Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 31, 2023, 9:14 a.m. | Oct. 31, 2023, 9:16 a.m. |
-
explorer.exe C:\Windows\Explorer.EXE
1452 -
javaw.exe "C:\Users\test22\AppData\Roaming\jre7\bin\javaw.exe" -jar "C:\Users\test22\AppData\Roaming\ahyzzfonw.txt"
3064-
icacls.exe C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M
1728 -
java.exe "C:\Users\test22\AppData\Roaming\jre7\bin\java.exe" -jar "C:\Users\test22\AppData\Roaming\jre7\ahyzzfonw.txt"
2272-
java.exe "C:\Users\test22\AppData\Roaming\jre7\bin\java.exe" -jar "C:\Users\test22\ahyzzfonw.txt"
204-
cmd.exe cmd /c schtasks /create /sc minute /mo 30 /tn Skype /tr "C:\Users\test22\AppData\Roaming\ahyzzfonw.txt"
2288-
schtasks.exe schtasks /create /sc minute /mo 30 /tn Skype /tr "C:\Users\test22\AppData\Roaming\ahyzzfonw.txt"
1320
-
-
java.exe "C:\Users\test22\AppData\Roaming\jre7\bin\java.exe" -jar "C:\Users\test22\AppData\Roaming\ahyzzfonw.txt"
1616
-
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
repo1.maven.org | 199.232.196.209 | |
50kteam.dynamic-dns.net | 185.222.58.83 | |
github.com | 20.200.245.247 | |
objects.githubusercontent.com | 185.199.109.133 | |
wshsoft.company | 185.232.14.169 |
Suricata Alerts
No Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.101:49171 185.199.110.133:443 |
C=US, O=DigiCert Inc, CN=DigiCert TLS RSA SHA256 2020 CA1 | C=US, ST=California, L=San Francisco, O=GitHub, Inc., CN=*.github.io | a1:46:14:c7:2a:1d:52:79:f6:aa:2b:b2:c5:0a:3b:d3:f5:02:06:75 |
TLS 1.2 192.168.56.101:49170 151.101.40.209:443 |
C=BE, O=GlobalSign nv-sa, CN=GlobalSign Atlas R3 DV TLS CA 2023 Q1 | CN=repo1.maven.org | 94:bc:2a:d0:1a:cf:41:94:d4:9a:de:44:ab:b4:42:39:8a:f6:bf:f3 |
TLS 1.2 192.168.56.101:49169 151.101.40.209:443 |
C=BE, O=GlobalSign nv-sa, CN=GlobalSign Atlas R3 DV TLS CA 2023 Q1 | CN=repo1.maven.org | 94:bc:2a:d0:1a:cf:41:94:d4:9a:de:44:ab:b4:42:39:8a:f6:bf:f3 |
TLS 1.2 192.168.56.101:49167 20.200.245.247:443 |
C=US, O=DigiCert Inc, CN=DigiCert TLS Hybrid ECC SHA384 2020 CA1 | C=US, ST=California, L=San Francisco, O=GitHub, Inc., CN=github.com | a3:b5:9e:5f:e8:84:ee:1f:34:d9:8e:ef:85:8e:3f:b6:62:ac:10:4a |
TLS 1.2 192.168.56.101:49168 151.101.40.209:443 |
C=BE, O=GlobalSign nv-sa, CN=GlobalSign Atlas R3 DV TLS CA 2023 Q1 | CN=repo1.maven.org | 94:bc:2a:d0:1a:cf:41:94:d4:9a:de:44:ab:b4:42:39:8a:f6:bf:f3 |
domain | 50kteam.dynamic-dns.net |
request | GET http://wshsoft.company/jv/jrex.zip |
file | C:\Users\test22\AppData\Local\Temp\jna--877171118\jna2206488719288708811.dll |
file | C:\Users\test22\AppData\Local\Temp\jna--877171118\jna7686053444325241709.dll |
cmdline | schtasks /create /sc minute /mo 30 /tn Skype /tr "C:\Users\test22\AppData\Roaming\ahyzzfonw.txt" |
cmdline | cmd /c schtasks /create /sc minute /mo 30 /tn Skype /tr "C:\Users\test22\AppData\Roaming\ahyzzfonw.txt" |
file | C:\Users\test22\AppData\Roaming\jre7\bin\t2k.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-crt-multibyte-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-core-util-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\pack200.exe |
file | C:\Users\test22\AppData\Roaming\jre7\bin\ssv.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-core-profile-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\management.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-crt-private-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-crt-environment-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\wsdetect.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-core-errorhandling-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\jfr.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\prism_common.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-core-console-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\javafx_iio.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-core-handle-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\dt_shmem.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\nio.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-core-debug-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\jjs.exe |
file | C:\Users\test22\AppData\Roaming\jre7\bin\jpeg.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\w2k_lsa_auth.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\eula.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-core-string-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\plugin2\msvcp140.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-core-datetime-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\jabswitch.exe |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-core-rtlsupport-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\npt.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\gstreamer-lite.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\jfxwebkit.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\fontmanager.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\sunmscapi.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\prism_d3d.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-core-synch-l1-2-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\javaw.exe |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-crt-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-crt-convert-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\jfxmedia.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\tnameserv.exe |
file | C:\Users\test22\AppData\Roaming\jre7\bin\rmid.exe |
file | C:\Users\test22\AppData\Roaming\jre7\bin\awt.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\kinit.exe |
file | C:\Users\test22\AppData\Roaming\jre7\bin\api-ms-win-core-processenvironment-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\dtplugin\deployJava1.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\decora_sse.dll |
file | C:\Users\test22\AppData\Roaming\jre7\bin\splashscreen.dll |
cmdline | schtasks /create /sc minute /mo 30 /tn Skype /tr "C:\Users\test22\AppData\Roaming\ahyzzfonw.txt" |
cmdline | cmd /c schtasks /create /sc minute /mo 30 /tn Skype /tr "C:\Users\test22\AppData\Roaming\ahyzzfonw.txt" |
reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ahyzzfonw | reg_value | "C:\Users\test22\AppData\Roaming\ahyzzfonw.txt" | ||||||
reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\ahyzzfonw | reg_value | "C:\Users\test22\AppData\Roaming\ahyzzfonw.txt" | ||||||
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ahyzzfonw.txt | ||||||||
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ahyzzfonw.txt | ||||||||
cmdline | schtasks /create /sc minute /mo 30 /tn Skype /tr "C:\Users\test22\AppData\Roaming\ahyzzfonw.txt" | ||||||||
cmdline | cmd /c schtasks /create /sc minute /mo 30 /tn Skype /tr "C:\Users\test22\AppData\Roaming\ahyzzfonw.txt" |
cmdline | C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M |
file | C:\Users\test22\AppData\Local\Temp\jna--877171118\jna2206488719288708811.dll |
file | C:\Users\test22\AppData\Local\Temp\jna--877171118\jna7686053444325241709.dll |
Lionic | Trojan.Script.Agent.4!c |
Skyhigh | JS/Agent.ha |
ALYac | JS:Trojan.Cryxos.13219 |
VIPRE | JS:Trojan.Cryxos.13219 |
Symantec | JS.Downloader |
ESET-NOD32 | JS/Kryptik.CPV |
Avast | Script:SNH-gen [Trj] |
Kaspersky | Trojan.JS.Agent.erc |
BitDefender | JS:Trojan.Cryxos.13219 |
NANO-Antivirus | Exploit.Script.Nemucod.dzzhbf |
MicroWorld-eScan | JS:Trojan.Cryxos.13219 |
Tencent | Js.Trojan.Agent.Umhl |
Sophos | JS/Drop-DHA |
DrWeb | Trojan.Siggen21.56157 |
FireEye | JS:Trojan.Cryxos.13219 |
Emsisoft | JS:Trojan.Cryxos.13219 (B) |
Ikarus | Trojan.Java.GenericGB |
Detected | |
Microsoft | TrojanDownloader:Win32/Nemucod!ml |
Arcabit | JS:Trojan.Cryxos.D33A3 |
ZoneAlarm | Trojan.JS.Agent.erc |
GData | JS:Trojan.Cryxos.13219 |
Varist | JS/Agent.BZP |
McAfee | JS/Agent.ha |
Rising | Trojan.Kryptik/JS!8.10DBE (TOPIS:E0:8FLEVXabM7O) |
MAX | malware (ai score=84) |
Fortinet | JS/Kryptik.CPV!tr |
AVG | Script:SNH-gen [Trj] |
dead_host | 185.222.58.83:1780 |
dead_host | 192.168.56.101:49181 |
dead_host | 192.168.56.101:49191 |
dead_host | 192.168.56.101:49180 |
dead_host | 192.168.56.101:49189 |
dead_host | 192.168.56.101:49188 |
dead_host | 192.168.56.101:49179 |
dead_host | 192.168.56.101:49187 |
dead_host | 185.222.58.83:1788 |
dead_host | 192.168.56.101:49183 |
dead_host | 192.168.56.101:49185 |
dead_host | 192.168.56.101:49182 |
dead_host | 192.168.56.101:49190 |