Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Jan. 29, 2024, 7:55 a.m. | Jan. 29, 2024, 8:04 a.m. |
-
-
toolspub1.exe "C:\Users\test22\AppData\Local\Temp\toolspub1.exe"
2768 -
7b0d48dbbf50fe239f1097f5d01c2a6d.exe "C:\Users\test22\AppData\Local\Temp\7b0d48dbbf50fe239f1097f5d01c2a6d.exe"
2816 -
rty25.exe "C:\Users\test22\AppData\Local\Temp\rty25.exe"
2864 -
FirstZ.exe "C:\Users\test22\AppData\Local\Temp\FirstZ.exe"
2908
-
Name | Response | Post-Analysis Lookup |
---|---|---|
apps.identrust.com |
CNAME
a1952.dscq.akamai.net
CNAME
identrust.edgesuite.net
|
23.50.121.137 |
i.alie3ksgaa.com | 154.92.15.189 | |
pastebin.com | 172.67.34.170 | |
zeph-eu2.nanopool.org | 51.195.43.17 |
Suricata Alerts
Suricata TLS
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
request | GET http://apps.identrust.com/roots/dstrootcax3.p7c |
file | C:\Users\test22\AppData\Local\Temp\toolspub1.exe |
file | C:\Users\test22\AppData\Local\Temp\FirstZ.exe |
file | C:\Users\test22\AppData\Local\Temp\7b0d48dbbf50fe239f1097f5d01c2a6d.exe |
file | C:\Users\test22\AppData\Local\Temp\rty25.exe |
file | C:\Users\test22\AppData\Local\Temp\toolspub1.exe |
file | C:\Users\test22\AppData\Local\Temp\7b0d48dbbf50fe239f1097f5d01c2a6d.exe |
file | C:\Users\test22\AppData\Local\Temp\rty25.exe |
file | C:\Users\test22\AppData\Local\Temp\FirstZ.exe |
file | C:\Users\test22\AppData\Local\Temp\7b0d48dbbf50fe239f1097f5d01c2a6d.exe |
file | C:\Users\test22\AppData\Local\Temp\toolspub1.exe |
section | {u'size_of_data': u'0x00779c00', u'virtual_address': u'0x00002000', u'entropy': 7.8509057969848675, u'name': u'.text', u'virtual_size': u'0x00779ae4'} | entropy | 7.85090579698 | description | A section with a high entropy has been found | |||||||||
entropy | 0.999738801097 | description | Overall entropy of this PE file is high |