Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | June 15, 2024, 8:16 a.m. | June 15, 2024, 8:20 a.m. |
-
4.exe "C:\Users\test22\AppData\Local\Temp\4.exe"
1280
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 164.155.205.99:999 -> 192.168.56.103:49162 | 2400026 | ET DROP Spamhaus DROP Listed Traffic Inbound group 27 | Misc Attack |
Suricata TLS
No Suricata TLS
packer | Armadillo v1.71 |
host | 164.155.205.99 | |||
host | 94.177.131.249 |
service_name | phqghumeay | service_path | C:\Windows\Systemyso.exe |
dead_host | 192.168.56.101:50767 |
dead_host | 192.168.56.101:50801 |
dead_host | 192.168.56.103:21 |
dead_host | 192.168.56.101:50778 |
dead_host | 192.168.56.103:1433 |
dead_host | 192.168.56.103:19490 |