Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Nov. 28, 2023, 2:44 p.m. | Nov. 28, 2023, 2:47 p.m. |
-
-
InstallerAdvanced_v2x.8.4.exe "C:\Users\test22\AppData\Local\Temp\InstallerAdvanced_v2x.8.4\InstallerAdvanced_v2x.8.4.exe" -pm8s3C7vEPTU17SJ5Ti0UBO9lRsEJPZhJHye5XnRE1Mn8GS1i213VzI7I8glkDVYZLktJNNiFBv3ZBbP9Av
2800-
Installer_Install_Easy_v3.5.0.exe "C:\Users\test22\AppData\Local\Temp\RarSFX0\Installer_Install_Easy_v3.5.0.exe"
2500
-
-
InstallerGeniusExpert_v5a.6.exe "C:\Users\test22\AppData\Local\Temp\InstallerAdvanced_v2x.8.4\InstallerGeniusExpert_v5a.6.exe" -pxxvzsEpTxueOig7AmThea3obthhRBE3tXadOuJh1BfJcevsz9pYX4aXEitfkxHr3AU0hdsgMLqN5tm68YRRmPgzXnIGaE6
2836-
iexplore.exe "C:\Program Files (x86)\Internet Explorer\iexplore.exe" C:\Users\test22\AppData\Local\Temp\RarSFX0\NTS_eTaxInvoice.html
2948-
iexplore.exe "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:2948 CREDAT:145409
3052
-
-
-
-
explorer.exe C:\Windows\Explorer.EXE
1452
Name | Response | Post-Analysis Lookup |
---|---|---|
srtk.hometax.go.kr | 116.67.103.155 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49177 116.67.103.155:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Extended Validation Secure Server CA | serialNumber=102-83-01521, unknown=KR, unknown=Government Entity, C=KR, ST=Sejong, O=National Tax Service, CN=www.hometax.go.kr | ad:c7:ba:35:01:64:a2:d8:57:ab:3a:46:65:c0:86:75:e4:5d:39:92 |
TLSv1 192.168.56.101:49176 116.67.103.155:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Extended Validation Secure Server CA | serialNumber=102-83-01521, unknown=KR, unknown=Government Entity, C=KR, ST=Sejong, O=National Tax Service, CN=www.hometax.go.kr | ad:c7:ba:35:01:64:a2:d8:57:ab:3a:46:65:c0:86:75:e4:5d:39:92 |
TLSv1 192.168.56.101:49178 116.67.103.155:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Extended Validation Secure Server CA | serialNumber=102-83-01521, unknown=KR, unknown=Government Entity, C=KR, ST=Sejong, O=National Tax Service, CN=www.hometax.go.kr | ad:c7:ba:35:01:64:a2:d8:57:ab:3a:46:65:c0:86:75:e4:5d:39:92 |
TLSv1 192.168.56.101:49175 116.67.103.155:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Extended Validation Secure Server CA | serialNumber=102-83-01521, unknown=KR, unknown=Government Entity, C=KR, ST=Sejong, O=National Tax Service, CN=www.hometax.go.kr | ad:c7:ba:35:01:64:a2:d8:57:ab:3a:46:65:c0:86:75:e4:5d:39:92 |
TLSv1 192.168.56.101:49179 116.67.103.155:443 |
None | None | None |
TLSv1 192.168.56.101:49174 116.67.103.155:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Extended Validation Secure Server CA | serialNumber=102-83-01521, unknown=KR, unknown=Government Entity, C=KR, ST=Sejong, O=National Tax Service, CN=www.hometax.go.kr | ad:c7:ba:35:01:64:a2:d8:57:ab:3a:46:65:c0:86:75:e4:5d:39:92 |
TLSv1 192.168.56.101:49180 116.67.103.155:443 |
None | None | None |
TLSv1 192.168.56.101:49173 116.67.103.155:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Extended Validation Secure Server CA | serialNumber=102-83-01521, unknown=KR, unknown=Government Entity, C=KR, ST=Sejong, O=National Tax Service, CN=www.hometax.go.kr | ad:c7:ba:35:01:64:a2:d8:57:ab:3a:46:65:c0:86:75:e4:5d:39:92 |
section | .ndata |
request | GET http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml |
request | GET https://srtk.hometax.go.kr/download/rollups/seed.js |
request | GET https://srtk.hometax.go.kr/download/jquery-1.11.1.min.js |
request | GET https://srtk.hometax.go.kr/download/cri.css?v=1 |
request | GET https://srtk.hometax.go.kr/download/components/enc-cp949-min.js |
request | GET https://srtk.hometax.go.kr/download/rollups/aes.js |
request | GET https://srtk.hometax.go.kr/download/cri_ems_nt.js?v=1 |
request | GET https://srtk.hometax.go.kr/download/rollups/md5.js |
request | GET https://srtk.hometax.go.kr/download/img/security_pop_bt_close.png |
request | GET https://srtk.hometax.go.kr/download/img/security_pop_ic_lock.png |
file | C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\seed[1].js |
file | C:\Users\test22\AppData\Local\Temp\InstallerAdvanced_v2x.8.4\InstallerGeniusExpert_v5a.6.exe |
file | C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\aes[1].js |
file | C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\cri_ems_nt[1].js |
file | C:\InstallerAdvanced_v2x.8.4.exe |
file | C:\Users\test22\AppData\Local\Temp\RarSFX0\Installer_Install_Easy_v3.5.0.exe |
file | C:\Users\test22\AppData\Local\Temp\InstallerAdvanced_v2x.8.4\InstallerAdvanced_v2x.8.4.exe |
file | C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\enc-cp949-min[1].js |
file | C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\md5[1].js |
file | C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\jquery-1.11.1.min[1].js |
file | C:\Users\test22\AppData\Local\Temp\RarSFX0\Installer_Install_Easy_v3.5.0.exe |
file | C:\Users\test22\AppData\Local\Temp\RarSFX0\NTS_eTaxInvoice.html |
file | C:\Users\test22\AppData\Local\Temp\InstallerAdvanced_v2x.8.4\InstallerAdvanced_v2x.8.4.exe |
file | C:\Users\test22\AppData\Local\Temp\InstallerAdvanced_v2x.8.4\InstallerGeniusExpert_v5a.6.exe |
file | C:\Users\test22\AppData\Local\Temp\RarSFX0\Installer_Install_Easy_v3.5.0.exe |
section | {u'size_of_data': u'0x0002a400', u'virtual_address': u'0x0003b000', u'entropy': 7.037634001863341, u'name': u'.rsrc', u'virtual_size': u'0x0002a216'} | entropy | 7.03763400186 | description | A section with a high entropy has been found | |||||||||
entropy | 0.838709677419 | description | Overall entropy of this PE file is high |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
cmdline | "C:\Program Files (x86)\Internet Explorer\iexplore.exe" C:\Users\test22\AppData\Local\Temp\RarSFX0\NTS_eTaxInvoice.html |
cmdline | "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:2948 CREDAT:145409 |
host | 117.18.232.200 |
file | C:\Users\test22\AppData\Local\Temp\InstallerAdvanced_v2x.8.4\InstallerGeniusExpert_v5a.6.exe |
CAT-QuickHeal | PUA.Skymonksol.Gen |
Zillya | Trojan.Generic.Win32.1693826 |
VirIT | PUP.Win32.SkyMonk.A |
Kaspersky | not-a-virus:AdWare.Win32.Skyli.a |
Emsisoft | Application.Generic (A) |
DrWeb | Tool.Skymonk.39 |
Ikarus | Trojan.MSIL.Basic |
Microsoft | PUA:Win32/Skymonk |
Gridinsoft | Adware.Win32.Gen.vl!c |
ZoneAlarm | not-a-virus:AdWare.Win32.Skyli.a |
DeepInstinct | MALICIOUS |