Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | July 22, 2023, 9:40 p.m. | July 22, 2023, 9:44 p.m. |
-
build.exe "C:\Users\test22\AppData\Local\Temp\build.exe"
2568
Name | Response | Post-Analysis Lookup |
---|---|---|
t.me | 149.154.167.99 | |
steamcommunity.com | 184.87.111.197 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49166 104.88.222.199:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | b1:30:5e:4c:ee:14:70:87:a7:d7:1c:77:07:b5:3c:2c:99:13:aa:c5 |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
suspicious_features | Connection to IP address | suspicious_request | GET http://116.203.7.113/ba898ce7ff6c6db9d00aca6445e5d347 | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://116.203.7.113/upgrade.zip |
request | GET http://116.203.7.113/ba898ce7ff6c6db9d00aca6445e5d347 |
request | GET http://116.203.7.113/upgrade.zip |
request | GET https://steamcommunity.com/profiles/76561198982268531 |
file | C:\ProgramData\vcruntime140.dll |
file | C:\ProgramData\msvcp140.dll |
file | C:\ProgramData\nss3.dll |
file | C:\ProgramData\freebl3.dll |
file | C:\ProgramData\mozglue.dll |
file | C:\ProgramData\softokn3.dll |
host | 116.203.7.113 |
Bkav | W32.AIDetectMalware |
Elastic | malicious (high confidence) |
FireEye | Generic.mg.ed3809d571d4d52f |
Malwarebytes | Spyware.RedLineStealer |
CrowdStrike | win/malicious_confidence_100% (W) |
Symantec | ML.Attribute.HighConfidence |
ESET-NOD32 | a variant of Win32/GenKryptik.GMBA |
APEX | Malicious |
Cynet | Malicious (score: 100) |
Avast | Win32:PWSX-gen [Trj] |
Trapmine | malicious.moderate.ml.score |
SentinelOne | Static AI - Suspicious PE |
Detected | |
Cylance | unsafe |
Rising | Backdoor.Agent!8.C5D (TFE:5:TmDVI2xbRDB) |
Ikarus | Trojan.Win32.Krypt |
Fortinet | W32/Kryptik.HUBJ!tr |
AVG | Win32:PWSX-gen [Trj] |
DeepInstinct | MALICIOUS |
process | build.exe | useragent | Mozilla/5.0 (Windows NT 10.0; x64 rv:107.0) Gecko / 20100101 Firefox / 107.0 | ||||||
process | build.exe | useragent | Mozilla/5.0 (X11; Linux 3.5.4-1-ARCH i686; es) KHTML/4.9.1 (like Gecko) Konqueror/4.9 |