| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1619710563.370502 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
|
1619710563.370502 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
| suspicious_features | POST method with no referer header | suspicious_request | POST https://livdecor.pt/work/Panel/index.php | ||||||
| request | GET http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
| request | GET http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D |
| request | GET http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D |
| request | POST https://livdecor.pt/work/Panel/index.php |
| request | POST https://livdecor.pt/work/Panel/index.php |
| Time & API | Arguments | Status | Return | Repeated |
|---|---|---|---|---|
|
1619710564.214502 GetAdaptersAddresses |
flags:
0
family: 0 |
failed | 111 | 0 |
| entropy | 7.757164466750114 | section | {'size_of_data': '0x00072000', 'virtual_address': '0x000c4000', 'entropy': 7.757164466750114, 'name': '.rsrc', 'virtual_size': '0x00071e0c'} | description | A section with a high entropy has been found | |||||||||
| entropy | 0.36219221604447976 | description | Overall entropy of this PE file is high | |||||||||||
| buffer | Buffer with sha1: 2de30e293fc192df976032c0b64e8134b5aa4b22 |
| host | 172.217.24.14 | |||