Summary | ZeroBOX

questioneer-pdf.js

Category Machine Started Completed
FILE s1_win7_x6403_us Oct. 18, 2021, 9:59 a.m. Oct. 18, 2021, 10:02 a.m.
Size 66.3KB
Type ASCII text, with very long lines, with no line terminators
MD5 93b27733d5e46b676eca9cf990652070
SHA256 a799700b7e69cf25a7a59b29a10152e1f6daac91c00da3b54b655b69dd5f07be
CRC32 1AD67BCD
ssdeep 1536:xEBprfWyvKwuY7FuG3ysXlpkXYFjW1gTc5iJoyGpM/cwua2:xEBprfWyvKwd7FPysXlpkXYFjW1gTEyY
Yara None matched

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
wmi select * from win32_VideoController
wmi select * from win32_ComputerSystemProduct
wmi select * from win32_Processor
wmi select * from win32_ComputerSystem
wmi select * from win32_LogicalDisk
wmi select * from win32_Processor
wmi select * from win32_LogicalDisk
wmi select * from win32_ComputerSystemProduct
wmi select * from win32_ComputerSystem
Lionic Trojan.Script.Startup.4!c
Arcabit Trojan.Generic.D2D02B51
Cyren JS/Agent.AUK!Eldorado
Symantec ISB.Downloader!gen52
TrendMicro-HouseCall TROJ_FRS.VSNTJH21
Kaspersky HEUR:Trojan.Script.Startup.gen
BitDefender Trojan.GenericKD.47197009
MicroWorld-eScan Trojan.GenericKD.47197009
Ad-Aware Trojan.GenericKD.47197009
Comodo .UnclassifiedMalware@0
FireEye Trojan.GenericKD.47197009
Emsisoft Trojan.GenericKD.47197009 (B)
MAX malware (ai score=81)
Microsoft Trojan:JS/Tnega.AL!MTB
GData Trojan.GenericKD.47197009