Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Sept. 25, 2023, 5 p.m. | Sept. 25, 2023, 5:04 p.m. |
-
-
-
-
-
svchost.exe "C:\Users\test22\AppData\Local\Temp\svchost.exe"
292 -
cmd.exe "cmd" /c mkdir "C:\Users\test22\AppData\Roaming\avast"
2972 -
cmd.exe "cmd" /c schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\test22\AppData\Roaming\avast\avast.exe'" /f
3044-
schtasks.exe schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\test22\AppData\Roaming\avast\avast.exe'" /f
2392
-
-
cmd.exe "cmd" /c copy "C:\Users\test22\AppData\Local\Temp\svchost.exe" "C:\Users\test22\AppData\Roaming\avast\avast.exe"
2464
-
-
-
-
-
svchost.exe "C:\Users\test22\AppData\Local\Temp\svchost.exe"
724 -
cmd.exe "cmd" /c mkdir "C:\Users\test22\AppData\Roaming\avast"
2132 -
cmd.exe "cmd" /c schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\test22\AppData\Roaming\avast\avast.exe'" /f
2516-
schtasks.exe schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\test22\AppData\Roaming\avast\avast.exe'" /f
2780
-
-
cmd.exe "cmd" /c copy "C:\Users\test22\AppData\Local\Temp\svchost.exe" "C:\Users\test22\AppData\Roaming\avast\avast.exe"
2676
-
-
cmd.exe "cmd" /c mkdir "C:\Users\test22\AppData\Roaming\svchost"
2708 -
cmd.exe "cmd" /c schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\test22\AppData\Roaming\svchost\svchost.exe'" /f
2752-
schtasks.exe schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\test22\AppData\Roaming\svchost\svchost.exe'" /f
2908
-
-
cmd.exe "cmd" /c copy "C:\Users\test22\AppData\Local\Temp\docjhny20230925.exe" "C:\Users\test22\AppData\Roaming\svchost\svchost.exe"
2800
-
Name | Response | Post-Analysis Lookup |
---|---|---|
mail.royalcheckout.store |
CNAME
royalcheckout.store
|
179.43.183.46 |
softwarez.online | ||
api.ipify.org |
CNAME
api4.ipify.org
|
104.237.62.212 |
Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Network\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Login Data |
file | C:\Users\test22\AppData\Local\Chromium\User Data |
file | C:\Users\test22\AppData\Local\MapleStudio\ChromePlus\User Data |
file | C:\Users\test22\AppData\Local\Yandex\YandexBrowser\User Data |
domain | api.ipify.org |
file | C:\Users\test22\AppData\Roaming\johnny10121.exe |
file | C:\Users\test22\AppData\Local\Temp\svchost.exe |
cmdline | "cmd" /c schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\test22\AppData\Roaming\svchost\svchost.exe'" /f |
cmdline | "C:\Users\test22\AppData\Local\Temp\svchost.exe" |
cmdline | schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\test22\AppData\Roaming\svchost\svchost.exe'" /f |
cmdline | "cmd" /c mkdir "C:\Users\test22\AppData\Roaming\svchost" |
cmdline | "cmd" /c copy "C:\Users\test22\AppData\Local\Temp\svchost.exe" "C:\Users\test22\AppData\Roaming\avast\avast.exe" |
cmdline | "C:\Users\test22\AppData\Local\Temp\svchost.exe" |
cmdline | C:\Users\test22\AppData\Local\Temp\svchost.exe |
cmdline | "cmd" /c copy "C:\Users\test22\AppData\Local\Temp\docjhny20230925.exe" "C:\Users\test22\AppData\Roaming\svchost\svchost.exe" |
cmdline | "cmd" /c schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\test22\AppData\Roaming\avast\avast.exe'" /f |
cmdline | schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\test22\AppData\Roaming\avast\avast.exe'" /f |
file | C:\Users\test22\AppData\Local\Temp\svchost.exe |
file | C:\Users\test22\AppData\Roaming\johnny10121.exe |
file | C:\Users\test22\AppData\Roaming\johnny10121.exe |
file | C:\Users\test22\AppData\Local\Temp\svchost.exe |
section | {u'size_of_data': u'0x00122c00', u'virtual_address': u'0x00002000', u'entropy': 7.980574836792098, u'name': u'.text', u'virtual_size': u'0x00122b20'} | entropy | 7.98057483679 | description | A section with a high entropy has been found | |||||||||
entropy | 0.878730638459 | description | Overall entropy of this PE file is high |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | PWS Memory | rule | Generic_PWS_Memory_Zero | ||||||
description | Communications smtp | rule | Network_SMTP_dotNet | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Affect hook table | rule | win_hook | ||||||
description | Run a KeyLogger | rule | KeyLogger |
cmdline | "cmd" /c schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\test22\AppData\Roaming\svchost\svchost.exe'" /f |
cmdline | schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\test22\AppData\Roaming\svchost\svchost.exe'" /f |
cmdline | "cmd" /c mkdir "C:\Users\test22\AppData\Roaming\svchost" |
cmdline | "cmd" /c mkdir "C:\Users\test22\AppData\Roaming\avast" |
cmdline | "cmd" /c schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\test22\AppData\Roaming\avast\avast.exe'" /f |
cmdline | schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\test22\AppData\Roaming\avast\avast.exe'" /f |
receiver | [] | sender | [] | server | 179.43.183.46 |
description | johnny10121.exe tried to sleep 2728223 seconds, actually delayed analysis time by 2728223 seconds |
cmdline | "cmd" /c schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\test22\AppData\Roaming\svchost\svchost.exe'" /f |
cmdline | schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\test22\AppData\Roaming\svchost\svchost.exe'" /f |
cmdline | "cmd" /c schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\test22\AppData\Roaming\avast\avast.exe'" /f |
cmdline | schtasks /create /sc minute /mo 1 /tn "Nafifas" /tr "'C:\Users\test22\AppData\Roaming\avast\avast.exe'" /f |
file | C:\Users\test22\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect |
file | C:\Users\test22\AppData\Roaming\FTPGetter\servers.xml |
file | C:\Users\test22\AppData\Roaming\FileZilla\recentservers.xml |
registry | HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions |
registry | HKEY_CURRENT_USER\SOFTWARE\FTPWare\COREFTP\Sites |