Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Feb. 7, 2025, 2:12 p.m. | Feb. 7, 2025, 2:25 p.m. |
IP Address | Status | Action |
---|---|---|
106.247.248.106 | Active | Moloch |
129.134.26.123 | Active | Moloch |
129.250.35.250 | Active | Moloch |
164.124.101.2 | Active | Moloch |
17.253.68.251 | Active | Moloch |
216.239.35.4 | Active | Moloch |
61.205.120.130 | Active | Moloch |
62.149.0.30 | Active | Moloch |
91.108.241.156 | Active | Moloch |
94.198.159.10 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.101:49165 91.108.241.156:6450 |
C=XX, ST=N/A, L=N/A, O=Self-signed certificate, CN=91.108.241.156: Self-signed certificate | C=XX, ST=N/A, L=N/A, O=Self-signed certificate, CN=91.108.241.156: Self-signed certificate | a4:a1:04:b9:d8:9e:94:ef:c4:9b:59:88:e0:15:d2:85:87:ca:2b:e9 |
TLS 1.2 192.168.56.101:49166 91.108.241.156:6450 |
C=XX, ST=N/A, L=N/A, O=Self-signed certificate, CN=91.108.241.156: Self-signed certificate | C=XX, ST=N/A, L=N/A, O=Self-signed certificate, CN=91.108.241.156: Self-signed certificate | a4:a1:04:b9:d8:9e:94:ef:c4:9b:59:88:e0:15:d2:85:87:ca:2b:e9 |
TLS 1.2 192.168.56.101:49167 91.108.241.156:6450 |
C=XX, ST=N/A, L=N/A, O=Self-signed certificate, CN=91.108.241.156: Self-signed certificate | C=XX, ST=N/A, L=N/A, O=Self-signed certificate, CN=91.108.241.156: Self-signed certificate | a4:a1:04:b9:d8:9e:94:ef:c4:9b:59:88:e0:15:d2:85:87:ca:2b:e9 |
TLS 1.2 192.168.56.101:49168 91.108.241.156:443 |
C=XX, ST=N/A, L=N/A, O=Self-signed certificate, CN=91.108.241.156: Self-signed certificate | C=XX, ST=N/A, L=N/A, O=Self-signed certificate, CN=91.108.241.156: Self-signed certificate | 60:1a:8a:4a:00:47:b8:2c:c4:4e:48:f7:cb:e5:ba:5c:fe:5d:b8:52 |
pdb_path | D:\a\wix4\wix4\build\burn\Release\x64\burn.pdb |
section | .didat |
section | .wixburn |
section | _RDATA |
file | C:\Windows\Temp\{AC844AAF-71D0-4EEA-8CB7-885DD29CB5B7}\.ba\Serum.dll |
file | C:\Windows\Temp\{AC844AAF-71D0-4EEA-8CB7-885DD29CB5B7}\.ba\libeay32.dll |
file | C:\Windows\Temp\{AC844AAF-71D0-4EEA-8CB7-885DD29CB5B7}\.ba\profile.dll |
file | C:\Windows\Temp\{AC844AAF-71D0-4EEA-8CB7-885DD29CB5B7}\.ba\WinX_DVD_Ripper_Platinum.exe |
file | C:\Windows\Temp\{E039CF43-5A4F-4EE7-A7B6-A922B7D60560}\.cr\ram.exe |
host | 91.108.241.156 |
file | C:\Windows\Temp\{E039CF43-5A4F-4EE7-A7B6-A922B7D60560}\.cr\ram.exe |
Lionic | Trojan.Win32.Nekark.4!c |
CAT-QuickHeal | Trojan.Ghanarava.17388875338c11e7 |
Skyhigh | BehavesLike.Win64.Ransom.vc |
Cylance | Unsafe |
CrowdStrike | win/malicious_confidence_60% (W) |
K7GW | Trojan-Downloader ( 005bfa841 ) |
K7AntiVirus | Trojan-Downloader ( 005bfa841 ) |
Symantec | ML.Attribute.HighConfidence |
Elastic | malicious (high confidence) |
ESET-NOD32 | multiple detections |
Avast | FileRepMalware [Misc] |
Kaspersky | Trojan.Win32.Penguish.drl |
F-Secure | Trojan.TR/AD.Nekark.tbmsh |
Zillya | Trojan.Penguish.Win32.680 |
McAfeeD | ti!019E368CDFE9 |
CTX | exe.trojan.nekark |
Sophos | Mal/Generic-S |
Detected | |
Avira | TR/AD.Nekark.tbmsh |
Kingsoft | Win32.Trojan.Penguish.drl |
Gridinsoft | Malware.Win64.Rhadamanthys.tr |
Microsoft | Program:Win32/Wacapew.C!ml |
GData | Win64.Trojan.Agent.9551H0 |
McAfee | Artemis!72EC64D0BC0B |
Ikarus | Trojan-Downloader.Win32.Rugmi |
huorong | HEUR:Trojan/HiJack.z |
Fortinet | W32/NDAoF |
AVG | FileRepMalware [Misc] |
alibabacloud | Trojan[downloader]:Win/Rugmi.EM |