Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | April 20, 2023, 11:15 a.m. | April 20, 2023, 11:17 a.m. |
-
wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\Complaint_Copy_838511.wsf
2556-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\ProgramData\aq2B7wGiC3vz.tmp,Motd
2772
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
103.20.235.243 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
suspicious_features | Connection to IP address | suspicious_request | GET http://103.20.235.243/aSxBaqnfj98wz.dat |
request | GET http://103.20.235.243/aSxBaqnfj98wz.dat |
host | 103.20.235.243 |
parent_process | wscript.exe | martian_process | "C:\Windows\System32\rundll32.exe" C:\ProgramData\aq2B7wGiC3vz.tmp,Motd | ||||||
parent_process | wscript.exe | martian_process | rundll32 C:\ProgramData\aq2B7wGiC3vz.tmp,Motd |
count | 3889 | name | heapspray | process | wscript.exe | total_mb | 106 | length | 28672 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 3890 | name | heapspray | process | wscript.exe | total_mb | 151 | length | 40960 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 19423 | name | heapspray | process | wscript.exe | total_mb | 606 | length | 32768 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 11654 | name | heapspray | process | wscript.exe | total_mb | 500 | length | 45056 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 7793 | name | heapspray | process | wscript.exe | total_mb | 60 | length | 8192 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 38847 | name | heapspray | process | wscript.exe | total_mb | 455 | length | 12288 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 7770 | name | heapspray | process | wscript.exe | total_mb | 182 | length | 24576 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 58292 | name | heapspray | process | wscript.exe | total_mb | 227 | length | 4096 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 3889 | name | heapspray | process | wscript.exe | total_mb | 75 | length | 20480 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 7768 | name | heapspray | process | wscript.exe | total_mb | 273 | length | 36864 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 3887 | name | heapspray | process | wscript.exe | total_mb | 182 | length | 49152 | protection | PAGE_READWRITE | ||||||||||||||||||
count | 3894 | name | heapspray | process | wscript.exe | total_mb | 60 | length | 16384 | protection | PAGE_READWRITE |
file | C:\Windows\System32\rundll32.exe |