March 3, 2018
3 hours
15:03:18
File Downloaded
SHA-256: 39ad98e44ff3bfe58f4658213defa6789c599af32a5b2e71b689fe5367e2472a
From URL http://naturalpetfood.com
URL
Actions
URL | |
Address | |
Category | |
3 endpoints have visited this URL 17 times
23 min
09:11:35
An executable was allowed to run
SHA-256: 39ad98e44ff3bfe58f4658213defa6789c599af32a5b2e71b689fe5367e2472a
Malware
Emotet
Search for
lateral movement
lateral movement
Search for lateral movement
Search
Time | Source | Category | File Name | URL | Activity | Destination | Lorem Ipsum | Lorem Ipsum | Action | ||
---|---|---|---|---|---|---|---|---|---|---|---|
Firewall | 78200.exe | http://myoneid.site90.com/ | Download | Allow |
Add
|
||||||
Traps | 78200.exe | Run | Allow |
Add
|
|||||||
Traps | 78200.exe | Run | Block |
Add
|
Sylvia Poggioli
Manager, Channel Sales
Santa Clara, CA
(o650) 123-4567
2 issues
Apple MacBook Air
OS version 10.13.3
Traps: Active (v 5.0.0.803)
Owned by Sylvia Poggioli
2 issues
HTTP Requests
Host | Method | URL | User Agent | In ENvironment | |||||
---|---|---|---|---|---|---|---|---|---|
0 | 145 | 0 |
54.227.38.29
|
POST
|
/
|
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET CLR 1.1.4322; .NET4.0C; .NET4.0E; InfoPath.3)
|
|||
0 | 134 | 0 |
93.42.184.106
|
POST
|
/
|
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET CLR 1.1.4322; .NET4.0C; .NET4.0E; InfoPath.3)
|
1
|
||
0 | 60 | 0 |
52.4.64.240
|
POST
|
/
|
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET CLR 1.1.4322; .NET4.0C; .NET4.0E; InfoPath.3)
|
|||
0 | 43 | 0 |
119.59.124.163
|
POST
|
/
|
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET CLR 1.1.4322; .NET4.0C; .NET4.0E; InfoPath.3)
|
3
|
||
0 | 28 | 0 |
91.217.66.130
|
POST
|
/
|
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET CLR 1.1.4322; .NET4.0C; .NET4.0E; InfoPath.3)
|
|||
0 | 4 | 0 |
lapsurgerymos.com
|
GET
|
/XnGB/
|
Filename/Hash | Type | URL | Size (KB) | WildFire Verdict | # in Logs | |
---|---|---|---|---|---|---|
invoice.doc
4fb319211b2e85cace04e8936100f024
|
DOC | random-url.com | 19,287 |
Malware
|
4 |
URL | # in Logs | ||||||
---|---|---|---|---|---|---|---|
33.33.33.33 |
npr-support.org
|
1 | |||||
54.227.38.29 |
Malicious URL
|
1 |
Alert Source | Description | Severity | Fidelity | Notes | Count |
---|---|---|---|---|---|
Firewall | C2 traffic detected | 5 |
|
(Rule has a high FP rate, traffic isn't corroborated by other sources, maybe there are instances of the same C2 traffic before the file was downloaded?) | 1.2K |
Traps | Post detection alert | 4 |
|
(Rule has a low FP rate, WF verdict correlates with VirusTotal and autofocus) | 1 |
Time | Source | Destination | Lorem Ipsum | Lorem Ipsum | Lorem Ipsum | Lorem Ipsum | Lorem Ipsum |
---|---|---|---|---|---|---|---|