Summary | ZeroBOX

ProjectFunding_D305.wsf

Category Machine Started Completed
FILE s1_win7_x6403_us April 28, 2023, 9:05 a.m. April 28, 2023, 9:07 a.m.
Size 47.2KB
Type Non-ISO extended-ASCII text, with very long lines, with CRLF, LF line terminators
MD5 254f413905e4ba561b0a85fa7c3a4790
SHA256 0ed98f68fb91a0cae4b8ed8386055318d21934c6e3ed201f997d31cf84108ed5
CRC32 3404138B
ssdeep 768:c0TapE5tZ2yA8PPAhTX//NTBb1VSZ+qNZeHZ1Sh5Qbp6ZoNJInTte:c0Wpu2Z8PPAZ//NTBb1mNZewAGU
Yara None matched

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
149.102.255.183 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

host 149.102.255.183
Time & API Arguments Status Return Repeated

InternetCrackUrlW

url: http://149.102.255.183/acv7jAPeF4lNZaiR.dat
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 4194304
http_method: GET
referer:
path: /acv7jAPeF4lNZaiR.dat
1 13369356 0
Time & API Arguments Status Return Repeated

InternetCrackUrlW

url: http://149.102.255.183/acv7jAPeF4lNZaiR.dat
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 4194304
http_method: GET
referer:
path: /acv7jAPeF4lNZaiR.dat
1 13369356 0

send

buffer: !
socket: 860
sent: 1
1 1 0
dead_host 149.102.255.183:80