Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | June 9, 2024, 9:10 a.m. | June 9, 2024, 9:19 a.m. |
-
-
-
svchost.exe "C:\Users\test22\AppData\Local\Temp\Delivery%2006.exe"
2252
-
-
-
-
firefox.exe "C:\Program Files\Mozilla Firefox\Firefox.exe"
2816
-
-
explorer.exe C:\Windows\Explorer.EXE
1236
IP Address | Status | Action |
---|---|---|
116.50.37.244 | Active | Moloch |
154.215.72.110 | Active | Moloch |
164.124.101.2 | Active | Moloch |
195.110.124.133 | Active | Moloch |
202.172.28.202 | Active | Moloch |
45.33.6.223 | Active | Moloch |
46.30.213.191 | Active | Moloch |
66.29.149.46 | Active | Moloch |
85.159.66.93 | Active | Moloch |
91.195.240.94 | Active | Moloch |
Suricata Alerts
Suricata TLS
No Suricata TLS
request | POST http://www.3xfootball.com/fo8o/ |
request | GET http://www.3xfootball.com/fo8o/?5R=IhZyPQIGe6uK3zPwwQVGm4hCASyaX3xlW2eS79Xk6ut4afzj0LiRHBqZsEmyTx+18GfGhVOagMos+c9dx/PGjLGAfpOvJ7U3hUqpnKd0zHv/hQdGhX4G3JlCydyJ23yerjxn4r8=&ERg=Lbajlol-F3v |
request | GET http://www.sqlite.org/2022/sqlite-dll-win32-x86-3380000.zip |
request | POST http://www.kasegitai.tokyo/fo8o/ |
request | GET http://www.kasegitai.tokyo/fo8o/?5R=0LNqIGaAWMhMIMLOr1FzuAu+QFTp+Isr9lFre+yu3/9GvRNYi1uHghhDsQ/pqDAQ+wkUrFUIurr7TLyDqzId9vCn3h40hICDSYZjejM1bTxHHnFMxARLyMCZMUhSp6GMEGHL0HI=&ERg=Lbajlol-F3v |
request | POST http://www.goldenjade-travel.com/fo8o/ |
request | GET http://www.goldenjade-travel.com/fo8o/?5R=LFKqyrcu7g1NCa8bIVnmntQ0zrEKrQSprIMLtaWgKJ9bBKQr4dsn0J7ZoYUgIJ+R6Sel8OhXEcHhC7LyM9bkgjIIu2U6i6kbe5asCJcEX28JEcHJIWfCjODnuc7OiogdzaMrHf8=&ERg=Lbajlol-F3v |
request | POST http://www.antonio-vivaldi.mobi/fo8o/ |
request | GET http://www.antonio-vivaldi.mobi/fo8o/?5R=PTl5gU/3CD/Xhg5KAVLGoeqWcilDUK5FTZuVmm6gfrwSjnBrSraU5xyBGUoA1k9xMbAGIU7PLJqf1PTsNd74L3d6+NgzbyGN2pTsiSyIeh1B8hC/nFfIu9UZrk9ku3J39HvVUu8=&ERg=Lbajlol-F3v |
request | POST http://www.magmadokum.com/fo8o/ |
request | GET http://www.magmadokum.com/fo8o/?5R=qL3nKp+YSjoaTomnND+fiETGbzpIgkHGMW8DXsDTZ4AADrD7Wpn1kxM1jYW2/C2WhyBblBh5NUSWrO5bZjyCcVkJYbxxq5QITB2h2xAyEikjbcoqZSmDOCeIE8A+B7hyBKIW8mw=&ERg=Lbajlol-F3v |
request | POST http://www.rssnewscast.com/fo8o/ |
request | GET http://www.rssnewscast.com/fo8o/?5R=x3jV/ECx7FuzXOI+6CNaISj98UIEn47HyCIVaqWvGMMqpfz0YC5wNp/pxM1zEFNKv4nPeGfT8/lZrDaJmccs4488pD+gaHK32CxgTEs5a2vdBlM4hQBa8nlaMF5vesFSU19kJNk=&ERg=Lbajlol-F3v |
request | POST http://www.techchains.info/fo8o/ |
request | GET http://www.techchains.info/fo8o/?5R=vefd0teQh+kbruh+iKW53cdcsQD4oFyRDgCUoL90YCYLczV+Hcc/VZ2eVbboy/u5EgiS3CnxBclKZHyNJ/4ALr08/A/SWk5lVGufGp2P4fG4f3GonqE4cYuaa0/JNC0RZIlRWrU=&ERg=Lbajlol-F3v |
request | POST http://www.elettrosistemista.zip/fo8o/ |
request | POST http://www.3xfootball.com/fo8o/ |
request | POST http://www.kasegitai.tokyo/fo8o/ |
request | POST http://www.goldenjade-travel.com/fo8o/ |
request | POST http://www.antonio-vivaldi.mobi/fo8o/ |
request | POST http://www.magmadokum.com/fo8o/ |
request | POST http://www.rssnewscast.com/fo8o/ |
request | POST http://www.techchains.info/fo8o/ |
request | POST http://www.elettrosistemista.zip/fo8o/ |
description | netbtugc.exe tried to sleep 164 seconds, actually delayed analysis time by 164 seconds |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ |
file | C:\Users\test22\AppData\Local\Chromium\User Data |
file | C:\Users\test22\AppData\Local\MapleStudio\ChromePlus\User Data |
file | C:\Users\test22\AppData\Local\Yandex\YandexBrowser\User Data |
file | C:\Users\test22\AppData\Local\Temp\sqlite3.dll |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup.vbs |
file | C:\Users\test22\AppData\Local\directory\.exe |
file | C:\Users\test22\AppData\Local\directory\.exe |
file | C:\Users\test22\AppData\Local\directory\.exe |
file | C:\Users\test22\AppData\Local\Temp\sqlite3.dll |
section | {u'size_of_data': u'0x0005b600', u'virtual_address': u'0x000c8000', u'entropy': 7.894681180861047, u'name': u'.rsrc', u'virtual_size': u'0x0005b424'} | entropy | 7.89468118086 | description | A section with a high entropy has been found | |||||||||
entropy | 0.31132879046 | description | Overall entropy of this PE file is high |
file | C:\Users\test22\AppData\Local\AVAST Software\Browser\User Data |
file | C:\Users\test22\AppData\Local\AVG\Browser\User Data |
Lionic | Trojan.Win32.Autoit.l!c |
CAT-QuickHeal | Trojan.AgentSM.S6640043 |
Skyhigh | BehavesLike.Win32.TrojanAitInject.tc |
ALYac | AIT:Trojan.Nymeria.6084 |
Cylance | Unsafe |
VIPRE | AIT:Trojan.Nymeria.6084 |
Sangfor | Trojan.Win32.Autoit.Vsfr |
BitDefender | AIT:Trojan.Nymeria.6084 |
Arcabit | AIT:Trojan.Nymeria.D17C4 [many] |
VirIT | Trojan.Win32.AutoIt_Heur.A |
Symantec | Trojan.Gen.2 |
Elastic | malicious (high confidence) |
ESET-NOD32 | a variant of Win32/Injector.Autoit.GBA |
APEX | Malicious |
McAfee | Artemis!132E9CB76DEF |
Avast | Win32:Malware-gen |
Kaspersky | Trojan-Spy.Win32.Noon.bglv |
Alibaba | Trojan:Win32/AutoitInject.a1bf3e35 |
MicroWorld-eScan | AIT:Trojan.Nymeria.6084 |
Emsisoft | AIT:Trojan.Nymeria.6084 (B) |
McAfeeD | ti!B79F9BFE9B5E |
FireEye | AIT:Trojan.Nymeria.6084 |
Sophos | Troj/AutoIt-DGJ |
Ikarus | Win32.Outbreak |
Detected | |
MAX | malware (ai score=86) |
Kingsoft | Win32.Trojan-Spy.Noon.bglv |
Gridinsoft | Ransom.Win32.Sabsik.sa |
Microsoft | Trojan:Win32/AutoitInject.OWAA!MTB |
ZoneAlarm | Trojan-Spy.Win32.Noon.bglv |
GData | AIT:Trojan.Nymeria.6084 (2x) |
Varist | W32/AutoIt.YE.gen!Eldorado |
DeepInstinct | MALICIOUS |
VBA32 | Trojan.Autoit.F |
Malwarebytes | Trojan.Injector.AutoIt |
Panda | Trj/CI.A |
TrendMicro-HouseCall | TROJ_GEN.F0D1C00F524 |
Fortinet | AutoIt/Injector.FZW!tr |
AVG | Win32:Malware-gen |
Paloalto | generic.ml |
alibabacloud | Trojan[spy]:Win/AutoitInject.OIZO3DGW |