Description

Files

IP Addresses

- Infected host: 192.168.1.128
    - IPv6 local address: fd2d:ab8c:225:0:512:a519:bb75:80ea
- Default GW: 192.168.1.2

Timeline

Tue Nov 8 15:31:07 CET 2016

started win18

Tue Nov 8 15:34:17 CET 2016

infected

162.247.242.19: VT: https://www.virustotal.com/en/ip-address/162.247.242.19/information/ PS: Two domains. Not good reputation bam.nr-data.net Periodic: Long:

Mon Dec 5 09:57:30 CET 2016

power off