Report - msg_19_12_01384462651-7272716591.vbs

ScreenShot
Created 2021.06.25 14:07 Machine s1_win7_x6402
Filename msg_19_12_01384462651-7272716591.vbs
Type ASCII text, with CRLF line terminators
AI Score Not founds Behavior Score
10.0
ZERO API file : clean
VT API (file) 33 detected (GIRansom, SCARAB, SMJS02, ExpKit, ewjogg, VBSDldr, Drldr, Schopets, ai score=100, TOPIS, 9cv31yapexE, GlobeImposter)
md5 861f2ecb29c3bd4ab3e1a13f10422e5d
sha256 3b931f0f86495e020d9c7c7029a7887e4e631dd7331341c1ac0fa4119103f982
ssdeep 96:SixZv/u/s/YjiVrJWC/pn2hNEp+TgTP4+by0TUkMKNNFD3qJUBm+Vx5O6di:D5/u/s/YjiVFWC/pn2TEpTg+jwkMYjqj
imphash
impfuzzy
  Network IP location

Signature (6cnts)

Level Description
danger File has been identified by 33 AntiVirus engines on VirusTotal as malicious
watch Communicates with host for which no DNS query was performed
watch Network communications indicative of a potential document or script payload download was initiated by the process wscript.exe
watch Wscript.exe initiated network communications indicative of a script based payload download
watch wscript.exe-based dropper (JScript
notice Performs some HTTP requests

Rules (0cnts)

Level Name Description Collection

Network (5cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://2-wave.com/MjdyeUHS32? JP GMO CLOUD K.K. 153.122.177.219 clean
intra.cfecgcaquitaine.com Unknown malware
2-wave.com JP GMO CLOUD K.K. 153.122.177.219 malware
depomedikal.com Unknown 0.0.0.0 malware
153.122.177.219 JP GMO CLOUD K.K. 153.122.177.219 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure