Loading content, please wait...
This report is generated from a file or URL submitted to this webservice on March 30th 2018 16:47:15 (UTC) and action script Heavy Anti-Evasion
Guest System: Windows 7 32 bit, Home Premium, 6.1 (build 7601), Service Pack 1
Report generated by
Falcon Sandbox v8.00 © Hybrid Analysis
Not all malicious and suspicious indicators are displayed. Get your own cloud service or the full version to view all details.
| Details | |||||
|---|---|---|---|---|---|
Loading content, please wait...
Tip: Click an analysed process below to view more details.
Analysed 1 process in total (System Resource Monitor).
No relevant DNS requests were made.
| IP Address | Port/Protocol | Associated Process | Details |
|---|---|---|---|
|
61.100.3.151 |
80
TCP |
client.exe PID: 3804 |
Korea Republic of |
| Endpoint | Request | URL | |
|---|---|---|---|
| 61.100.3.151:80 | HEAD | /data/notice.exe | HEAD /data/notice.exe HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
Host: 61.100.3.151 More Details |
| 61.100.3.151:80 | GET | /data/notice.exe | GET /data/notice.exe HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
Host: 61.100.3.151 More Details |
| 61.100.3.151:80 | GET | /data/count.php?stauts=BEGIN&code= | GET /data/count.php?stauts=BEGIN&code= HTTP/1.1
Connection: Keep-Alive
User-Agent: Winnet Client
Host: 61.100.3.151 More Details |
| String | Context | Stream UID |
|---|---|---|
| 61.100.3.151 | Domain/IP reference | 00035902-00003804-32871-2135-0040E950 |
| http://61.100.3.151/data/notice.exe | Domain/IP reference | 00035902-00003804-32871-2257-0040E530 |
| mail.ru | Domain/IP reference | 00035902-00003804-32871-2190-0040F940 |
| Event | Category | Description | SID |
|---|---|---|---|
| local -> 61.100.3.151:80 (TCP) | A Network Trojan was detected | ET INFO Executable Download from dotted-quad Host | 2016141 |
| local -> 61.100.3.151:80 (TCP) | A Network Trojan was detected | ET INFO Executable Download from dotted-quad Host | 2016141 |
| 61.100.3.151 -> local:63541 (TCP) | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP | 2018959 |
| 61.100.3.151 -> local:63541 (TCP) | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download | 2016538 |
| 61.100.3.151 -> local:63541 (TCP) | Potentially Bad Traffic | ET INFO SUSPICIOUS Dotted Quad Host MZ Response | 2021076 |
| local -> 61.100.3.151:80 (TCP) | Hidden Category | Additional ETPro rules are available in the private webservice or standalone version | Hidden SID |
Displaying 38 extracted file(s). The remaining 18 file(s) are available in the full version and XML/JSON reports.