Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | July 4, 2024, 10:05 a.m. | July 4, 2024, 10:08 a.m. |
-
moon.txt.exe "C:\Users\test22\AppData\Local\Temp\moon.txt.exe"
2556
Name | Response | Post-Analysis Lookup |
---|---|---|
geoplugin.net | 178.237.33.50 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49168 -> 191.101.130.177:6903 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49166 -> 191.101.130.177:6903 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49167 -> 191.101.130.177:6903 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49162 -> 191.101.130.177:6903 | 2036594 | ET JA3 Hash - Remcos 3.x/4.x TLS Connection | Malware Command and Control Activity Detected |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.3 192.168.56.101:49168 191.101.130.177:6903 |
None | None | None |
TLS 1.3 192.168.56.101:49166 191.101.130.177:6903 |
None | None | None |
TLS 1.3 192.168.56.101:49167 191.101.130.177:6903 |
None | None | None |
TLS 1.3 192.168.56.101:49162 191.101.130.177:6903 |
None | None | None |
section | .gfids |
suspicious_features | GET method with no useragent header | suspicious_request | GET http://geoplugin.net/json.gp |
request | GET http://geoplugin.net/json.gp |
description | moon.txt.exe tried to sleep 448 seconds, actually delayed analysis time by 448 seconds |
host | 191.101.130.177 |
Bkav | W32.Common.19ECC1D2 |
Lionic | Trojan.Win32.Remcos.m!c |
Elastic | Windows.Trojan.Remcos |
Cynet | Malicious (score: 100) |
CAT-QuickHeal | Backdoor.RemcosIH.S31010159 |
Skyhigh | BehavesLike.Win32.Remcos.gh |
ALYac | Generic.Remcos.97550BDE |
Cylance | Unsafe |
VIPRE | Generic.Remcos.97550BDE |
Sangfor | Trojan.Win32.Save.a |
K7AntiVirus | Riskware ( 00584baa1 ) |
BitDefender | Generic.Remcos.97550BDE |
K7GW | Riskware ( 00584baa1 ) |
Cybereason | malicious.2c5285 |
Arcabit | Generic.Remcos.D17D0EBDE |
Baidu | Win32.Trojan.Kryptik.awm |
VirIT | Trojan.Win32.Genus.UED |
Symantec | ML.Attribute.HighConfidence |
ESET-NOD32 | Win32/Rescoms.V |
APEX | Malicious |
McAfee | Remcos-FDQO!076A4A72C528 |
Avast | Win32:RATX-gen [Trj] |
ClamAV | Win.Trojan.Remcos-9841897-0 |
Kaspersky | HEUR:Backdoor.Win32.Remcos.gen |
NANO-Antivirus | Trojan.Win32.Remcos.keikbt |
SUPERAntiSpyware | Trojan.Agent/Gen-Remcos |
MicroWorld-eScan | Generic.Remcos.97550BDE |
Rising | Backdoor.Remcos!1.BAC7 (CLASSIC) |
Emsisoft | Generic.Remcos.97550BDE (B) |
F-Secure | Backdoor.BDS/Backdoor.Gen |
DrWeb | Trojan.Siggen22.19832 |
Zillya | Trojan.Rescoms.Win32.1521 |
McAfeeD | Real Protect-LS!076A4A72C528 |
FireEye | Generic.mg.076a4a72c5285c9d |
Sophos | Mal/Remcos-B |
Ikarus | Backdoor.Remcos |
Jiangmin | Backdoor.Remcos.dyc |
Detected | |
Avira | BDS/Backdoor.Gen |
MAX | malware (ai score=85) |
Antiy-AVL | Trojan[Backdoor]/Win32.Rescoms.b |
Gridinsoft | Ransom.Win32.Wacatac.oa!s1 |
Microsoft | Backdoor:Win32/Remcos.GA!MTB |
ZoneAlarm | HEUR:Backdoor.Win32.Remcos.gen |
GData | Win32.Trojan.PSE.1OHYAG0 |
Varist | W32/Trojan.SMWB-4856 |
AhnLab-V3 | Backdoor/Win.Remcos.R625673 |
BitDefenderTheta | Gen:NN.ZexaF.36806.ECW@aub0MQfi |
DeepInstinct | MALICIOUS |
VBA32 | Backdoor.Remcos |