Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Feb. 19, 2025, 11:23 a.m. | Feb. 19, 2025, 11:42 a.m. |
-
blaq.exe "C:\Users\test22\AppData\Local\Temp\blaq.exe"
1740 -
-
firefox.exe "C:\Program Files\Mozilla Firefox\Firefox.exe"
2776
-
-
explorer.exe C:\Windows\Explorer.EXE
1236
Name | Response | Post-Analysis Lookup |
---|---|---|
www.meacci.xyz | ||
www.xiuqicloud.website | ||
www.sfrouter.express | ||
www.trosky.lol | ||
www.zkplant.xyz | ||
www.adventurerepair24.live | ||
www.sqlite.org |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
request | POST http://www.zkplant.xyz/t2z5/ |
request | GET http://www.zkplant.xyz/t2z5/?wHwUOH=8VSe6D3+FdM96toYTkKYm4RfQN80B92Wswse+lRCZ5nd7JghEm3UVr0Q9u8PqQyGlh2BEZGJRS/hf5/2khKxbH6/CmdYSP+iYipsDo45rax8LzXX361i2DUedI4l6JslNrlk314=&li8B=Uh_aOYB7iOocT0e |
request | GET http://www.sqlite.org/2017/sqlite-dll-win32-x86-3170000.zip |
request | POST http://www.adventurerepair24.live/gc4d/ |
request | GET http://www.adventurerepair24.live/gc4d/?wHwUOH=LebFdeUSCMRA/h5sT7+2M2f/vQ1SufiCCUGQxkTYOySh8g+yOOCA1ht778Ujr70KVg4fy0FUcNIIjE4P2FpJife2AASvW/TiUzxRyQ9XEF5r5nlv8N9vw4E60m8WiXkOYycYg/o=&li8B=Uh_aOYB7iOocT0e |
request | POST http://www.meacci.xyz/ieqn/ |
request | GET http://www.meacci.xyz/ieqn/?wHwUOH=TXRwMNvNe7nWWxt2VYpYoe82JcF/DsRex1DbWUgtb2d4F8KnEpYV4uyghREjRYGlO9HLzYmvfgx+GjFyjye3bAwXsHcICLs5dZyytw3BsbuHZoaHGoXRgZC8N0lOdICFON5OFP4=&li8B=Uh_aOYB7iOocT0e |
request | POST http://www.sfrouter.express/f0c8/ |
request | GET http://www.sfrouter.express/f0c8/?wHwUOH=AHWHpIA83/7LQm5yWEptZovqcpfzyuCrVryDOXq41boPuGcZhCFYx0rfPVc+QU4vzPoFex3ntizgmAr9Oi8RON6E+Z9iOl73gIFM5BR9EAZ97ZYdmY/eiK7meSUUDtSRRtG1C5s=&li8B=Uh_aOYB7iOocT0e |
request | POST http://www.trosky.lol/o88r/ |
request | GET http://www.trosky.lol/o88r/?wHwUOH=ziUBiNnCPTx0D233h1ca1hydMmiXXNXHNMEY4JnQ/dp2McfnObELxA6oJBnFDOsWb/bM3s4W56oDTG7CCmWbz1/lpBHwSztieMVQct0KvuNR8Sztn05hRZ1RNhlgsM5Legpcclw=&li8B=Uh_aOYB7iOocT0e |
request | POST http://www.xiuqicloud.website/g63r/ |
request | POST http://www.zkplant.xyz/t2z5/ |
request | POST http://www.adventurerepair24.live/gc4d/ |
request | POST http://www.meacci.xyz/ieqn/ |
request | POST http://www.sfrouter.express/f0c8/ |
request | POST http://www.trosky.lol/o88r/ |
request | POST http://www.xiuqicloud.website/g63r/ |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ |
file | C:\Users\test22\AppData\Local\Chromium\User Data |
file | C:\Users\test22\AppData\Local\MapleStudio\ChromePlus\User Data |
file | C:\Users\test22\AppData\Local\Yandex\YandexBrowser\User Data |
file | C:\Users\test22\AppData\Local\Temp\sqlite3.dll |
file | C:\Users\test22\AppData\Local\Temp\sqlite3.dll |
section | {u'size_of_data': u'0x00045600', u'virtual_address': u'0x00001000', u'entropy': 7.996319502854979, u'name': u'.text', u'virtual_size': u'0x000455d4'} | entropy | 7.99631950285 | description | A section with a high entropy has been found | |||||||||
entropy | 1.0 | description | Overall entropy of this PE file is high |
file | C:\Users\test22\AppData\Local\AVAST Software\Browser\User Data |
file | C:\Users\test22\AppData\Local\AVG\Browser\User Data |