Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Jan. 13, 2024, 7:15 p.m. | Jan. 13, 2024, 7:24 p.m. |
-
-
-
-
-
chcp.com chcp 1251
1400 -
schtasks.exe schtasks /create /tn "MalayamaraUpdate" /tr "'C:\Users\test22\AppData\Local\Temp\Updater.exe'" /sc minute /mo 30 /F
2256
-
-
-
-
rty25.exe "C:\Users\test22\AppData\Local\Temp\rty25.exe"
2716
-
Name | Response | Post-Analysis Lookup |
---|---|---|
apps.identrust.com |
CNAME
a1952.dscq.akamai.net
CNAME
identrust.edgesuite.net
|
23.67.53.27 |
i.alie3ksgaa.com | 154.92.15.189 |
Suricata Alerts
Suricata TLS
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
suspicious_features | Connection to IP address | suspicious_request | GET http://185.172.128.90/cpa/ping.php?substr=seven&s=ab | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://185.172.128.53/syncUpd.exe |
request | GET http://185.172.128.90/cpa/ping.php?substr=seven&s=ab |
request | GET http://185.172.128.53/syncUpd.exe |
request | GET http://apps.identrust.com/roots/dstrootcax3.p7c |
file | C:\Users\test22\AppData\Local\Temp\nswF2BD.tmp\INetC.dll |
file | C:\Users\test22\AppData\Roaming\Temp\Task.bat |
file | C:\Users\test22\AppData\Local\Temp\InstallSetup7.exe |
file | C:\Users\test22\AppData\Local\Temp\31839b57a4f11171d6abc8bbc4451ee4.exe |
file | C:\Users\test22\AppData\Local\Temp\BroomSetup.exe |
file | C:\Users\test22\AppData\Local\Temp\rty25.exe |
cmdline | schtasks /create /tn "MalayamaraUpdate" /tr "'C:\Users\test22\AppData\Local\Temp\Updater.exe'" /sc minute /mo 30 /F |
file | C:\Users\test22\AppData\Local\Temp\InstallSetup7.exe |
file | C:\Users\test22\AppData\Local\Temp\31839b57a4f11171d6abc8bbc4451ee4.exe |
file | C:\Users\test22\AppData\Local\Temp\rty25.exe |
file | C:\Users\test22\AppData\Local\Temp\SandboxieInstall.exe |
file | C:\Users\test22\AppData\Local\Temp\BroomSetup.exe |
file | C:\Users\test22\AppData\Local\Temp\202005191702_6d173b9549ce4fe1e5ada5ab9ce0bfff5d9569f19e7fa916db5c8d4f0dace63b_setup_nwc275a_demo.exe |
file | C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\winamp58_3660_beta_full_en-us[1].exe |
file | C:\Users\test22\AppData\Local\Temp\nstF8B9.tmp |
file | C:\Users\test22\AppData\Local\Temp\31839b57a4f11171d6abc8bbc4451ee4.exe |
file | C:\Users\test22\AppData\Local\Temp\InstallSetup7.exe |
file | C:\Users\test22\AppData\Local\Temp\nswF2BD.tmp\INetC.dll |
file | C:\Users\test22\AppData\Local\Temp\newrock2.exe |