Edit tour
Windows
Analysis Report
Process Monitor.exe
Overview
General Information
Detection
Score: | 76 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Multi AV Scanner detection for submitted file
Malicious sample detected (through community Yara rule)
Snort IDS alert for network traffic
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
May modify the system service descriptor table (often done to hook functions)
Performs DNS TXT record lookups
Uses 32bit PE files
Yara signature match
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Detected potential crypto function
Contains functionality to query CPU information (cpuid)
Found potential string decryption / allocating functions
Sample execution stops while process was sleeping (likely an evasion)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to call native functions
Contains functionality to dynamically determine API calls
Contains functionality to record screenshots
Contains functionality which may be used to detect a debugger (GetProcessHeap)
PE file contains executable resources (Code or Archives)
Sample file is different than original file name gathered from version info
PE file contains an invalid checksum
Extensive use of GetProcAddress (often used to hide API calls)
PE file contains strange resources
Found evasive API chain checking for process token information
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to launch a program with higher privileges
PE / OLE file has an invalid certificate
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Found large amount of non-executed APIs
Contains functionality for read data from the clipboard
Classification
- System is w10x64
- Process Monitor.exe (PID: 5972 cmdline:
"C:\Users\ user\Deskt op\Process Monitor.e xe" MD5: 3D55E52BF84C8B1CB08CF447E195B006)
- cleanup
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Windows_Shellcode_Generic_8c487e57 | unknown | unknown |
| |
Windows_Trojan_Metasploit_38b8ceec | Identifies the API address lookup function used by metasploit. Also used by other tools (like beacon). | unknown |
|
⊘No Sigma rule has matched
Timestamp: | 192.168.2.38.8.8.860582532847439 09/18/22-17:07:11.562484 |
SID: | 2847439 |
Source Port: | 60582 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.857387532847439 09/18/22-17:07:24.194124 |
SID: | 2847439 |
Source Port: | 57387 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.854283532847439 09/18/22-17:07:29.226053 |
SID: | 2847439 |
Source Port: | 54283 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.852387532847439 09/18/22-17:07:10.272964 |
SID: | 2847439 |
Source Port: | 52387 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.851139532847439 09/18/22-17:07:11.170526 |
SID: | 2847439 |
Source Port: | 51139 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.850228532847439 09/18/22-17:07:24.364057 |
SID: | 2847439 |
Source Port: | 50228 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.851592532847439 09/18/22-17:07:28.423748 |
SID: | 2847439 |
Source Port: | 51592 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.865511532847439 09/18/22-17:07:19.758372 |
SID: | 2847439 |
Source Port: | 65511 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.864376532847439 09/18/22-17:07:27.269341 |
SID: | 2847439 |
Source Port: | 64376 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.860625532847439 09/18/22-17:07:10.628522 |
SID: | 2847439 |
Source Port: | 60625 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.861359532847439 09/18/22-17:07:28.603368 |
SID: | 2847439 |
Source Port: | 61359 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.865385532847439 09/18/22-17:07:21.931334 |
SID: | 2847439 |
Source Port: | 65385 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.851105532847439 09/18/22-17:07:25.157982 |
SID: | 2847439 |
Source Port: | 51105 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.857743532809850 09/18/22-17:07:17.807037 |
SID: | 2809850 |
Source Port: | 57743 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.858912532847439 09/18/22-17:07:26.816961 |
SID: | 2847439 |
Source Port: | 58912 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.853466532847439 09/18/22-17:07:17.612305 |
SID: | 2847439 |
Source Port: | 53466 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.862431532847439 09/18/22-17:07:24.831301 |
SID: | 2847439 |
Source Port: | 62431 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.857990532847439 09/18/22-17:07:10.103736 |
SID: | 2847439 |
Source Port: | 57990 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.859433532847439 09/18/22-17:07:15.237878 |
SID: | 2847439 |
Source Port: | 59433 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.855390532847439 09/18/22-17:07:26.665994 |
SID: | 2847439 |
Source Port: | 55390 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.860644532847439 09/18/22-17:07:28.098121 |
SID: | 2847439 |
Source Port: | 60644 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.858480532847439 09/18/22-17:07:28.753771 |
SID: | 2847439 |
Source Port: | 58480 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.856616532847439 09/18/22-17:07:23.846528 |
SID: | 2847439 |
Source Port: | 56616 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.854153532847439 09/18/22-17:07:22.105508 |
SID: | 2847439 |
Source Port: | 54153 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.864602532847439 09/18/22-17:07:22.286338 |
SID: | 2847439 |
Source Port: | 64602 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.865320532847439 09/18/22-17:07:12.851983 |
SID: | 2847439 |
Source Port: | 65320 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.864271532847439 09/18/22-17:07:24.996996 |
SID: | 2847439 |
Source Port: | 64271 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.856949532847439 09/18/22-17:07:16.693035 |
SID: | 2847439 |
Source Port: | 56949 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.860418532847439 09/18/22-17:07:29.076080 |
SID: | 2847439 |
Source Port: | 60418 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.864595532847439 09/18/22-17:07:20.143048 |
SID: | 2847439 |
Source Port: | 64595 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.849302532847439 09/18/22-17:07:10.818703 |
SID: | 2847439 |
Source Port: | 49302 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.860767532847439 09/18/22-17:07:13.048445 |
SID: | 2847439 |
Source Port: | 60767 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.852110532847439 09/18/22-17:07:27.443917 |
SID: | 2847439 |
Source Port: | 52110 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.853269532847439 09/18/22-17:07:24.532168 |
SID: | 2847439 |
Source Port: | 53269 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.855649532847439 09/18/22-17:07:27.119889 |
SID: | 2847439 |
Source Port: | 55649 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.864969532847439 09/18/22-17:07:25.680782 |
SID: | 2847439 |
Source Port: | 64969 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.863687532847439 09/18/22-17:07:27.611185 |
SID: | 2847439 |
Source Port: | 63687 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.859820532847439 09/18/22-17:07:19.922462 |
SID: | 2847439 |
Source Port: | 59820 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.862424532847439 09/18/22-17:07:26.339688 |
SID: | 2847439 |
Source Port: | 62424 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.861416532847439 09/18/22-17:07:18.210206 |
SID: | 2847439 |
Source Port: | 61416 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.858691532847439 09/18/22-17:07:14.203939 |
SID: | 2847439 |
Source Port: | 58691 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.864967532847439 09/18/22-17:07:22.800242 |
SID: | 2847439 |
Source Port: | 64967 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.858301532847439 09/18/22-17:07:21.232458 |
SID: | 2847439 |
Source Port: | 58301 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.859636532847439 09/18/22-17:07:12.315640 |
SID: | 2847439 |
Source Port: | 59636 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.860088532847439 09/18/22-17:07:19.243261 |
SID: | 2847439 |
Source Port: | 60088 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.853428532847439 09/18/22-17:07:19.583371 |
SID: | 2847439 |
Source Port: | 53428 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.857134532847439 09/18/22-17:07:11.737698 |
SID: | 2847439 |
Source Port: | 57134 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.862050532847439 09/18/22-17:07:11.920045 |
SID: | 2847439 |
Source Port: | 62050 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.852955532847439 09/18/22-17:07:11.371670 |
SID: | 2847439 |
Source Port: | 52955 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.853037532847439 09/18/22-17:07:25.831456 |
SID: | 2847439 |
Source Port: | 53037 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.852547532847439 09/18/22-17:07:16.861417 |
SID: | 2847439 |
Source Port: | 52547 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.859827532847439 09/18/22-17:07:24.681633 |
SID: | 2847439 |
Source Port: | 59827 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.858708532847439 09/18/22-17:07:18.633823 |
SID: | 2847439 |
Source Port: | 58708 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.863446532847439 09/18/22-17:07:21.428506 |
SID: | 2847439 |
Source Port: | 63446 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.855951532847439 09/18/22-17:07:28.244855 |
SID: | 2847439 |
Source Port: | 55951 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.857571532847439 09/18/22-17:07:13.704944 |
SID: | 2847439 |
Source Port: | 57571 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.853844532847439 09/18/22-17:07:17.177911 |
SID: | 2847439 |
Source Port: | 53844 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.853305532847439 09/18/22-17:07:14.506207 |
SID: | 2847439 |
Source Port: | 53305 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.865196532847439 09/18/22-17:07:18.446638 |
SID: | 2847439 |
Source Port: | 65196 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.865459532847439 09/18/22-17:07:21.761569 |
SID: | 2847439 |
Source Port: | 65459 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.855638532847439 09/18/22-17:07:12.479999 |
SID: | 2847439 |
Source Port: | 55638 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.865107532847439 09/18/22-17:07:13.253711 |
SID: | 2847439 |
Source Port: | 65107 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.853975532847439 09/18/22-17:07:10.968952 |
SID: | 2847439 |
Source Port: | 53975 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.853623532847439 09/18/22-17:07:18.045058 |
SID: | 2847439 |
Source Port: | 53623 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.859374532847439 09/18/22-17:07:23.679047 |
SID: | 2847439 |
Source Port: | 59374 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.856042532847439 09/18/22-17:07:12.122666 |
SID: | 2847439 |
Source Port: | 56042 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.859581532847439 09/18/22-17:07:18.812839 |
SID: | 2847439 |
Source Port: | 59581 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.849166532847439 09/18/22-17:07:21.060651 |
SID: | 2847439 |
Source Port: | 49166 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.856924532847439 09/18/22-17:07:10.443975 |
SID: | 2847439 |
Source Port: | 56924 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.865017532847439 09/18/22-17:07:17.434078 |
SID: | 2847439 |
Source Port: | 65017 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.852455532847439 09/18/22-17:07:25.337136 |
SID: | 2847439 |
Source Port: | 52455 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.860816532847439 09/18/22-17:07:26.170261 |
SID: | 2847439 |
Source Port: | 60816 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.857824532847439 09/18/22-17:07:27.755938 |
SID: | 2847439 |
Source Port: | 57824 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.864823532847439 09/18/22-17:07:20.522990 |
SID: | 2847439 |
Source Port: | 64823 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.863562532847439 09/18/22-17:07:19.417113 |
SID: | 2847439 |
Source Port: | 63562 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.849874532847439 09/18/22-17:07:21.606663 |
SID: | 2847439 |
Source Port: | 49874 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.864121532847439 09/18/22-17:07:22.645440 |
SID: | 2847439 |
Source Port: | 64121 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.850622532847439 09/18/22-17:07:26.966706 |
SID: | 2847439 |
Source Port: | 50622 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.853049532847439 09/18/22-17:07:19.031587 |
SID: | 2847439 |
Source Port: | 53049 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.858119532847439 09/18/22-17:07:20.884113 |
SID: | 2847439 |
Source Port: | 58119 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.860473532847439 09/18/22-17:07:23.531670 |
SID: | 2847439 |
Source Port: | 60473 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.850784532847439 09/18/22-17:07:22.457054 |
SID: | 2847439 |
Source Port: | 50784 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.864936532847439 09/18/22-17:07:23.351211 |
SID: | 2847439 |
Source Port: | 64936 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.853848532847439 09/18/22-17:07:13.469060 |
SID: | 2847439 |
Source Port: | 53848 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.851992532847439 09/18/22-17:07:20.699180 |
SID: | 2847439 |
Source Port: | 51992 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.852079532847439 09/18/22-17:07:20.352550 |
SID: | 2847439 |
Source Port: | 52079 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.852741532847439 09/18/22-17:07:27.947161 |
SID: | 2847439 |
Source Port: | 52741 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.849201532847439 09/18/22-17:07:23.199072 |
SID: | 2847439 |
Source Port: | 49201 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.857704532847439 09/18/22-17:07:12.662394 |
SID: | 2847439 |
Source Port: | 57704 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.860749532847439 09/18/22-17:07:15.469676 |
SID: | 2847439 |
Source Port: | 60749 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.860825532847439 09/18/22-17:07:23.012681 |
SID: | 2847439 |
Source Port: | 60825 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.855244532847439 09/18/22-17:07:25.529724 |
SID: | 2847439 |
Source Port: | 55244 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.855457532847439 09/18/22-17:07:26.014383 |
SID: | 2847439 |
Source Port: | 55457 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.851889532847439 09/18/22-17:07:28.922774 |
SID: | 2847439 |
Source Port: | 51889 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.857743532847439 09/18/22-17:07:17.807037 |
SID: | 2847439 |
Source Port: | 57743 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.861184532847439 09/18/22-17:07:24.020425 |
SID: | 2847439 |
Source Port: | 61184 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.38.8.8.861126532847439 09/18/22-17:07:26.499232 |
SID: | 2847439 |
Source Port: | 61126 |
Destination Port: | 53 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Static PE information: |
Source: | Window detected: |