Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Aug. 9, 2024, 7:47 a.m. | Aug. 9, 2024, 7:55 a.m. |
-
-
bsso_tor.exe "C:\Users\test22\AppData\Local\Temp\\bsso_tor.exe"
2712
-
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 199.195.253.180:9000 -> 192.168.56.101:49170 | 2520069 | ET TOR Known Tor Exit Node Traffic group 70 | Misc Attack |
TCP 199.195.253.180:9000 -> 192.168.56.101:49170 | 2522069 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 70 | Misc Attack |
TCP 178.33.36.64:8080 -> 192.168.56.101:49175 | 2522257 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 258 | Misc Attack |
TCP 145.239.136.129:8080 -> 192.168.56.101:49171 | 2522193 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 194 | Misc Attack |
TCP 84.240.60.234:9001 -> 192.168.56.101:49172 | 2522787 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 788 | Misc Attack |
TCP 137.226.34.45:9008 -> 192.168.56.101:49174 | 2522169 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 170 | Misc Attack |
TCP 137.226.34.45:9008 -> 192.168.56.101:49182 | 2522169 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 170 | Misc Attack |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.3 192.168.56.101:49170 199.195.253.180:9000 |
None | None | None |
TLS 1.3 192.168.56.101:49175 178.33.36.64:8080 |
None | None | None |
TLS 1.3 192.168.56.101:49171 145.239.136.129:8080 |
None | None | None |
TLS 1.3 192.168.56.101:49172 84.240.60.234:9001 |
None | None | None |
TLS 1.3 192.168.56.101:49177 178.33.36.64:8080 |
None | None | None |
TLS 1.3 192.168.56.101:49174 137.226.34.45:9008 |
None | None | None |
TLS 1.3 192.168.56.101:49180 178.33.36.64:8080 |
None | None | None |
TLS 1.3 192.168.56.101:49178 137.226.34.45:9008 |
None | None | None |
TLS 1.3 192.168.56.101:49182 137.226.34.45:9008 |
None | None | None |
ip | 137.226.34.45 |
ip | 145.239.136.129 |
ip | 178.33.36.64 |
ip | 199.195.253.180 |
ip | 84.240.60.234 |
file | C:\Users\test22\AppData\Local\Temp\bsso_tor.exe |
section | {u'size_of_data': u'0x00279600', u'virtual_address': u'0x00012000', u'entropy': 7.999801760102147, u'name': u'.data', u'virtual_size': u'0x0027c120'} | entropy | 7.9998017601 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00003600', u'virtual_address': u'0x0028f000', u'entropy': 7.898432288310628, u'name': u'.rsrc', u'virtual_size': u'0x00003548'} | entropy | 7.89843228831 | description | A section with a high entropy has been found | |||||||||
entropy | 0.974928229665 | description | Overall entropy of this PE file is high |
host | 137.226.34.45 | |||
host | 145.239.136.129 | |||
host | 178.33.36.64 | |||
host | 199.195.253.180 | |||
host | 84.240.60.234 |
file | C:\Users\test22\AppData\Local\Temp\bsso_tor.exe |
file | C:\Users\test22\AppData\Roaming\tor\cached-certs |
file | C:\Users\test22\AppData\Roaming\tor\cached-consensus |
file | C:\Users\test22\AppData\Roaming\tor\cached-descriptors |
file | C:\Users\test22\AppData\Roaming\tor\geoip |
file | C:\Users\test22\AppData\Roaming\tor\state |
file | C:\Users\test22\AppData\Roaming\tor\torrc |