Report - ref-06092021_pdf.hta

ScreenShot
Created 2021.06.10 10:26 Machine s1_win7_x6401
Filename ref-06092021_pdf.hta
Type HTML document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
AI Score Not founds Behavior Score
2.2
ZERO API file : clean
VT API (file)
md5 0f21460d981d6c274325d9233d446322
sha256 8f133bf24f369fda7a2458fcad2194f5ca629bc29719152986f8626ad86648c6
ssdeep 24576:dxhleitEm5+zVcl/u5jftOoATGJpfmgFmsMhc+CVF3F3SeBHfkJuHkJaRcqp/P8Q:XtkNb
imphash
impfuzzy
  Network IP location

Signature (6cnts)

Level Description
watch A potential heapspray has been detected. 76 megabytes was sprayed onto the heap of the mshta.exe process
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Connects to a Dynamic DNS Domain
info Checks amount of memory in system
info Queries for the computername

Rules (0cnts)

Level Name Description Collection

Network (3cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://kundecamton.serveftp.com:9898/ CH Datawire Ag 185.19.85.169 clean
kundecamton.serveftp.com CH Datawire Ag 185.19.85.169 clean
185.19.85.169 CH Datawire Ag 185.19.85.169 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure