Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | June 7, 2024, 9:35 a.m. | June 7, 2024, 9:49 a.m. |
-
WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE" C:\Users\test22\AppData\Local\Temp\lionsarekingogthejunglewhorulestheentireforestandlionsgreattounderstandtheyaregreattoundersetandlionsarekindofthejungle__lionsarekingofjungle.doc
2544
Name | Response | Post-Analysis Lookup |
---|---|---|
www1.militarydefensenow.com | 34.192.83.212 |
Suricata Alerts
Suricata TLS
No Suricata TLS
suspicious_features | Connection to IP address | suspicious_request | GET http://67.207.166.175/T0406W/lsass.exe |
request | GET http://67.207.166.175/T0406W/lsass.exe |
file | C:\Users\test22\AppData\Local\Temp\~$onsarekingogthejunglewhorulestheentireforestandlionsgreattounderstandtheyaregreattoundersetandlionsarekindofthejungle__lionsarekingofjungle.doc |
host | 67.207.166.175 |