Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Dec. 18, 2023, 9:49 a.m. | Dec. 18, 2023, 10:03 a.m. |
-
WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Office15\WINWORD.EXE" C:\Users\test22\AppData\Local\Temp\microsoftprofiledeletedhistorycachecookieeverythingfromthepc.Doc
932
Name | Response | Post-Analysis Lookup |
---|---|---|
www.magssin.com | 167.86.119.6 |
Suricata Alerts
Suricata TLS
No Suricata TLS
suspicious_features | Connection to IP address | suspicious_request | GET http://198.46.178.135/3590/wlanext.exe |
request | GET http://198.46.178.135/3590/wlanext.exe |
file | C:\Users\test22\AppData\Local\Temp\~$crosoftprofiledeletedhistorycachecookieeverythingfromthepc.Doc |
host | 198.46.178.135 |