Summary | ZeroBOX

Claim_F419.wsf

Category Machine Started Completed
FILE s1_win7_x6401 April 26, 2023, 9:27 a.m. April 26, 2023, 9:29 a.m.
Size 95.1KB
Type Non-ISO extended-ASCII text, with very long lines, with CRLF, LF line terminators
MD5 d40ce5e628bc2fb4df85539432a90fb7
SHA256 7474a7908c38cf8560813ade4511204e5ca1b2f604e8e401b5f2951b86a73a6b
CRC32 0D5F0BB9
ssdeep 1536:jl3DLP1CQid1fMdhbNQidV7heyiQweDQUSDumRXCl4yWpyCNjg9+MOTnps3gNiAj:jBRg0bTMecum9Cl4yWHjg9+MQQ6
Yara None matched

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
185.39.18.107 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

host 185.39.18.107
Time & API Arguments Status Return Repeated

InternetCrackUrlW

url: http://185.39.18.107/aDktGgiub.dat
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 4194304
http_method: GET
referer:
path: /aDktGgiub.dat
1 13369356 0
Time & API Arguments Status Return Repeated

InternetCrackUrlW

url: http://185.39.18.107/aDktGgiub.dat
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 4194304
http_method: GET
referer:
path: /aDktGgiub.dat
1 13369356 0

send

buffer: !
socket: 864
sent: 1
1 1 0
dead_host 185.39.18.107:80