Summary | ZeroBOX

Complaint_Copy_195040.wsf

Category Machine Started Completed
FILE s1_win7_x6402 April 21, 2023, 8:56 a.m. April 21, 2023, 8:58 a.m.
Size 17.3KB
Type UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
MD5 9ebb0b07e289a4882ba12b0e7549d064
SHA256 3018367aa693f37ae9cfef2573a6ab0b53ab40e536d7499dcec089e8f9a14967
CRC32 3501EEAA
ssdeep 192:Lz0cYSDDNlhkeEFZV8QBg21unMLY9+bsyE/ZzhhuUNhOPE63ku11hkoD1hkoLoGN:x3NlhkeCzg9MLYEoyKok0kHbJAMYgyZN
Yara None matched

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch
51.83.193.0 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

host 51.83.193.0
Time & API Arguments Status Return Repeated

InternetCrackUrlW

url: http://51.83.193.0/aO03psmvtKQUf9B5.dat
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 4194304
http_method: GET
referer:
path: /aO03psmvtKQUf9B5.dat
1 13369356 0
Time & API Arguments Status Return Repeated

InternetCrackUrlW

url: http://51.83.193.0/aO03psmvtKQUf9B5.dat
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 4194304
http_method: GET
referer:
path: /aO03psmvtKQUf9B5.dat
1 13369356 0

send

buffer: !
socket: 864
sent: 1
1 1 0
dead_host 51.83.193.0:80