Report - Docs_Request_06(62).js

ScreenShot
Created 2023.06.15 10:42 Machine s1_win7_x6403
Filename Docs_Request_06(62).js
Type ASCII text, with very long lines, with no line terminators
AI Score Not founds Behavior Score
10.0
ZERO API file : clean
VT API (file)
md5 9a27bf21439229a96a0c621003e867e7
sha256 76c2fbd003945044ebb5cbd5952c170f3a3f5ffce7f1599eb4d551ab6d4a90bf
ssdeep 24576:m9mM16EtVEh941Wpu5UFbSgk8FQANZTOGyP0j8ZKAmxgEUS22i2oWUuNv8ROJI5n:OmM16EtVEh941Wpu5UFbSgk8FQANZTOT
imphash
impfuzzy
  Network IP location

Signature (3cnts)

Level Description
watch Network communications indicative of a potential document or script payload download was initiated by the process wscript.exe
watch Wscript.exe initiated network communications indicative of a script based payload download
watch wscript.exe-based dropper (JScript

Rules (0cnts)

Level Name Description Collection

Network (2cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
masar-alulaedu.com US A2HOSTING 68.66.248.36 malware
68.66.248.36 US A2HOSTING 68.66.248.36 malware

Suricata ids



Similarity measure (PE file only) - Checking for service failure