Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | Dec. 9, 2022, 10:53 a.m. | Dec. 9, 2022, 10:55 a.m. |
-
wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\summit_1208.js
3004
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
count | 496 | name | heapspray | process | wscript.exe | total_mb | 60 | length | 126976 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 234 | name | heapspray | process | wscript.exe | total_mb | 58 | length | 262144 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 331 | name | heapspray | process | wscript.exe | total_mb | 81 | length | 258048 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 6306 | name | heapspray | process | wscript.exe | total_mb | 123 | length | 20480 | protection | PAGE_READWRITE |