Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | March 28, 2024, 7:46 a.m. | March 28, 2024, 7:49 a.m. |
-
-
setup.exe "C:\Users\test22\AppData\Local\Temp\setup.exe"
2772
-
Name | Response | Post-Analysis Lookup |
---|---|---|
yigeyo.xyz | 185.117.88.231 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49163 -> 185.117.88.231:80 | 2011227 | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) | Potentially Bad Traffic |
TCP 185.117.88.231:80 -> 192.168.56.103:49163 | 2018959 | ET POLICY PE EXE or DLL Windows file download HTTP | Potential Corporate Privacy Violation |
Suricata TLS
No Suricata TLS
section | .ndata |
request | GET http://yigeyo.xyz/21_2/huge.dat |
file | C:\Users\test22\AppData\Roaming\Pinball\Pinball.exe |
file | C:\Users\test22\AppData\Local\Temp\setup.exe |
file | C:\Users\test22\AppData\Local\Temp\nsrC2FF.tmp\INetC.dll |
file | C:\Users\test22\AppData\Roaming\Pinball\libEGL.dll |
file | C:\Users\test22\AppData\Roaming\Pinball\Snetchball.exe |
file | C:\Users\test22\AppData\Roaming\Pinball\libGLESv2.dll |
file | C:\Users\test22\AppData\Roaming\Pinball\chrome_elf.dll |
file | C:\Users\test22\AppData\Roaming\Pinball\d3dcompiler_47.dll |
file | C:\Users\test22\AppData\Local\Temp\nsrC2FF.tmp\nsProcess.dll |
file | C:\Users\test22\AppData\Roaming\Pinball\Del.exe |
file | C:\Users\test22\AppData\Roaming\Pinball\Xilium.CefGlue.dll |
file | C:\Users\test22\AppData\Roaming\Pinball\Ionic.Zip.dll |
file | C:\Users\test22\AppData\Roaming\Pinball\Newtonsoft.Json.dll |
file | C:\Users\test22\AppData\Roaming\Pinball\Newtonsoft.Json.dll |
file | C:\Users\test22\AppData\Roaming\Pinball\Pinball.exe |
file | C:\Users\test22\AppData\Roaming\Pinball\libEGL.dll |
file | C:\Users\test22\AppData\Roaming\Pinball\chrome_elf.dll |
file | C:\Users\test22\AppData\Roaming\Pinball\Snetchball.exe |
file | C:\Users\test22\AppData\Local\Temp\setup.exe |
file | C:\Users\test22\AppData\Roaming\Pinball\Ionic.Zip.dll |
file | C:\Users\test22\AppData\Roaming\Pinball\libGLESv2.dll |
file | C:\Users\test22\AppData\Roaming\Pinball\Del.exe |
file | C:\Users\test22\AppData\Roaming\Pinball\Xilium.CefGlue.dll |
file | C:\Users\test22\AppData\Local\Temp\nsrC2FF.tmp\INetC.dll |
file | C:\Users\test22\AppData\Local\Temp\nsrC2FF.tmp\nsProcess.dll |
file | C:\Users\test22\AppData\Roaming\Pinball\d3dcompiler_47.dll |
Kaspersky | UDS:DangerousObject.Multi.Generic |
ZoneAlarm | UDS:DangerousObject.Multi.Generic |
DeepInstinct | MALICIOUS |
CrowdStrike | win/malicious_confidence_70% (W) |