Summary | ZeroBOX

Complaint_Copy_798708.wsf

Category Machine Started Completed
FILE s1_win7_x6401 April 20, 2023, 11:20 a.m. April 20, 2023, 11:22 a.m.
Size 17.6KB
Type ASCII text, with very long lines, with CRLF, LF line terminators
MD5 c91431eb09675290e644c2e8a07213cd
SHA256 b3fe399fba93aff43112369ae44a6db80a16dcaf72b5dd5a66a4a6ee216e15ec
CRC32 122BDF06
ssdeep 384:X3kgIqQwE5nyQaDfTEnJEBtjHzTvfK9whxUPbJmUtPYZWxDUk:X3JIm3DfTdjTTyX1ZOWr
Yara None matched

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
85.239.53.73 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

host 85.239.53.73
Time & API Arguments Status Return Repeated

InternetCrackUrlW

url: http://85.239.53.73/aO03psmvtKQU.dat
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 4194304
http_method: GET
referer:
path: /aO03psmvtKQU.dat
1 13369356 0
Time & API Arguments Status Return Repeated

InternetCrackUrlW

url: http://85.239.53.73/aO03psmvtKQU.dat
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 4194304
http_method: GET
referer:
path: /aO03psmvtKQU.dat
1 13369356 0

send

buffer: !
socket: 872
sent: 1
1 1 0
dead_host 85.239.53.73:80