ScreenShot
Created 2024.07.04 09:46 Machine s1_win7_x6403
Filename ggrace.vbs
Type Little-endian UTF-16 Unicode text, with very long lines, with CRLF, CR line terminators
AI Score Not founds Behavior Score
10.0
ZERO API file : mailcious
VT API (file) 7 detected (SAgent, Detected)
md5 82e15bfd5d0ba8fb1f211f4b04c3e404
sha256 6d72df6b1b7ab5850faf88a08d02dd7418d7fa4b0ea82491836990992c92bcee
ssdeep 768:gmgQFBD04DXA/ZFay4c+n2/0LKj1Ln3vK8FqBKEtjb:AQEhZFay4c+n2cLKxLn/K8FqcKjb
imphash
impfuzzy
  Network IP location

Signature (6cnts)

Level Description
danger Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually)
watch Network communications indicative of a potential document or script payload download was initiated by the process wscript.exe
watch Wscript.exe initiated network communications indicative of a script based payload download
watch wscript.exe-based dropper (JScript
notice File has been identified by 7 AntiVirus engines on VirusTotal as malicious
info One or more processes crashed

Rules (0cnts)

Level Name Description Collection

Network (2cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
paste.ee FR Avenir Telematique SAS 185.26.104.247 mailcious
185.26.104.247 FR Avenir Telematique SAS 185.26.104.247 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure