Report - scan_doc_000_371.js

ScreenShot
Created 2025.02.20 03:54 Machine s1_win7_x6401
Filename scan_doc_000_371.js
Type UTF-8 Unicode text, with very long lines, with CRLF line terminators
AI Score Not founds Behavior Score
1.4
ZERO API file : clean
VT API (file) 6 detected (ExpKit, fbenub, ELBP, Detected)
md5 60aa9509a011433b98f1a3677183bfa9
sha256 101c7c3c8ef65809c092f06fb34c2e0661b98944c3914b0a28824cde6813c7ea
ssdeep 12288:sWAmOGMiKvfXXr8D4tm4KPiEPH4jWV5ENsU8ig25EtLbHd:uAMiKvfX7/DEPH4jWV5/tLbHd
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
notice Executes one or more WMI queries
notice Executes one or more WMI queries which can be used to identify virtual machines
notice File has been identified by 6 AntiVirus engines on VirusTotal as malicious
info Queries for the computername

Rules (0cnts)

Level Name Description Collection

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure