Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | July 7, 2023, 7:31 a.m. | July 7, 2023, 7:35 a.m. |
-
qlmfckzvtoso.exe "C:\Users\test22\AppData\Local\Temp\qlmfckzvtoso.exe"
2560
Name | Response | Post-Analysis Lookup |
---|---|---|
t.me | 149.154.167.99 | |
steamcommunity.com | 104.76.78.101 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49167 104.75.41.21:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | b1:30:5e:4c:ee:14:70:87:a7:d7:1c:77:07:b5:3c:2c:99:13:aa:c5 |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
suspicious_features | Connection to IP address | suspicious_request | GET http://128.140.41.121/19c538606b75d27e13807e5f5b638b12 | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://128.140.41.121/archive.zip |
request | GET http://128.140.41.121/19c538606b75d27e13807e5f5b638b12 |
request | GET http://128.140.41.121/archive.zip |
request | GET https://steamcommunity.com/profiles/76561199520592470 |
description | qlmfckzvtoso.exe tried to sleep 175 seconds, actually delayed analysis time by 175 seconds |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State |
file | C:\ProgramData\vcruntime140.dll |
file | C:\ProgramData\msvcp140.dll |
file | C:\ProgramData\nss3.dll |
file | C:\ProgramData\freebl3.dll |
file | C:\ProgramData\mozglue.dll |
file | C:\ProgramData\softokn3.dll |
host | 128.140.41.121 |
process | qlmfckzvtoso.exe | useragent | Mozilla/5.0 (Windows NT 10.0; x64 rv:107.0) Gecko / 20100101 Firefox / 107.0 | ||||||
process | qlmfckzvtoso.exe | useragent | Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko/20100101 Firefox/111.0 |