Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | July 19, 2023, 7:24 a.m. | July 19, 2023, 7:28 a.m. |
-
WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Office15\WINWORD.EXE" C:\Users\test22\AppData\Local\Temp\officialzx.doc
840
Suricata Alerts
Suricata TLS
No Suricata TLS
suspicious_features | Connection to IP address | suspicious_request | GET http://87.121.221.212/officialzx.exe | ||||||
suspicious_features | POST method with no referer header, HTTP version 1.0 used, Connection to IP address | suspicious_request | POST http://185.246.220.60/official/five/fre.php |
request | GET http://87.121.221.212/officialzx.exe |
request | POST http://185.246.220.60/official/five/fre.php |
request | POST http://185.246.220.60/official/five/fre.php |
file | C:\Users\test22\AppData\Local\Temp\~$ficialzx.doc |
filetype_details | Rich Text Format data, version 1, unknown character set | filename | officialzx.doc |
host | 185.246.220.60 | |||
host | 87.121.221.212 |