Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Nov. 17, 2023, 6:31 p.m. | Nov. 17, 2023, 6:33 p.m. |
-
update.exe "C:\Users\test22\AppData\Local\Temp\update.exe"
2548
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
193.233.132.13 | Active | Moloch |
Suricata Alerts
Suricata TLS
No Suricata TLS
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
section | .3YF |
section | .ld} |
section | .6OI |
suspicious_features | POST method with no referer header, Connection to IP address | suspicious_request | POST http://193.233.132.13/ | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://193.233.132.13/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/nss3.dll | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://193.233.132.13/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/msvcp140.dll | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://193.233.132.13/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/vcruntime140.dll | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://193.233.132.13/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/mozglue.dll | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://193.233.132.13/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/freebl3.dll | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://193.233.132.13/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/softokn3.dll | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://193.233.132.13/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll | ||||||
suspicious_features | POST method with no referer header, Connection to IP address | suspicious_request | POST http://193.233.132.13/4b3d724e3280557cef4603019e268268 |
request | POST http://193.233.132.13/ |
request | GET http://193.233.132.13/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/nss3.dll |
request | GET http://193.233.132.13/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/msvcp140.dll |
request | GET http://193.233.132.13/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/vcruntime140.dll |
request | GET http://193.233.132.13/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/mozglue.dll |
request | GET http://193.233.132.13/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/freebl3.dll |
request | GET http://193.233.132.13/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/softokn3.dll |
request | GET http://193.233.132.13/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll |
request | POST http://193.233.132.13/4b3d724e3280557cef4603019e268268 |
request | POST http://193.233.132.13/ |
request | POST http://193.233.132.13/4b3d724e3280557cef4603019e268268 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State |
file | C:\Users\test22\AppData\LocalLow\msvcp140.dll |
file | C:\Users\test22\AppData\LocalLow\softokn3.dll |
file | C:\Users\test22\AppData\LocalLow\freebl3.dll |
file | C:\Users\test22\AppData\LocalLow\mozglue.dll |
file | C:\Users\test22\AppData\LocalLow\vcruntime140.dll |
file | C:\Users\test22\AppData\LocalLow\sqlite3.dll |
file | C:\Users\test22\AppData\LocalLow\nss3.dll |
file | C:\Users\test22\AppData\LocalLow\vcruntime140.dll |
file | C:\Users\test22\AppData\LocalLow\softokn3.dll |
file | C:\Users\test22\AppData\LocalLow\nss3.dll |
file | C:\Users\test22\AppData\LocalLow\msvcp140.dll |
file | C:\Users\test22\AppData\LocalLow\mozglue.dll |
file | C:\Users\test22\AppData\LocalLow\freebl3.dll |
file | C:\Users\test22\AppData\LocalLow\sqlite3.dll |