Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | July 4, 2023, 5:30 p.m. | July 4, 2023, 5:33 p.m. |
-
-
RegEdit.exe "C:\Users\test22\AppData\Local\Temp\RegEdit.exe"
2660
-
Name | Response | Post-Analysis Lookup |
---|---|---|
www.skywardcaresolutions.com |
CNAME
skywardcaresolutions.com
|
34.102.136.180 |
www.wpdisk.online | 162.246.16.124 | |
www.knackwoodcraft.com | 103.224.182.242 | |
www.georgiapoolrepair.com | 3.64.163.50 |
Suricata Alerts
Suricata TLS
No Suricata TLS
section | .ndata |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.georgiapoolrepair.com/m42i/?Tj8=sca8Wgav+7lpr46mO2SOfn8L1FqfIRKRflu72oULm95UjSDEvk18j06OoJk9i9lBkDmqwETQ&6l=t8eH-ni8gH7P7 | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.wpdisk.online/m42i/?Tj8=0sZ28+ci8yt/ivZsj55lF15XBhnwAOFinpe3O8Cu7exdqn0Kmyu5eUmJDSvcLDOVyCRsFL+q&6l=t8eH-ni8gH7P7 | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.skywardcaresolutions.com/m42i/?Tj8=HYStpBgXm5OSuuoTrjSOUG+Ep+BfwFVeF26GwyixNj4tMYPsRs5ox28XQOKN0Z9jWLsOl7rl&6l=t8eH-ni8gH7P7 | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://www.knackwoodcraft.com/m42i/?Tj8=xCeaUZyvi6lN/KmTLqcakS33huDpVYz01lvWq0zTkBCYj/gauxIj8jp1kNsv+HiFGZvFrtg2&6l=t8eH-ni8gH7P7 |
request | GET http://www.georgiapoolrepair.com/m42i/?Tj8=sca8Wgav+7lpr46mO2SOfn8L1FqfIRKRflu72oULm95UjSDEvk18j06OoJk9i9lBkDmqwETQ&6l=t8eH-ni8gH7P7 |
request | GET http://www.wpdisk.online/m42i/?Tj8=0sZ28+ci8yt/ivZsj55lF15XBhnwAOFinpe3O8Cu7exdqn0Kmyu5eUmJDSvcLDOVyCRsFL+q&6l=t8eH-ni8gH7P7 |
request | GET http://www.skywardcaresolutions.com/m42i/?Tj8=HYStpBgXm5OSuuoTrjSOUG+Ep+BfwFVeF26GwyixNj4tMYPsRs5ox28XQOKN0Z9jWLsOl7rl&6l=t8eH-ni8gH7P7 |
request | GET http://www.knackwoodcraft.com/m42i/?Tj8=xCeaUZyvi6lN/KmTLqcakS33huDpVYz01lvWq0zTkBCYj/gauxIj8jp1kNsv+HiFGZvFrtg2&6l=t8eH-ni8gH7P7 |
file | C:\Users\test22\AppData\Roaming\iiqaavf\fbkktp.exe |
file | C:\Users\test22\AppData\Local\Temp\nslF0AB.tmp\heqtnvfb.dll |
file | C:\Users\test22\AppData\Local\Temp\nslF0AB.tmp\heqtnvfb.dll |
file | C:\Users\test22\AppData\Roaming\iiqaavf\fbkktp.exe |
reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\yyienjsscxxhqq | reg_value | C:\Users\test22\AppData\Roaming\iiqaavf\fbkktp.exe "C:\Users\test22\AppData\Local\Temp\RegEdit.exe" |
Bkav | W32.AIDetectMalware |
Lionic | Trojan.Win32.Agent.tshg |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Gen:Variant.Nemesis.23876 |
ALYac | Trojan.NSISX.Spy.Gen.24 |
Malwarebytes | Generic.Malware/Suspicious |
Sangfor | Suspicious.Win32.Save.ins |
Cybereason | malicious.9f5527 |
Arcabit | Trojan.Nemesis.D5D44 [many] |
Cyren | W32/Injector.BOI.gen!Eldorado |
Symantec | ML.Attribute.HighConfidence |
ESET-NOD32 | a variant of Win32/Injector.ETCC |
APEX | Malicious |
Kaspersky | UDS:DangerousObject.Multi.Generic |
BitDefender | Gen:Variant.Nemesis.23876 |
Avast | Win32:TrojanX-gen [Trj] |
Emsisoft | Gen:Variant.Nemesis.23876 (B) |
VIPRE | Gen:Variant.Nemesis.23876 |
McAfee-GW-Edition | BehavesLike.Win32.Generic.fc |
Trapmine | malicious.moderate.ml.score |
FireEye | Generic.mg.923b2cf57335ee57 |
Sophos | Mal/Generic-S |
SentinelOne | Static AI - Suspicious PE |
Detected | |
MAX | malware (ai score=81) |
Microsoft | Trojan:Win32/Sabsik.FL.B!ml |
ZoneAlarm | UDS:DangerousObject.Multi.Generic |
GData | Win32.Trojan.Agent.QBIPL1 |
Cynet | Malicious (score: 100) |
AhnLab-V3 | Trojan/Win.Generic.R587806 |
Acronis | suspicious |
McAfee | Artemis!923B2CF57335 |
Cylance | unsafe |
TrendMicro-HouseCall | TROJ_GEN.R002H01G423 |
Rising | Trojan.Injector!8.C4 (TFE:6:mGe17sBdx5E) |
Ikarus | Trojan-Spy.FormBook |
Fortinet | NSIS/Agent.DCAC!tr |
AVG | Win32:TrojanX-gen [Trj] |
DeepInstinct | MALICIOUS |
CrowdStrike | win/malicious_confidence_100% (W) |