Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Nov. 11, 2023, 4:16 p.m. | Nov. 11, 2023, 4:18 p.m. |
Name | Response | Post-Analysis Lookup |
---|---|---|
blmceii.xyz | 213.226.100.83 |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
suspicious_features | POST method with no referer header | suspicious_request | POST http://blmceii.xyz/cbot/blista.php | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://blmceii.xyz/cbot/collector.php |
request | POST http://blmceii.xyz/cbot/blista.php |
request | POST http://blmceii.xyz/cbot/collector.php |
request | POST http://blmceii.xyz/cbot/blista.php |
request | POST http://blmceii.xyz/cbot/collector.php |
description | relog.exe tried to sleep 153 seconds, actually delayed analysis time by 153 seconds |
wmi | SELECT * FROM Win32_Processor |
section | {u'size_of_data': u'0x00094e00', u'virtual_address': u'0x000df000', u'entropy': 7.999580649441448, u'name': u'.rdata', u'virtual_size': u'0x00095000'} | entropy | 7.99958064944 | description | A section with a high entropy has been found | |||||||||
entropy | 0.999161073826 | description | Overall entropy of this PE file is high |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
wmi | SELECT * FROM Win32_Processor |
buffer | Buffer with sha1: b2f67b73c35459c3823b9f7d1159a0215d2f13fe |
reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\07717ltc | reg_value | C:\Users\test22\AppData\Local\Systemservices\Winserv.exe |