Report - curriculum_vitae-copie.vbs

ScreenShot
Created 2023.03.07 09:57 Machine s1_win7_x6403
Filename curriculum_vitae-copie.vbs
Type ASCII text, with very long lines, with no line terminators
AI Score Not founds Behavior Score
10.0
ZERO API file : clean
VT API (file) 1 detected ()
md5 5e175b3bb3d8dc97174238b3f620992c
sha256 114db15adc53b9ac6c4de60512aeca4f99df4da7b465ee7389a3140bd58c7138
ssdeep 1536:9Dur2+AwU45wqUMRfjyJ7uoaFMFYgw9K7vLe4xTQKSlgP6z2tfC/i:Bui+95dHLoe3Z9ke4xTQnlGhCq
imphash
impfuzzy
  Network IP location

Signature (5cnts)

Level Description
watch Network communications indicative of a potential document or script payload download was initiated by the process wscript.exe
watch Wscript.exe initiated network communications indicative of a script based payload download
watch wscript.exe-based dropper (JScript
notice File has been identified by one AntiVirus engine on VirusTotal as malicious
info One or more processes crashed

Rules (0cnts)

Level Name Description Collection

Network (2cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
gitlab.com US CLOUDFLARENET 172.65.251.78 malware
172.65.251.78 US CLOUDFLARENET 172.65.251.78 malware

Suricata ids



Similarity measure (PE file only) - Checking for service failure