Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Nov. 7, 2023, 7:40 a.m. | Nov. 7, 2023, 7:42 a.m. |
-
My2.exe "C:\Users\test22\AppData\Local\Temp\My2.exe"
2552
Name | Response | Post-Analysis Lookup |
---|---|---|
pool.hashvault.pro | 131.153.76.130 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.56.101:59002 -> 164.124.101.2:53 | 2036289 | ET COINMINER CoinMiner Domain in DNS Lookup (pool .hashvault .pro) | Crypto Currency Mining Activity Detected |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.3 192.168.56.101:49163 125.253.92.50:3333 |
None | None | None |
section | {u'size_of_data': u'0x0052b400', u'virtual_address': u'0x0000c000', u'entropy': 7.705731102421746, u'name': u'.data', u'virtual_size': u'0x0052b240'} | entropy | 7.70573110242 | description | A section with a high entropy has been found | |||||||||
entropy | 0.988514333738 | description | Overall entropy of this PE file is high |