danger |
Connects to IP addresses that are no longer responding to requests (legitimate services will remain up-and-running usually) |
danger |
The process wscript.exe wrote an executable file to disk which it then attempted to execute |
warning |
File has been identified by 26 AntiVirus engines on VirusTotal as malicious |
watch |
Installs itself for autorun at Windows startup |
watch |
Network communications indicative of a potential document or script payload download was initiated by the process wscript.exe |
watch |
One or more non-whitelisted processes were created |
watch |
Wscript.exe initiated network communications indicative of a script based payload download |
watch |
wscript.exe-based dropper (JScript |
notice |
A process created a hidden window |
notice |
Connects to a Dynamic DNS Domain |
notice |
Creates a suspicious process |
notice |
Uses Windows utilities for basic Windows functionality |
info |
Command line console output was observed |
info |
Queries for the computername |