Summary | ZeroBOX

ProjectFunding_F095_Apr28.wsf

Category Machine Started Completed
FILE s1_win7_x6402 April 29, 2023, 2 p.m. April 29, 2023, 2:02 p.m.
Size 38.9KB
Type UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
MD5 5f22cd6c30898540df18fe6fb40a31d2
SHA256 61d2003abbab41089f232052d368cda88e68a8d78685e9b6ade069698dc02217
CRC32 39C5C41D
ssdeep 768:FTapEBYyKxzxzknJ9lhkeCJlmWlJdtawbVxauZP2s6gjNKBdaNm3DfTHEqH/bKo:FWpTNc9lDCJlmWlHbVxauQCjqaU3Db9
Yara None matched

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch
51.161.204.236 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

host 51.161.204.236
Time & API Arguments Status Return Repeated

InternetCrackUrlW

url: http://51.161.204.236/aNr9WxPI5p.dat
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 4194304
http_method: GET
referer:
path: /aNr9WxPI5p.dat
1 13369356 0
Time & API Arguments Status Return Repeated

InternetCrackUrlW

url: http://51.161.204.236/aNr9WxPI5p.dat
flags: 0
1 1 0

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 4194304
http_method: GET
referer:
path: /aNr9WxPI5p.dat
1 13369356 0

send

buffer: !
socket: 864
sent: 1
1 1 0
dead_host 51.161.204.236:80