Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | May 6, 2025, 9:29 p.m. | May 6, 2025, 9:31 p.m. |
-
x.exe "C:\Users\test22\AppData\Local\Temp\x.exe"
2032
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
185.156.72.39 | Active | Moloch |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 185.156.72.39:5151 -> 192.168.56.103:49162 | 2400031 | ET DROP Spamhaus DROP Listed Traffic Inbound group 32 | Misc Attack |
TCP 192.168.56.103:49162 -> 185.156.72.39:5151 | 2024792 | ET POLICY Cryptocurrency Miner Checkin | Potential Corporate Privacy Violation |
TCP 192.168.56.103:49162 -> 185.156.72.39:5151 | 2024792 | ET POLICY Cryptocurrency Miner Checkin | Potential Corporate Privacy Violation |
Suricata TLS
No Suricata TLS