Summary | ZeroBOX

e4C7Fwop.wsf

Category Machine Started Completed
FILE s1_win7_x6402 Sept. 5, 2023, 8:40 a.m. Sept. 5, 2023, 8:42 a.m.
Size 153.8KB
Type UTF-8 Unicode text, with very long lines, with CRLF line terminators
MD5 6f83b9c7c240127c0b92ce814d02bcb0
SHA256 9bdac91cec897f3b2fdb8ecd1fd279cdfa708ef5629d8f090d66fa96a2d8468a
CRC32 2502062C
ssdeep 384:xp5ocorp5ocorp5ocorp5ocorp5ocorp5ocorp5ocorp5ocorp5ocorp5ocorp5u:J+d
Yara None matched

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch
185.252.178.121 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

host 185.252.178.121
Time & API Arguments Status Return Repeated

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 4194320
http_method: GET
referer:
path: /gen.txt
1 13369356 0
Time & API Arguments Status Return Repeated

HttpOpenRequestW

connect_handle: 0x00cc0008
http_version:
flags: 4194320
http_method: GET
referer:
path: /gen.txt
1 13369356 0

send

buffer: !
socket: 716
sent: 1
1 1 0
dead_host 185.252.178.121:222