Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | March 17, 2025, 9:39 a.m. | March 17, 2025, 10:02 a.m. |
-
-
-
gThseXGYz6VkS34E.exe C:\Users\test22\AppData\Local\Temp\dRA90OLc\gThseXGYz6VkS34E.exe 0
2284
-
-
NXonNmvE9cRRFfxL.exe C:\Users\test22\AppData\Local\Temp\NXonNmvE9cRRFfxL.exe 2552
2684 -
cHR8R5ijyj1Ic1Y9.exe C:\Users\test22\AppData\Local\Temp\cHR8R5ijyj1Ic1Y9.exe 2552
2724 -
aib0Q1C72l45FOvW.exe C:\Users\test22\AppData\Local\Temp\aib0Q1C72l45FOvW.exe 2552
2764 -
gV47SdjcEzTDlUBt.exe C:\Users\test22\AppData\Local\Temp\gV47SdjcEzTDlUBt.exe 2552
2808 -
0STUp9LWMUPLvYAo.exe C:\Users\test22\AppData\Local\Temp\0STUp9LWMUPLvYAo.exe 2552
2852 -
YkHscCZsekqgi3Ns.exe C:\Users\test22\AppData\Local\Temp\YkHscCZsekqgi3Ns.exe 2552
2920 -
f7clVsTKgBeGBZm1.exe C:\Users\test22\AppData\Local\Temp\f7clVsTKgBeGBZm1.exe 2552
2548 -
z1yeYXhNXfWOcn4u.exe C:\Users\test22\AppData\Local\Temp\z1yeYXhNXfWOcn4u.exe 2552
4560 -
NJzn2Uzi0Eo8JgrZ.exe C:\Users\test22\AppData\Local\Temp\NJzn2Uzi0Eo8JgrZ.exe 2552
4248 -
Im8VwB4YUvmJZae6.exe C:\Users\test22\AppData\Local\Temp\Im8VwB4YUvmJZae6.exe 2552
3388 -
xqIyPU1Pncvy4Wif.exe C:\Users\test22\AppData\Local\Temp\xqIyPU1Pncvy4Wif.exe 2552
4676 -
Di940XWRk4TvkcIn.exe C:\Users\test22\AppData\Local\Temp\Di940XWRk4TvkcIn.exe 2552
5408 -
yXZJ2Z1iWleuXExA.exe C:\Users\test22\AppData\Local\Temp\yXZJ2Z1iWleuXExA.exe 2552
14820 -
qVHqqCmUJT4LLZxK.exe C:\Users\test22\AppData\Local\Temp\qVHqqCmUJT4LLZxK.exe 2552
12456 -
PyH3oS4HVckLB6EE.exe C:\Users\test22\AppData\Local\Temp\PyH3oS4HVckLB6EE.exe 2552
3152 -
ldlnYW79I6TMCEw3.exe C:\Users\test22\AppData\Local\Temp\ldlnYW79I6TMCEw3.exe 2552
14288 -
0hZyrWhxomMrOptC.exe C:\Users\test22\AppData\Local\Temp\0hZyrWhxomMrOptC.exe 2552
14052 -
seJrfTgW2l6OVW78.exe C:\Users\test22\AppData\Local\Temp\seJrfTgW2l6OVW78.exe 2552
5032
-
-
explorer.exe C:\Windows\Explorer.EXE
1452
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 77.90.153.245:8293 -> 192.168.56.101:49238 | 2400006 | ET DROP Spamhaus DROP Listed Traffic Inbound group 7 | Misc Attack |
TCP 77.90.153.244:80 -> 192.168.56.101:49236 | 2400006 | ET DROP Spamhaus DROP Listed Traffic Inbound group 7 | Misc Attack |
TCP 192.168.56.101:49236 -> 77.90.153.244:80 | 2016141 | ET INFO Executable Download from dotted-quad Host | Potentially Bad Traffic |
TCP 77.90.153.244:80 -> 192.168.56.101:49236 | 2018959 | ET POLICY PE EXE or DLL Windows file download HTTP | Potential Corporate Privacy Violation |
TCP 77.90.153.244:80 -> 192.168.56.101:49236 | 2021076 | ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response | Potentially Bad Traffic |
Suricata TLS
No Suricata TLS
suspicious_features | Connection to IP address | suspicious_request | GET http://77.90.153.244/l9543.exe |
request | GET http://77.90.153.244/l9543.exe |
description | aib0Q1C72l45FOvW.exe tried to sleep 1005 seconds, actually delayed analysis time by 1005 seconds | |||
description | NXonNmvE9cRRFfxL.exe tried to sleep 1135 seconds, actually delayed analysis time by 1135 seconds | |||
description | cHR8R5ijyj1Ic1Y9.exe tried to sleep 964 seconds, actually delayed analysis time by 964 seconds | |||
description | yXZJ2Z1iWleuXExA.exe tried to sleep 317 seconds, actually delayed analysis time by 317 seconds | |||
description | f7clVsTKgBeGBZm1.exe tried to sleep 855 seconds, actually delayed analysis time by 855 seconds | |||
description | Di940XWRk4TvkcIn.exe tried to sleep 390 seconds, actually delayed analysis time by 390 seconds | |||
description | z1yeYXhNXfWOcn4u.exe tried to sleep 787 seconds, actually delayed analysis time by 787 seconds | |||
description | NJzn2Uzi0Eo8JgrZ.exe tried to sleep 526 seconds, actually delayed analysis time by 526 seconds | |||
description | gV47SdjcEzTDlUBt.exe tried to sleep 788 seconds, actually delayed analysis time by 788 seconds | |||
description | qVHqqCmUJT4LLZxK.exe tried to sleep 232 seconds, actually delayed analysis time by 232 seconds | |||
description | 0STUp9LWMUPLvYAo.exe tried to sleep 1185 seconds, actually delayed analysis time by 1185 seconds | |||
description | vpZvQeDoVnhQnT6u.exe tried to sleep 155 seconds, actually delayed analysis time by 155 seconds | |||
description | xqIyPU1Pncvy4Wif.exe tried to sleep 396 seconds, actually delayed analysis time by 396 seconds | |||
description | Im8VwB4YUvmJZae6.exe tried to sleep 549 seconds, actually delayed analysis time by 549 seconds | |||
description | YkHscCZsekqgi3Ns.exe tried to sleep 652 seconds, actually delayed analysis time by 652 seconds |
file | C:\Users\test22\AppData\Local\Temp\dRA90OLc\gThseXGYz6VkS34E.exe |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GoogleChrome.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GoogleChrome.lnk |
file | C:\Users\test22\AppData\Local\Temp\SandboxieInstall.exe |
file | C:\Users\test22\AppData\Local\Temp\sss81242.exe |
file | C:\Users\test22\AppData\Local\Temp\202005191702_6d173b9549ce4fe1e5ada5ab9ce0bfff5d9569f19e7fa916db5c8d4f0dace63b_setup_nwc275a_demo.exe |