Report - index.html

PNG Format MSOffice File JPEG Format
ScreenShot
Created 2023.08.23 09:25 Machine s1_win7_x6401
Filename index.html
Type HTML document, ASCII text, with very long lines
AI Score Not founds Behavior Score
2.2
ZERO API file : clean
VT API (file)
md5 880b2ed0181f9c6ca6b85ba7ead160c7
sha256 61bd01bc2617574a349501817cffbd7ef529c94ddbf83fdc566e7b1b53ff7250
ssdeep 96:/GvSSWDjLYNWihOjLCfsIpcToXwAEKZwN1liabixKsggSoEtCKihj:/YFWL8dIjLBa/TZwNUaal
imphash
impfuzzy
  Network IP location

Signature (5cnts)

Level Description
watch Resumed a suspended thread in a remote process potentially indicative of process injection
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Performs some HTTP requests
notice Uses Windows utilities for basic Windows functionality

Rules (3cnts)

Level Name Description Collection
info JPEG_Format_Zero JPEG Format binaries (download)
info Microsoft_Office_File_Zero Microsoft Office File binaries (download)
info PNG_Format_Zero PNG Format binaries (download)

Network (3cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://challenges.cloudflare.com/ US CLOUDFLARENET 104.17.2.184 clean
challenges.cloudflare.com US CLOUDFLARENET 104.17.2.184 clean
104.17.3.184 US CLOUDFLARENET 104.17.3.184 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure