Report - tarksloader.hta

ScreenShot
Created 2025.03.27 10:28 Machine s1_win7_x6401
Filename tarksloader.hta
Type HTML document, UTF-8 Unicode text, with very long lines
AI Score Not founds Behavior Score
1.0
ZERO API
VT API (file)
md5 3ffacc93b7d3de5d0d47f31853807f49
sha256 8c8443d340c374af33e1f00a52a54c56d9b64b91eb50706703ad0b57f62fe9fa
ssdeep 6144:Nrst7pOL/saqkPV97HILqgIDSsqI19VvZJT3CqbMrhryf65NRPaCieMjAkvCJv1v:lst7pOL/saqkPV97HILqgIDSsqI19Vv4
imphash
impfuzzy
  Network IP location

Signature (3cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
info Checks amount of memory in system

Rules (0cnts)

Level Name Description Collection

Network (2cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
github.githubassets.com US FASTLY 185.199.109.154
185.199.111.154 US FASTLY 185.199.111.154

Suricata ids



Similarity measure (PE file only) - Checking for service failure