Report - datingloverstartingAgain.vbs

Created 2024.07.06 18:18 Machine s1_win7_x6401
Filename datingloverstartingAgain.vbs
Type Little-endian UTF-16 Unicode text, with CRLF, CR line terminators
AI Score Not founds Behavior Score
ZERO API file : clean
VT API (file) 7 detected (SLoad, druvzi, Detected, Eldorado)
md5 66decb1e47d3173c8046c1a921244190
sha256 f292f94387a5349a067022f2c3377681987a49e2030ca18b611a52cf5ad30c6b
ssdeep 96:CA2i3jdA2H0A2B6G0A2bA2F3jdA2f2pLd3jkoA2k:Cyh3070LVRP2pLdYo0
  Network IP location

Signature (3cnts)

Level Description
danger Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually)
watch Communicates with host for which no DNS query was performed
notice File has been identified by 7 AntiVirus engines on VirusTotal as malicious

Rules (0cnts)

Level Name Description Collection

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ? Unknown mailcious

Suricata ids

Similarity measure (PE file only) - Checking for service failure