Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Feb. 1, 2024, 7:59 a.m. | Feb. 1, 2024, 8:04 a.m. |
-
rty25.exe "C:\Users\test22\AppData\Local\Temp\rty25.exe"
660
Name | Response | Post-Analysis Lookup |
---|---|---|
apps.identrust.com |
CNAME
a1952.dscq.akamai.net
CNAME
identrust.edgesuite.net
|
23.67.53.27 |
i.alie3ksgaa.com | 154.92.15.189 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49166 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49163 154.92.15.189:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=i.alie3ksgaa.com | e3:88:72:04:24:5c:12:17:a4:e2:c1:d9:33:f0:d9:60:91:71:d3:dc |
TLSv1 192.168.56.103:49165 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49172 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49173 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49167 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49178 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49169 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49176 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49182 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49175 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49179 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49168 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49181 154.92.15.189:443 |
None | None | None |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
pdb_path | wusa.pdb |
resource name | MUI |
resource name | WEVT_TEMPLATE |
request | GET http://apps.identrust.com/roots/dstrootcax3.p7c |
section | {u'size_of_data': u'0x00015000', u'virtual_address': u'0x00038000', u'entropy': 7.3971931278824155, u'name': u'.rsrc', u'virtual_size': u'0x00015000'} | entropy | 7.39719312788 | description | A section with a high entropy has been found | |||||||||
entropy | 0.282352941176 | description | Overall entropy of this PE file is high |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob |