Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Oct. 4, 2024, 11:14 a.m. | Oct. 4, 2024, 11:17 a.m. |
Name | Response | Post-Analysis Lookup |
---|---|---|
sevtvx17ht.top | 80.66.81.78 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.56.103:52760 -> 164.124.101.2:53 | 2023883 | ET DNS Query to a *.top domain - Likely Hostile | Potentially Bad Traffic |
TCP 192.168.56.103:49164 -> 80.66.81.78:80 | 2023882 | ET INFO HTTP Request to a *.top domain | Potentially Bad Traffic |
TCP 192.168.56.103:49164 -> 80.66.81.78:80 | 2054350 | ET MALWARE Win32/Cryptbotv2 CnC Activity (POST) M4 | A Network Trojan was detected |
TCP 192.168.56.103:49163 -> 80.66.81.78:80 | 2054350 | ET MALWARE Win32/Cryptbotv2 CnC Activity (POST) M4 | A Network Trojan was detected |
TCP 192.168.56.103:49162 -> 80.66.81.78:80 | 2054350 | ET MALWARE Win32/Cryptbotv2 CnC Activity (POST) M4 | A Network Trojan was detected |
Suricata TLS
No Suricata TLS
suspicious_features | POST method with no referer header | suspicious_request | POST http://sevtvx17ht.top/v1/upload.php |
request | POST http://sevtvx17ht.top/v1/upload.php |
request | POST http://sevtvx17ht.top/v1/upload.php |
domain | sevtvx17ht.top | description | Generic top level domain TLD |
file | C:\Users\test22\AppData\Local\Temp\service123.exe |
file | C:\Users\test22\AppData\Local\Temp\LkwWQfCuAuZdmvADjZkd.dll |
section | {u'size_of_data': u'0x0006ae00', u'virtual_address': u'0x0069c000', u'entropy': 6.80263450437104, u'name': u'.reloc', u'virtual_size': u'0x0006ad40'} | entropy | 6.80263450437 | description | A section with a high entropy has been found |
Bkav | W32.AIDetectMalware |
CrowdStrike | win/malicious_confidence_90% (D) |
Elastic | malicious (high confidence) |
ESET-NOD32 | a variant of Win32/GenKryptik.HBZR |
APEX | Malicious |
Avast | Win32:CrypterX-gen [Trj] |
Rising | Trojan.Kryptik!8.8 (TFE:5:25KWoxie6RB) |
AhnLab-V3 | Infostealer/Win.CryptBot.C5677842 |
Malwarebytes | Trojan.MalPack |
Tencent | Win32.Trojan.Genkryptik.Ckjl |
AVG | Win32:CrypterX-gen [Trj] |