Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Nov. 11, 2024, 10:03 a.m. | Nov. 11, 2024, 10:24 a.m. |
-
wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\MONDAYconstraints.vbs
2540
Name | Response | Post-Analysis Lookup |
---|---|---|
paste.ee | 172.67.187.200 |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.56.101:59002 -> 164.124.101.2:53 | 2054041 | ET INFO Pastebin-like Service Domain in DNS Lookup (paste .ee) | Misc activity |
UDP 192.168.56.101:59002 -> 164.124.101.2:53 | 2054041 | ET INFO Pastebin-like Service Domain in DNS Lookup (paste .ee) | Misc activity |
UDP 192.168.56.101:59002 -> 164.124.101.2:53 | 2054041 | ET INFO Pastebin-like Service Domain in DNS Lookup (paste .ee) | Misc activity |
UDP 192.168.56.101:59002 -> 8.8.8.8:53 | 2054041 | ET INFO Pastebin-like Service Domain in DNS Lookup (paste .ee) | Misc activity |
UDP 192.168.56.101:59002 -> 8.8.8.8:53 | 2054041 | ET INFO Pastebin-like Service Domain in DNS Lookup (paste .ee) | Misc activity |
UDP 192.168.56.101:59002 -> 8.8.8.8:53 | 2054041 | ET INFO Pastebin-like Service Domain in DNS Lookup (paste .ee) | Misc activity |
UDP 192.168.56.101:59002 -> 8.8.8.8:53 | 2054041 | ET INFO Pastebin-like Service Domain in DNS Lookup (paste .ee) | Misc activity |
Suricata TLS
No Suricata TLS
Lionic | Trojan.Script.SAgent.4!c |
CTX | mp3.trojan.generic |
ALYac | Trojan.Generic.36895517 |
VIPRE | Trojan.Generic.36895517 |
Arcabit | Trojan.Generic.D232FB1D |
Symantec | ISB.Downloader!gen40 |
Avast | Script:SNH-gen [Trj] |
Kaspersky | HEUR:Trojan.VBS.SAgent.gen |
BitDefender | Trojan.Generic.36895517 |
NANO-Antivirus | Trojan.Script.Downloader.hrpyor |
MicroWorld-eScan | Trojan.Generic.36895517 |
Rising | Trojan.AgentTesla/VBS!8.160F9 (TOPIS:E0:5TAXQq7FJaT) |
Emsisoft | Trojan.Generic.36895517 (B) |
Ikarus | Trojan.Script.Agent |
FireEye | Trojan.Generic.36895517 |
Detected | |
Microsoft | Trojan:VBS/AgentTesla.RVI!MTB |
GData | Trojan.Generic.36895517 |
Fortinet | VBS/Agent.SXD!tr.dldr |
AVG | Script:SNH-gen [Trj] |