Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Dec. 13, 2023, 8:11 p.m. | Dec. 13, 2023, 8:13 p.m. |
-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -ExecutionPolicy unrestricted -File C:\Users\test22\AppData\Local\Temp\paste.ps1
1372-
-
taskkill.exe taskkill /f /im dsm.exe
2216
-
-
-
taskkill.exe taskkill /f /im dom.exe
2376
-
-
cmd.exe "C:\Windows\system32\cmd.exe" /c del /f /q C:\Windows\System32\config\systemprofile\dom\*
2440 -
-
taskkill.exe taskkill /f /im WindowsUpdate.exe
2528
-
-
cmd.exe "C:\Windows\system32\cmd.exe" /c del /f /q C:\Windows\temp\WindowsUpdate.exe
2592 -
-
attrib.exe attrib -s -h -r C:\Users\test22\AppData\Local\Temp\config.json
2680
-
-
-
attrib.exe attrib -s -h -r C:\Windows\temp\config.json
2768
-
-
cmd.exe "C:\Windows\system32\cmd.exe" /c rd /s /q %tmp%\config.json
2812 -
cmd.exe "C:\Windows\system32\cmd.exe" /c rd /s /q C:\Windows\temp\config.json
2860 -
-
attrib.exe attrib +R +S +H C:\Users\test22\AppData\Local\Temp\config.json
2992
-
-
-
attrib.exe attrib +R +S +H C:\Windows\temp\config.json
2160
-
-
javas.exe "C:\Users\test22\AppData\Local\Temp\javas.exe"
2268 -
-
taskkill.exe taskkill /f /im shella.exe
660
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
auto.skypool.xyz | 18.163.108.2 |
Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\javas.exe |
cmdline | "C:\Windows\system32\cmd.exe" /c taskkill /f /im dsm.exe |
cmdline | "C:\Windows\system32\cmd.exe" /c rd /s /q %tmp%\config.json |
cmdline | "C:\Windows\system32\cmd.exe" /c attrib +R +S +H C:\Windows\temp\config.json |
cmdline | "C:\Windows\system32\cmd.exe" /c taskkill /f /im dom.exe |
cmdline | "C:\Windows\system32\cmd.exe" /c attrib -s -h -r C:\Windows\temp\config.json |
cmdline | "C:\Windows\system32\cmd.exe" /c taskkill /f /im WindowsUpdate.exe |
cmdline | "C:\Windows\system32\cmd.exe" /c rd /s /q C:\Windows\temp\config.json |
cmdline | "C:\Windows\system32\cmd.exe" /c attrib +R +S +H %tmp%\config.json |
cmdline | "C:\Windows\system32\cmd.exe" /c del /f /q C:\Windows\System32\config\systemprofile\dom\* |
cmdline | "C:\Windows\system32\cmd.exe" /c attrib -s -h -r %tmp%\config.json |
cmdline | "C:\Windows\system32\cmd.exe" /c taskkill /f /im shella.exe |
cmdline | "C:\Windows\system32\cmd.exe" /c del /f /q C:\Windows\temp\WindowsUpdate.exe |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "shella.exe") |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "dsm.exe") |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "WindowsUpdate.exe") |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = "dom.exe") |
Data received | HTTP/1.1 200 Accept-Ranges: bytes ETag: W/"5389312-1701966496000" Last-Modified: Thu, 07 Dec 2023 16:28:16 GMT Content-Type: application/x-rar-compressed Content-Length: 5389312 Date: Wed, 13 Dec 2023 11:11:15 GMT |
Data received | (EçfEçHÇEÇ HEçHEÏ(EÇfE×H´E HEÇLuÏHUÇHM÷èËÞúÿ¿ }§Lu÷H}LCu÷WÀE×HÞHÿÃA< uöû w¸ fEåAÇ*ÃEäL}×ë2¸ fEå]×SIÌènÄüÿLøHEßH¹ ÿÿH#ÁIÇHEßÛDÃIÖIÏè£Û. BÆ; WÀEǸ fEÕHEÏI¾ ÿÿI#ÆH Î E HÁHEÏÇEÇ MÌLE×HUÇIÍèçüÿHUHúr1HÿÂHM÷HÁHú rHÂ'HIøH+ÁHÀøHøò èå´. H]¯A¿ HUçHËèóÊûÿLÀWÀEǸ fEÕHEÏI#ÆH ¹D HÁHEÏÇEÇ MÌHUÇIÍèuæüÿHɼD HEÇÇEÏ MÌD¶CHUÇIÍèþSýÿHKWÀº H ÉuÏ}§EçHEçë/Ï}§EÇfUÕHEÏI#ÆHÁHEÏHÆHÿÀ< u÷EÇHEÇ Eç@öÇtçï}§@öÇtç÷}§WÀEÇfUÕHEÏI#ÆH *¼D HÁHEÏÇEÇ MÌLEçHUÇIÍè¥åüÿHK(WÀº H ÉuÏ }§EçHEçë3Ï@}§EÇfUÕHEÏI#ÆHÁHEÏHÆ@ HÿÀ< u÷EÇHEÇ Eç@öÇ@tç¿}§@öÇ tçß}§WÀEÇfUÕHEÏI#ÆH »D HÁHEÏÇEÇ MÌLEçHUÇIÍè÷äüÿHKWÀº H Éuºï}§EçHEçë4ºï}§EÇfUÕHEÏI#ÆHÁHEÏHÆ@ HÿÀ< u÷EÇHEÇ Eçºçsº÷}§@ÿyº÷}§WÀEÇfUÕHEÏI#ÆH ÛºD HÁHEÏÇEÇ MÌLEçHUÇIÍèFäüÿHK8WÀº H Éuºï }§EçHEçë3ºï }§EÇfUÕHEÏI#ÆHÁHEÏHÆ HÿÀ< u÷EÇHEÇ Eçºç sº÷ }§ºç sº÷ }§WÀEÇfUÕHEÏI#ÆH Ò¸D HÁHEÏÇEÇ MÌLEçHUÇIÍèãüÿHCPHUÇH ÀQ HEç(EçfEçHÇEÇ HEçHEÏ(EÇfE×HFúD HEÇHÇEÏ LE×HM÷è-Úúÿºï}§H}÷H}HC}÷WÀE×HÿÆ<7 u÷þ w¸ fEåD*þD}äLu×ë2¸ fEåu×VIÌèÕ¿üÿLðHEßH¹ ÿÿH#ÁIÆHEßÞDÆH×IÎè ×. AÆ WÀEǸ fEÕHEÏH¹ ÿÿH#ÁH ¹D HÁHEÏÇEÇ MÌLE×HUÇIÍèlâüÿHUHúrOHÿÂHM÷HÁHú rHÂ'HIøH+ÁHÀøHøwQèP°. ë H §¸D HMÇÇEÏ MÌE3ÀIÍèKýÿIÅHMH3Ìèï. H$ø HÄ A_A^A]A\_^]Ãè/ Ìèy/ Ìès/ ÌÌÌÌÌÌÌH|$UHìHì H¡I H3ÄHEðHùH Éu3Àé 3ÒH$ DB è$/ ØHÿù ° E LE°(E HEàHE¨HU HÇE H ûD fEàHMÀ(E fE°HE HÇE¨ è)ØúÿH}ØHUÀHÏHCUÀèÇh/ ÀuiÛ@B ë3ÛHUØHúð HMÀHÿÂHÁHú Ô HIøHÂ'H+ÁHÀøHøí é¶ ûú tûô t3Àé¦ ]°HE°(E°LEàHE¨HU HÇE HUúD fE°HMÀ(E fEàHE HÇE¨ èb×úÿH}ØHUÀHÏHCUÀè h/ ÀuiÛè ë3ÛHUØHúr-HMÀHÿÂHÁHú rHIøHÂ'H+ÁHÀøHøw,è3®. ÃH$ HMðH3ÌèÁ. H¼$ HÄ ]Ãè/ Ìè/ ÌÌÌÌÌH\$Hl$Ht$H|$ DIùHÙM;Át?t$0Hl$(D E¶A¶Â ¶ÈEJ¿AÃAùAGÊ:(u=AÿÃD;Þt-IÿÀL;ÇuÏDÇ Hl$HÃHt$H|$ LCH\$Ã3Àëܸ Ç ëÍÌÌÌH\$DM;Át3H`±; @ A¶ EÓ A:u:AÿÃAûtIÿÀM;ÁuàDHÁÇ LAH\$Ã3ÀHÁLAH\$ø HÁH\$Ç LAÃÌÌÌÌÌÌÌÌÌÌÌÌÌH\$H|$DMÙM;Át(\$0H|$(fAÂD¶8E8uCAÿÂD;Ót#IÿÀM;ÃuãDHÁÇ LAH\$H|$Ã3ÀHÁLAH\$H|$ø HÁH\$H|$Ç LAÃÌ·ARLÁ¹ f;Áw&·ÐfÁàfÐfÒfAPRE Éx¹ÿÿ ·ÂA+É;Á~¸ ÃAÁ·Ê÷Ø;È|îfAѸç fAPRf;ÐwÛ3ÀÃÌH\$Ht$H|$ UATAUAVAWH¬$0ýÿÿHìÐ A8MðÿÈHÚHñ=µ K= HL=7 úÿL-0ì Ç ¿÷ÿ L¯; I¹Lɳ; A¸ I¸ÿÿÿÿÿÿÿIÏH ì E3äÿáI;Ö ÷ ¸³ é2, I;Ö Ç ¸© é, I;Ö ¸Z é, I;Ö ¸Y éù+ I;Ö Û ¸W éæ+ I;Ö ¸Q éÓ+ I;Ö ó ¸R éÀ+ I;Ö à ¸P é+ I;Ö î ¸N é+ I;Ö ? ¸L é+ I;Ö ¸; ét+ I;Ö ±' |