C:\Users\user\Desktop\eW1QrimJYd.exe
|
"C:\Users\user\Desktop\eW1QrimJYd.exe"
|
 |
|
Is windows: |
false
|
Is dropped: |
false
|
PID: |
4500
|
Target ID: |
1
|
Parent PID: |
5436
|
Name: |
eW1QrimJYd.exe
|
Path: |
C:\Users\user\Desktop\eW1QrimJYd.exe
|
Commandline: |
"C:\Users\user\Desktop\eW1QrimJYd.exe"
|
Size: |
75264
|
MD5: |
B7325E075262FFDEAA68CAE94018CADB
|
Time: |
23:48:35
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
low
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xa80000
|
Modulesize: |
90112
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Yara detected Gandcrab |
Spam, unwanted Advertisements and Ransom Demands |
|
Machine Learning detection for sample |
AV Detection |
|
Uses 32bit PE files |
Compliance, System Summary |
|
PE file has an executable .text section and no other executable section |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
Spawns processes |
System Summary |
|
Contains modern PE file flags such as dynamic base (ASLR) or NX |
Compliance, System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup nomoreransom.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
5720
|
Target ID: |
5
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup nomoreransom.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:48:44
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
moderate
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup emsisoft.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
5916
|
Target ID: |
7
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup emsisoft.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:48:48
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
moderate
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup gandcrab.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
5400
|
Target ID: |
9
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup gandcrab.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:48:50
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
moderate
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Users\user\AppData\Roaming\Microsoft\qvvfpl.exe
|
"C:\Users\user\AppData\Roaming\Microsoft\qvvfpl.exe"
|
 |
|
Is windows: |
false
|
Is dropped: |
true
|
PID: |
3252
|
Target ID: |
11
|
Parent PID: |
3452
|
Name: |
qvvfpl.exe
|
Path: |
C:\Users\user\AppData\Roaming\Microsoft\qvvfpl.exe
|
Commandline: |
"C:\Users\user\AppData\Roaming\Microsoft\qvvfpl.exe"
|
Size: |
75264
|
MD5: |
E5E0C9F951E9947AEA55720B7D0299F2
|
Time: |
23:48:52
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
low
|
Is admin: |
false
|
Is elevated: |
false
|
Modulebase: |
0xd70000
|
Modulesize: |
90112
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Gandcrab |
Spam, unwanted Advertisements and Ransom Demands |
|
Drops PE files |
Persistence and Installation Behavior |
|
Creates files inside the user directory |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup nomoreransom.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
5732
|
Target ID: |
13
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup nomoreransom.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:48:55
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
moderate
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup emsisoft.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
4788
|
Target ID: |
20
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup emsisoft.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:48:58
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup gandcrab.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
5276
|
Target ID: |
22
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup gandcrab.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:49:01
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Users\user\AppData\Roaming\Microsoft\qvvfpl.exe
|
"C:\Users\user\AppData\Roaming\Microsoft\qvvfpl.exe"
|
 |
|
Is windows: |
false
|
Is dropped: |
true
|
PID: |
68
|
Target ID: |
24
|
Parent PID: |
3452
|
Name: |
qvvfpl.exe
|
Path: |
C:\Users\user\AppData\Roaming\Microsoft\qvvfpl.exe
|
Commandline: |
"C:\Users\user\AppData\Roaming\Microsoft\qvvfpl.exe"
|
Size: |
75264
|
MD5: |
E5E0C9F951E9947AEA55720B7D0299F2
|
Time: |
23:49:02
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
false
|
Is elevated: |
false
|
Modulebase: |
0xd70000
|
Modulesize: |
90112
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Gandcrab |
Spam, unwanted Advertisements and Ransom Demands |
|
Drops PE files |
Persistence and Installation Behavior |
|
Creates files inside the user directory |
System Summary |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup nomoreransom.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
6148
|
Target ID: |
25
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup nomoreransom.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:49:02
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup emsisoft.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
6220
|
Target ID: |
28
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup emsisoft.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:49:04
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup gandcrab.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
6316
|
Target ID: |
30
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup gandcrab.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:49:06
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup nomoreransom.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
6372
|
Target ID: |
32
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup nomoreransom.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:49:08
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup emsisoft.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
6528
|
Target ID: |
35
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup emsisoft.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:49:13
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup gandcrab.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
6632
|
Target ID: |
37
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup gandcrab.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:49:16
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup nomoreransom.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
6720
|
Target ID: |
39
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup nomoreransom.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:49:17
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup emsisoft.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
6808
|
Target ID: |
41
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup emsisoft.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:49:20
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup gandcrab.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
6920
|
Target ID: |
43
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup gandcrab.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:49:21
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup nomoreransom.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7028
|
Target ID: |
45
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup nomoreransom.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:49:23
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup emsisoft.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7100
|
Target ID: |
47
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup emsisoft.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:49:25
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup gandcrab.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
7156
|
Target ID: |
49
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup gandcrab.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:49:27
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup nomoreransom.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
6164
|
Target ID: |
51
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup nomoreransom.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:49:34
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup emsisoft.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
6288
|
Target ID: |
53
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup emsisoft.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:49:38
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup gandcrab.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
2852
|
Target ID: |
56
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup gandcrab.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:49:39
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup nomoreransom.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
2408
|
Target ID: |
58
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup nomoreransom.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:49:43
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\SysWOW64\nslookup.exe
|
nslookup emsisoft.bit dns1.soprodns.ru
|
 |
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
6392
|
Target ID: |
61
|
Parent PID: |
4500
|
Name: |
nslookup.exe
|
Path: |
C:\Windows\SysWOW64\nslookup.exe
|
Commandline: |
nslookup emsisoft.bit dns1.soprodns.ru
|
Size: |
78336
|
MD5: |
8E82529D1475D67615ADCB4E1B8F4EEC
|
Time: |
23:49:46
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0xb80000
|
Modulesize: |
98304
|
Wow64: |
true
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Uses nslookup.exe to query domains |
Networking |
System Network Configuration Discovery
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Too many similar processes found |
DDoS |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
5276
|
Target ID: |
6
|
Parent PID: |
5720
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
625664
|
MD5: |
EA777DEEA782E8B4D7C7C33BBF8A4496
|
Time: |
23:48:44
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
high
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff6da640000
|
Modulesize: |
651264
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
5460
|
Target ID: |
8
|
Parent PID: |
5916
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
625664
|
MD5: |
EA777DEEA782E8B4D7C7C33BBF8A4496
|
Time: |
23:48:48
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
high
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff6da640000
|
Modulesize: |
651264
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
492
|
Target ID: |
12
|
Parent PID: |
5400
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
625664
|
MD5: |
EA777DEEA782E8B4D7C7C33BBF8A4496
|
Time: |
23:48:54
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
high
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff6da640000
|
Modulesize: |
651264
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
5964
|
Target ID: |
15
|
Parent PID: |
5732
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
625664
|
MD5: |
EA777DEEA782E8B4D7C7C33BBF8A4496
|
Time: |
23:48:56
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff6da640000
|
Modulesize: |
651264
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
3572
|
Target ID: |
21
|
Parent PID: |
4788
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
625664
|
MD5: |
EA777DEEA782E8B4D7C7C33BBF8A4496
|
Time: |
23:48:58
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
Is admin: |
true
|
Is elevated: |
true
|
Modulebase: |
0x7ff6da640000
|
Modulesize: |
651264
|
Wow64: |
false
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Creates a process in suspended mode (likely to inject code) |
HIPS / PFW / Operating System Protection Evasion |
|
Spawns processes |
System Summary |
|
|
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
|
|
Is windows: |
true
|
Is dropped: |
false
|
PID: |
5380
|
Target ID: |
23
|
Parent PID: |
5276
|
Name: |
conhost.exe
|
Path: |
C:\Windows\System32\conhost.exe
|
Commandline: |
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
Size: |
625664
|
MD5: |
EA777DEEA782E8B4D7C7C33BBF8A4496
|
Time: |
23:49:01
|
Date: |
31/08/2022
|
Reason: |
newprocess
|
Reputation: |
timeout
|
|