Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 17, 2023, 4:35 p.m. | Oct. 17, 2023, 4:38 p.m. |
-
bQGy.exe "C:\Users\test22\AppData\Local\Temp\bQGy.exe"
2548
Name | Response | Post-Analysis Lookup |
---|---|---|
apps.identrust.com |
CNAME
a1952.dscq.akamai.net
CNAME
identrust.edgesuite.net
|
23.67.53.27 |
pt.textbin.net |
CNAME
textbin.net
|
148.72.177.212 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.101:49168 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49166 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49169 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49173 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49174 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49187 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49184 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49193 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49201 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49198 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49206 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49164 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49220 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49200 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49225 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49203 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49226 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49165 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49182 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49183 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49205 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49185 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49208 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49209 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49188 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49211 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49162 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49170 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49191 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49171 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49194 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49172 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49176 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49195 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49213 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49175 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49217 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49199 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49221 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49223 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49177 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49202 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49181 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49207 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49186 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49178 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49190 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49192 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49212 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49196 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49222 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49204 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49179 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49210 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49214 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49224 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49216 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49180 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49218 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49189 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49197 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49215 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
TLS 1.2 192.168.56.101:49219 148.72.177.212:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pt.textbin.net | 1d:23:54:67:33:68:c9:3a:86:52:9e:a1:51:50:39:64:8e:b5:c2:cc |
request | GET http://apps.identrust.com/roots/dstrootcax3.p7c |
description | bQGy.exe tried to sleep 241 seconds, actually delayed analysis time by 241 seconds |
Lionic | Trojan.Win32.SpyGate.4!c |
MicroWorld-eScan | Generic.MSIL.Bladabindi.134BC814 |
ClamAV | Win.Trojan.B-468 |
Skyhigh | BehavesLike.Win32.Generic.mm |
McAfee | Trojan-FJXA |
Malwarebytes | Bladabindi.Backdoor.Bot.DDS |
Zillya | Trojan.Bladabindi.Win32.150595 |
Sangfor | Suspicious.Win32.Save.a |
K7AntiVirus | Trojan ( 700000121 ) |
Alibaba | Backdoor:MSIL/Bladabindi.234b924f |
K7GW | Trojan ( 700000121 ) |
Cybereason | malicious.0b28fc |
Arcabit | Generic.MSIL.Bladabindi.134BC814 |
Baidu | MSIL.Backdoor.Bladabindi.a |
VirIT | Trojan.Win32.Genus.PRT |
Symantec | Backdoor.Ratenjay |
Elastic | Windows.Trojan.Njrat |
ESET-NOD32 | a variant of MSIL/Bladabindi.BC |
APEX | Malicious |
Cynet | Malicious (score: 100) |
Kaspersky | HEUR:Backdoor.MSIL.SpyGate.gen |
BitDefender | Generic.MSIL.Bladabindi.134BC814 |
Avast | Win32:RATX-gen [Trj] |
Tencent | Trojan.Win32.Bladabindi.16000442 |
Emsisoft | Generic.MSIL.Bladabindi.134BC814 (B) |
F-Secure | Trojan.TR/Dropper.Gen7 |
DrWeb | BackDoor.BladabindiNET.27 |
VIPRE | Generic.MSIL.Bladabindi.134BC814 |
TrendMicro | BKDR_BLADABI.SMC |
Trapmine | malicious.high.ml.score |
FireEye | Generic.mg.a60c2e8459387329 |
Sophos | Troj/Bbindi-W |
Ikarus | Trojan.MSIL.Bladabindi |
Detected | |
Avira | TR/Dropper.Gen7 |
Kingsoft | malware.kb.c.1000 |
Microsoft | Backdoor:MSIL/Bladabindi.B |
ViRobot | Backdoor.Win32.Bladabindi.Gen.A |
ZoneAlarm | HEUR:Backdoor.MSIL.SpyGate.gen |
GData | MSIL.Backdoor.Bladabindi.AV |
Varist | W32/MSIL_Agent.AQ.gen!Eldorado |
AhnLab-V3 | Malware/Win32.RL_SpyGate.C3495328 |
BitDefenderTheta | Gen:NN.ZemsilF.36738.bm0@a4jVUQh |
ALYac | Generic.MSIL.Bladabindi.134BC814 |
MAX | malware (ai score=88) |
VBA32 | Trojan.MSIL.Bladabindi.Heur |
Cylance | unsafe |
Panda | Trj/GdSda.A |
Rising | Backdoor.njRAT!1.9E49 (CLASSIC) |
SentinelOne | Static AI - Malicious PE |