Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | March 25, 2024, 9:17 a.m. | March 25, 2024, 9:22 a.m. |
-
-
-
iexplore.exe "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:2620 CREDAT:145409
2700
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
ssl.gstatic.com | 172.217.26.227 | |
accounts.google.com | 64.233.188.84 | |
www.youtube.com |
CNAME
youtube-ui.l.google.com
|
142.250.206.206 |
www.google.com | 142.250.206.196 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49166 142.251.222.206:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 | CN=*.google.com | 23:75:5e:3d:ea:9f:a0:42:86:8d:14:ae:43:04:f0:b2:91:0b:da:cf |
TLSv1 192.168.56.101:49170 74.125.23.84:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 | CN=accounts.google.com | 89:5f:a0:36:ad:7d:38:10:5b:58:71:f2:d2:8b:75:99:05:74:ed:fd |
TLSv1 192.168.56.101:49171 74.125.23.84:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 | CN=accounts.google.com | 89:5f:a0:36:ad:7d:38:10:5b:58:71:f2:d2:8b:75:99:05:74:ed:fd |
TLSv1 192.168.56.101:49172 216.58.203.67:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 | CN=*.gstatic.com | f3:56:10:42:a8:3c:bf:f5:89:9c:4c:c0:f8:e3:dc:c4:1c:e9:34:9e |
TLSv1 192.168.56.101:49167 142.251.222.206:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 | CN=*.google.com | 23:75:5e:3d:ea:9f:a0:42:86:8d:14:ae:43:04:f0:b2:91:0b:da:cf |
TLSv1 192.168.56.101:49176 74.125.23.84:443 |
None | None | None |
TLSv1 192.168.56.101:49175 74.125.23.84:443 |
None | None | None |
TLSv1 192.168.56.101:49173 216.58.203.67:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 | CN=*.gstatic.com | f3:56:10:42:a8:3c:bf:f5:89:9c:4c:c0:f8:e3:dc:c4:1c:e9:34:9e |
TLSv1 192.168.56.101:49177 142.250.204.68:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 | CN=www.google.com | 32:a3:19:7a:6b:d5:c7:5e:ca:7c:c8:08:79:14:56:fd:fc:3e:06:f0 |
TLSv1 192.168.56.101:49178 142.250.204.68:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 | CN=www.google.com | 32:a3:19:7a:6b:d5:c7:5e:ca:7c:c8:08:79:14:56:fd:fc:3e:06:f0 |
request | GET http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml |
request | GET https://www.youtube.com/account |
request | GET https://accounts.google.com/ServiceLogin?service=youtube&uilel=3&passive=true&continue=https%3A%2F%2Fwww.youtube.com%2Fsignin%3Faction_handle_signin%3Dtrue%26app%3Ddesktop%26hl%3Dko%26next%3Dhttps%253A%252F%252Fwww.youtube.com%252Faccount%26feature%3Dredirect_login&hl=ko |
request | GET https://accounts.google.com/InteractiveLogin?continue=https://www.youtube.com/signin?action_handle_signin%3Dtrue%26app%3Ddesktop%26hl%3Dko%26next%3Dhttps%253A%252F%252Fwww.youtube.com%252Faccount%26feature%3Dredirect_login&hl=ko&passive=true&service=youtube&uilel=3&ifkv=ARZ0qKKXo7ZF9PtGz47baT8UVWdFT0eYzdn5It88GOwmzA_LWU4tMF7c7RwCmN7IKO4ExzugA_5g9A |
request | GET https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fwww.youtube.com%2Fsignin%3Faction_handle_signin%3Dtrue%26app%3Ddesktop%26hl%3Dko%26next%3Dhttps%253A%252F%252Fwww.youtube.com%252Faccount%26feature%3Dredirect_login&hl=ko&ifkv=ARZ0qKK-VHHnZwpNm7p5uN6Dl_ZvvZmCoYYXn02kHS5p_HaZ7ePY9EYzutDBHK0NXYfixHOOw7mtlw&passive=true&service=youtube&uilel=3&flowName=WebLiteSignIn&flowEntry=ServiceLogin&dsh=S-553555903%3A1711326027463105 |
request | GET https://accounts.google.com/_/bscframe |
request | GET https://ssl.gstatic.com/images/branding/googlelogo/2x/googlelogo_color_74x24dp.png |
request | GET https://accounts.google.com/generate_204?vBL53Q |
request | GET https://accounts.google.com/favicon.ico |
request | GET https://www.google.com/favicon.ico |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
cmdline | "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:2620 CREDAT:145409 |
cmdline | "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome |
host | 117.18.232.200 |
Bkav | W32.Common.844F8942 |
Lionic | Trojan.Win64.Injects.ts93 |
Cynet | Malicious (score: 100) |
Skyhigh | BehavesLike.Win32.Genericuh.ch |
ALYac | Trojan.GenericKD.72075749 |
Cylance | unsafe |
VIPRE | Trojan.GenericKD.72075749 |
Sangfor | Virus.Win32.Save.a |
BitDefender | Trojan.GenericKD.72075749 |
Arcabit | Trojan.Generic.D44BC9E5 |
Symantec | ML.Attribute.HighConfidence |
Elastic | malicious (high confidence) |
APEX | Malicious |
McAfee | Artemis!4E937DB554CF |
Avast | Win32:Malware-gen |
Kaspersky | UDS:DangerousObject.Multi.Generic |
MicroWorld-eScan | Trojan.GenericKD.72075749 |
Emsisoft | Trojan.GenericKD.72075749 (B) |
F-Secure | Heuristic.HEUR/AGEN.1372185 |
TrendMicro | Trojan.Win32.AMADEY.YXECUZ |
FireEye | Generic.mg.4e937db554cf1826 |
Sophos | Mal/Generic-S |
Ikarus | Trojan.Win32.Acll |
Jiangmin | Trojan.Script.awbz |
Avira | HEUR/AGEN.1372185 |
MAX | malware (ai score=85) |
Gridinsoft | Trojan.Win32.Agent.ca |
Microsoft | Trojan:Win32/Acll |
ZoneAlarm | UDS:DangerousObject.Multi.Generic |
GData | Trojan.GenericKD.72075749 |
Varist | W32/AutoIt.XQ.gen!Eldorado |
DeepInstinct | MALICIOUS |
VBA32 | BScope.Trojan.Script |
Malwarebytes | Generic.Malware/Suspicious |
TrendMicro-HouseCall | Trojan.Win32.AMADEY.YXECUZ |
SentinelOne | Static AI - Malicious PE |
MaxSecure | Trojan.Malware.121218.susgen |
Fortinet | W32/PossibleThreat |
AVG | Win32:Malware-gen |