Report - Update (1).js

ScreenShot
Created 2024.07.23 15:08 Machine s1_win7_x6401
Filename Update (1).js
Type ASCII text, with very long lines
AI Score Not founds Behavior Score
10.0
ZERO API file : clean
VT API (file)
md5 9d28c59e246359f102981b014dd875ed
sha256 6877b33291a4043468f9b488e908885af0d672d4ffcd48f02717b60db047d7ed
ssdeep 96:eQm4lOgxYZBPt9VNKmAl9B8X3J1KIKPtB+774yaJD2TmoJQW3xpY6PWxNGo5b:e5yrkBPt9VOnB8nJ1Kn834jJDa1mWBpI
imphash
impfuzzy
  Network IP location

Signature (3cnts)

Level Description
watch Network communications indicative of a potential document or script payload download was initiated by the process wscript.exe
watch Wscript.exe initiated network communications indicative of a script based payload download
watch wscript.exe-based dropper (JScript

Rules (0cnts)

Level Name Description Collection

Network (2cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
byqb.loyalty.hienphucuanhanloai.org US GBTCLOUD 45.88.186.194 clean
45.88.186.194 US GBTCLOUD 45.88.186.194 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure