Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | May 28, 2024, 9:33 a.m. | May 28, 2024, 9:35 a.m. |
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
104.149.139.42 | Active | Moloch |
116.12.180.237 | Active | Moloch |
128.31.0.39 | Active | Moloch |
131.188.40.189 | Active | Moloch |
154.35.175.225 | Active | Moloch |
176.123.3.222 | Active | Moloch |
185.97.32.34 | Active | Moloch |
192.121.44.26 | Active | Moloch |
192.46.225.58 | Active | Moloch |
193.23.244.244 | Active | Moloch |
199.58.81.140 | Active | Moloch |
86.59.21.38 | Active | Moloch |
87.151.147.113 | Active | Moloch |
89.163.164.202 | Active | Moloch |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.101:49174 192.121.44.26:9001 |
CN=www.kmsevoanps.com | CN=www.zkcn7rgvovblj52r6lef.net | 6b:e5:ac:76:50:79:2e:03:e9:94:13:e0:a6:8d:09:a5:03:9a:d5:f3 |
TLS 1.2 192.168.56.101:49175 199.58.81.140:443 |
CN=www.gnmd2gvjeipnopwemui3.com | CN=www.rvkj3a73jvrcd5.net | 5e:47:22:34:cf:3e:63:ab:5a:73:3f:70:de:89:5b:e0:01:e3:88:a7 |
TLS 1.2 192.168.56.101:49178 193.23.244.244:443 |
CN=www.nc4fiighnz.com | CN=www.krdkrcttf37.net | 85:ee:dc:f6:23:f9:c0:67:af:06:45:53:0b:f5:58:d7:0f:45:c9:ff |
TLS 1.2 192.168.56.101:49182 131.188.40.189:443 |
CN=www.uhlqmuy6t3oe3hhf.com | CN=www.amm5v4wst.net | db:7a:ee:da:d0:fc:d2:72:2a:b4:1c:b3:7d:b8:26:58:df:50:ea:ef |
TLS 1.2 192.168.56.101:49179 116.12.180.237:443 |
CN=www.pd2obsqq62wrucno.com | CN=www.kokyf72j2oxz.net | 69:7f:19:51:5d:d8:67:50:be:0b:90:f2:b4:b6:9e:bb:76:17:49:dc |
TLS 1.2 192.168.56.101:49181 89.163.164.202:443 |
CN=www.ujmqkjo45qb.com | CN=www.x2sipc6jkict7z2.net | 49:f9:cb:b5:9b:f9:4a:ad:41:ef:72:d2:0d:9d:83:3b:ef:24:9f:98 |
resource name | AFX_DIALOG_LAYOUT |
name | RT_ICON | language | LANG_JAPANESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02a34ec0 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_JAPANESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02a34ec0 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_JAPANESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02a34ec0 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_JAPANESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02a34ec0 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_JAPANESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02a34ec0 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_JAPANESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02a34ec0 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_JAPANESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_DEFAULT | offset | 0x02a34ec0 | size | 0x00000468 | ||||||||||||||||||
name | RT_STRING | language | LANG_JAPANESE | filetype | data | sublanguage | SUBLANG_DEFAULT | offset | 0x02a38258 | size | 0x0000028a | ||||||||||||||||||
name | RT_STRING | language | LANG_JAPANESE | filetype | data | sublanguage | SUBLANG_DEFAULT | offset | 0x02a38258 | size | 0x0000028a | ||||||||||||||||||
name | RT_STRING | language | LANG_JAPANESE | filetype | data | sublanguage | SUBLANG_DEFAULT | offset | 0x02a38258 | size | 0x0000028a | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_JAPANESE | filetype | data | sublanguage | SUBLANG_DEFAULT | offset | 0x02a35328 | size | 0x00000068 |
file | C:\ProgramData\Drivers\csrss.exe |
section | {u'size_of_data': u'0x001baa00', u'virtual_address': u'0x00018000', u'entropy': 7.994785189056425, u'name': u'.data', u'virtual_size': u'0x02a16380'} | entropy | 7.99478518906 | description | A section with a high entropy has been found | |||||||||
entropy | 0.934794086589 | description | Overall entropy of this PE file is high |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
buffer | Buffer with sha1: d28efb268620185702b8d301d25e4dd45dcf4414 |
host | 104.149.139.42 | |||
host | 116.12.180.237 | |||
host | 128.31.0.39 | |||
host | 131.188.40.189 | |||
host | 154.35.175.225 | |||
host | 176.123.3.222 | |||
host | 185.97.32.34 | |||
host | 192.121.44.26 | |||
host | 192.46.225.58 | |||
host | 193.23.244.244 | |||
host | 199.58.81.140 | |||
host | 86.59.21.38 | |||
host | 87.151.147.113 | |||
host | 89.163.164.202 |
reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\CSRSS | reg_value | "C:\ProgramData\Drivers\csrss.exe" |