Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Oct. 13, 2023, 8:34 a.m. | Oct. 13, 2023, 8:43 a.m. |
-
Setup.exe "C:\Users\test22\AppData\Local\Temp\Setup.exe"
872
Name | Response | Post-Analysis Lookup |
---|---|---|
ip-api.com | 208.95.112.1 |
IP Address | Status | Action |
---|---|---|
103.54.250.99 | Active | Moloch |
104.20.55.214 | Active | Moloch |
104.21.1.213 | Active | Moloch |
104.21.27.205 | Active | Moloch |
104.21.50.138 | Active | Moloch |
104.21.55.151 | Active | Moloch |
104.21.68.7 | Active | Moloch |
104.21.73.229 | Active | Moloch |
104.21.76.140 | Active | Moloch |
104.21.77.146 | Active | Moloch |
104.21.79.166 | Active | Moloch |
104.21.92.170 | Active | Moloch |
104.26.0.82 | Active | Moloch |
104.26.10.81 | Active | Moloch |
104.26.12.244 | Active | Moloch |
104.26.2.124 | Active | Moloch |
141.193.213.20 | Active | Moloch |
172.67.129.18 | Active | Moloch |
172.67.134.134 | Active | Moloch |
172.67.140.52 | Active | Moloch |
172.67.142.169 | Active | Moloch |
172.67.148.35 | Active | Moloch |
172.67.150.80 | Active | Moloch |
172.67.156.49 | Active | Moloch |
172.67.173.200 | Active | Moloch |
172.67.181.113 | Active | Moloch |
172.67.193.133 | Active | Moloch |
172.67.198.26 | Active | Moloch |
172.67.199.57 | Active | Moloch |
172.67.201.26 | Active | Moloch |
172.67.209.11 | Active | Moloch |
172.67.212.131 | Active | Moloch |
172.67.33.252 | Active | Moloch |
172.67.70.22 | Active | Moloch |
185.208.164.106 | Active | Moloch |
185.63.228.45 | Active | Moloch |
186.230.14.42 | Active | Moloch |
164.124.101.2 | Active | Moloch |
208.95.112.1 | Active | Moloch |
193.231.236.124 | Active | Moloch |
193.57.67.4 | Active | Moloch |
200.40.52.151 | Active | Moloch |
23.227.38.74 | Active | Moloch |
34.174.61.199 | Active | Moloch |
46.242.233.27 | Active | Moloch |
64.26.60.153 | Active | Moloch |
76.223.54.146 | Active | Moloch |
80.147.223.166 | Active | Moloch |
81.22.97.159 | Active | Moloch |
83.56.13.220 | Active | Moloch |
88.198.0.105 | Active | Moloch |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49161 -> 208.95.112.1:80 | 2022082 | ET POLICY External IP Lookup ip-api.com | Device Retrieving External IP Address Detected |
Suricata TLS
No Suricata TLS
pdb_path | F:\StryzonNet\Release\Setup.pdb |
section | .gfids |
request | GET http://ip-api.com/line/?fields=hosting |
domain | ip-api.com |
Bkav | W64.AIDetectMalware |
CrowdStrike | win/malicious_confidence_60% (W) |
Avast | Win32:Dh-A [Heur] |
Kingsoft | malware.kb.a.738 |
AVG | Win32:Dh-A [Heur] |
host | 103.54.250.99 | |||
host | 104.20.55.214 | |||
host | 104.21.1.213 | |||
host | 104.21.27.205 | |||
host | 104.21.50.138 | |||
host | 104.21.55.151 | |||
host | 104.21.68.7 | |||
host | 104.21.73.229 | |||
host | 104.21.76.140 | |||
host | 104.21.77.146 | |||
host | 104.21.79.166 | |||
host | 104.21.92.170 | |||
host | 104.26.0.82 | |||
host | 104.26.10.81 | |||
host | 104.26.12.244 | |||
host | 104.26.2.124 | |||
host | 141.193.213.20 | |||
host | 172.67.129.18 | |||
host | 172.67.134.134 | |||
host | 172.67.140.52 | |||
host | 172.67.142.169 | |||
host | 172.67.148.35 | |||
host | 172.67.150.80 | |||
host | 172.67.156.49 | |||
host | 172.67.173.200 | |||
host | 172.67.181.113 | |||
host | 172.67.193.133 | |||
host | 172.67.198.26 | |||
host | 172.67.199.57 | |||
host | 172.67.201.26 | |||
host | 172.67.209.11 | |||
host | 172.67.212.131 | |||
host | 172.67.33.252 | |||
host | 172.67.70.22 | |||
host | 185.208.164.106 | |||
host | 185.63.228.45 | |||
host | 186.230.14.42 | |||
host | 193.231.236.124 | |||
host | 193.57.67.4 | |||
host | 200.40.52.151 | |||
host | 23.227.38.74 | |||
host | 34.174.61.199 | |||
host | 46.242.233.27 | |||
host | 64.26.60.153 | |||
host | 76.223.54.146 | |||
host | 80.147.223.166 | |||
host | 81.22.97.159 | |||
host | 83.56.13.220 | |||
host | 88.198.0.105 |
dead_host | 185.63.228.45:25 |