Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Nov. 26, 2023, 1:32 p.m. | Nov. 26, 2023, 1:57 p.m. |
-
-
go-memexec-2265040774.exe C:\Users\test22\AppData\Local\Temp\go-memexec-2265040774.exe
2156
-
-
explorer.exe C:\Windows\Explorer.EXE
1236
Name | Response | Post-Analysis Lookup |
---|---|---|
needforrat.hopto.org |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.56.103:64894 -> 164.124.101.2:53 | 2028681 | ET POLICY DNS Query to DynDNS Domain *.hopto .org | Potentially Bad Traffic |
Suricata TLS
No Suricata TLS
section | .symtab |
domain | needforrat.hopto.org |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TestLink.lnk |
file | C:\Users\test22\AppData\Local\Temp\go-memexec-2265040774.exe |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TestLink.lnk |
file | C:\Users\test22\AppData\Local\Temp\go-memexec-2265040774.exe |
section | {u'size_of_data': u'0x00025200', u'virtual_address': u'0x0027b000', u'entropy': 7.994340505844019, u'name': u'/19', u'virtual_size': u'0x000250e2'} | entropy | 7.99434050584 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00007400', u'virtual_address': u'0x002a1000', u'entropy': 7.924061196329007, u'name': u'/32', u'virtual_size': u'0x000072b7'} | entropy | 7.92406119633 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00040800', u'virtual_address': u'0x002aa000', u'entropy': 7.996590037460738, u'name': u'/65', u'virtual_size': u'0x00040735'} | entropy | 7.99659003746 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00029400', u'virtual_address': u'0x002eb000', u'entropy': 7.990850969829446, u'name': u'/78', u'virtual_size': u'0x000292b8'} | entropy | 7.99085096983 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x0000c400', u'virtual_address': u'0x00315000', u'entropy': 7.794339889247348, u'name': u'/90', u'virtual_size': u'0x0000c24b'} | entropy | 7.79433988925 | description | A section with a high entropy has been found | |||||||||
entropy | 0.220918367347 | description | Overall entropy of this PE file is high |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TestLink.lnk |
file | C:\Users\test22\AppData\Local\Temp\go-memexec-2265040774.exe |
Bkav | W64.AIDetectMalware |
Lionic | Trojan.Win32.Tasker.tsbe |
Elastic | malicious (high confidence) |
MicroWorld-eScan | Trojan.GenericKD.61684544 |
Skyhigh | BehavesLike.Win64.Backdoor.vh |
ALYac | Backdoor.RAT.Netwire |
Cylance | unsafe |
Zillya | Dropper.Agent.Win32.511527 |
Sangfor | Trojan.Win32.Save.a |
K7AntiVirus | Trojan ( 0058879c1 ) |
Alibaba | TrojanDropper:Win32/NetWire.0ee943b3 |
K7GW | Trojan ( 0058879c1 ) |
Arcabit | Trojan.Generic.D3AD3B40 |
VirIT | Trojan.Win32.Genus.DPKP |
Symantec | ML.Attribute.HighConfidence |
ESET-NOD32 | a variant of WinGo/TrojanDropper.Agent.K |
Cynet | Malicious (score: 99) |
APEX | Malicious |
ClamAV | Win.Malware.Wingo-9966132-0 |
Kaspersky | Trojan.Win32.NetWire.kux |
BitDefender | Trojan.GenericKD.61684544 |
Avast | Win64:Evo-gen [Trj] |
Tencent | Win32.Trojan.Netwire.Anhl |
Emsisoft | Trojan.GenericKD.61684544 (B) |
F-Secure | Heuristic.HEUR/AGEN.1318165 |
DrWeb | Trojan.MulDrop20.50375 |
VIPRE | Trojan.GenericKD.61684544 |
FireEye | Trojan.GenericKD.61684544 |
Sophos | ATK/Ekocit-A |
Ikarus | Trojan-Dropper.WinGo.Agent |
Webroot | W32.Trojan.GenKD |
Varist | W64/ABTrojan.XGHI-8480 |
Avira | HEUR/AGEN.1318165 |
Antiy-AVL | Trojan[Dropper]/Win32.Agent |
Xcitium | Malware@#3d9w0t89m7uad |
Microsoft | VirTool:Win32/Ekocit.A!MTB |
ZoneAlarm | Trojan.Win32.NetWire.kux |
GData | Trojan.GenericKD.61684544 |
Detected | |
AhnLab-V3 | Trojan/Win.Ekocit.R525732 |
McAfee | Artemis!2B5ECA0C8DCF |
MAX | malware (ai score=82) |
VBA32 | Trojan.NetWiredRC |
Malwarebytes | Generic.Malware/Suspicious |
Panda | Trj/CI.A |
SentinelOne | Static AI - Suspicious PE |
MaxSecure | Trojan.Malware.187683045.susgen |
Fortinet | W64/Agent.K!tr |
AVG | Win64:Evo-gen [Trj] |
DeepInstinct | MALICIOUS |