Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 14, 2024, 10:45 a.m. | Oct. 14, 2024, 10:55 a.m. |
-
-
DocuSign.exe "C:\Users\test22\AppData\Local\Temp\DocuSign.exe"
2552
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | _RDATA |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\libssl-1_1.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tk86t.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\VCRUNTIME140.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\libffi-7.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl86t.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\python310.dll |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\libcrypto-1_1.dll |
VirIT | Trojan.Win64.Genus.FYE |
Elastic | malicious (moderate confidence) |
ESET-NOD32 | a variant of Win32/GenCBL.FHT |
APEX | Malicious |
Detected | |
Malwarebytes | Agent.Spyware.Stealer.DDS |
Ikarus | Trojan.Win32.Generic |
Fortinet | W32/GenCBL.FHT!tr |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macCroatian.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp850.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\ascii.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp932.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\ebcdic.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\koi8-u.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-15.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\jis0212.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp1257.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-9.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-6.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp775.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-3.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macTurkish.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp866.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp861.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\ksc5601.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp1256.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-4.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-13.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\euc-kr.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp936.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-5.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-2.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macThai.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\jis0208.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso2022-kr.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\symbol.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp862.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macGreek.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\tis-620.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macJapan.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-1.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macIceland.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp865.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-16.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\gb1988.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp1258.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-8.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp864.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp869.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\big5.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp737.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macDingbats.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\koi8-r.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macCentEuro.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macRomania.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\euc-cn.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp852.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\jis0201.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macCroatian.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\America\Managua |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Asia\Ulaanbaatar |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\msgs\sk.msg |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\Crypto\Util\_cpuid_c.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\PRC |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\msgs\es_hn.msg |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Pacific\Pago_Pago |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Asia\Chongqing |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\America\Santa_Isabel |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\UTC |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\msgs\es_bo.msg |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\America\Blanc-Sablon |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Africa\Djibouti |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Iceland |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Africa\Ouagadougou |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\GMT |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\msgs\es_gt.msg |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Europe\Busingen |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\Crypto\Cipher\_raw_cbc.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-5.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\base_library.zip |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\America\Argentina\Tucuman |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\msgs\be.msg |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\msgs\es_pa.msg |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tk\unsupported.tcl |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Africa\Lagos |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\America\Ensenada |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Pacific\Saipan |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Pacific\Wake |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\msgs\de.msg |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Brazil\Acre |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-16.enc |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\Crypto\PublicKey\_ec_ws.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Africa\Abidjan |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\_hashlib.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Turkey |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tk\dialog.tcl |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Africa\Harare |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Antarctica\Palmer |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\America\Nassau |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\logo.jpg |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\Crypto\Hash\_BLAKE2b.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\Crypto\Hash\_ghash_portable.pyd |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Etc\GMT+2 |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Etc\GMT+3 |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\msgs\es_ni.msg |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Etc\GMT+1 |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\America\Port_of_Spain |
file | C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Etc\GMT+7 |