Summary | ZeroBOX

ProjectFunding_D371_Apr28.wsf

Category Machine Started Completed
FILE s1_win7_x6401 April 29, 2023, 2 p.m. April 29, 2023, 2:02 p.m.
Size 45.5KB
Type UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
MD5 dd9b616637cb67d4823ca2ce569a158e
SHA256 160e0496b42fff90fb965d4cfb99a9a35a38e2622f10ba099a24becde3e0fa78
CRC32 206B01DA
ssdeep 768:JJMdW95HWNaZYBpjC5es97816gpnJsrolhkeCc/a7LZE/37YobK:JJb5yaZYBpKmrj2olDC0a7tg7Y3
Yara None matched

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
51.161.204.236 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

host 51.161.204.236
Time & API Arguments Status Return Repeated

InternetCrackUrlW

url: http://51.161.204.236/a06Ey3h4WQb7wgB2m.dat
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 4194304
http_method: GET
referer:
path: /a06Ey3h4WQb7wgB2m.dat
1 13369356 0
Time & API Arguments Status Return Repeated

InternetCrackUrlW

url: http://51.161.204.236/a06Ey3h4WQb7wgB2m.dat
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 4194304
http_method: GET
referer:
path: /a06Ey3h4WQb7wgB2m.dat
1 13369356 0

send

buffer: !
socket: 868
sent: 1
1 1 0
dead_host 51.161.204.236:80