Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | June 16, 2023, 1:53 p.m. | June 16, 2023, 1:56 p.m. |
-
wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\update.vbs
3048
Name | Response | Post-Analysis Lookup |
---|---|---|
well-story.co.kr | 183.111.141.93 | |
html.gethompy.com | 112.175.246.91 | |
img.fmcity.com | 112.175.246.145 |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
request | GET http://well-story.co.kr/adm/inc/js/list.php?query=1 |
request | GET http://html.gethompy.com/404.html?id=ZGFoYW53 |
request | GET http://html.gethompy.com/favicon.ico |
request | GET http://img.fmcity.com/images/reseller/common/tle_info.gif |
request | GET http://img.fmcity.com/images/reseller/common/img_info.gif |
Symantec | ISB.Downloader!gen175 |
Avast | Script:SNH-gen [Trj] |
AVG | Script:SNH-gen [Trj] |