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\python311.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\translations\qtbase_fr.qm |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-synch-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\iconengines\qsvgicon.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-processenvironment-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\select.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\cryptography\hazmat\bindings\_rust.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5Core.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\certifi\py.typed |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-profile-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-time-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\translations\qtbase_fi.qm |
file | C:\Users\test22\AppData\Local\Temp\_MEI26522\_hashlib.pyd |