Report - NDA_D753_May_10.wsf

ScreenShot
Created 2023.05.11 09:21 Machine s1_win7_x6402
Filename NDA_D753_May_10.wsf
Type UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
AI Score Not founds Behavior Score
10.0
ZERO API file : clean
VT API (file)
md5 8624646d76bcbcc599c9321fb06cddd1
sha256 4f0f597046a24c165dd54f35dd5ef818d3c6961890923ebb268616931d5ba8d4
ssdeep 768:qN16gyU9bTCVw0TaKCwcbTuinOKsnnWpyTvTlhkehECw4tGtW3NlhkehER9:qN16gR+Vw0WZLEJWp4vTlDhvAtW3NlDu
imphash
impfuzzy
  Network IP location

Signature (10cnts)

Level Description
danger Connects to IP addresses that are no longer responding to requests (legitimate services will remain up-and-running usually)
danger A potential heapspray has been detected. 4401 megabytes was sprayed onto the heap of the wscript.exe process
warning Uses WMI to create a new process
watch Communicates with host for which no DNS query was performed
watch Network communications indicative of a potential document or script payload download was initiated by the process wscript.exe
watch Wscript.exe initiated network communications indicative of a script based payload download
watch wscript.exe-based dropper (JScript
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice Performs some HTTP requests
info Queries for the computername

Rules (0cnts)

Level Name Description Collection

Network (8cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://207.148.14.105/a3hdJG9pj.dat US AS-CHOOPA 207.148.14.105 clean
http://149.102.225.18/a3hdJG9pj.dat Unknown 149.102.225.18 clean
45.155.37.101 GB SHOCK-1 45.155.37.101 mailcious
144.208.127.242 US SHOCK-1 144.208.127.242 mailcious
149.102.225.18 Unknown 149.102.225.18 mailcious
91.193.16.139 NL HZ Hosting Ltd 91.193.16.139 mailcious
5.42.221.144 Unknown 5.42.221.144 mailcious
207.148.14.105 US AS-CHOOPA 207.148.14.105 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure