Report - photo.htm

Javascript_Blob AntiDebug AntiVM MSOffice File
ScreenShot
Created 2025.04.18 03:51 Machine s1_win7_x6401
Filename photo.htm
Type HTML document, ASCII text, with very long lines
AI Score Not founds Behavior Score
3.0
ZERO API file : clean
VT API (file)
md5 e030e64f0874a226ff367aac2c0fd45d
sha256 051d4fc33d3eecee192ab3c4325eaac8eaf89d31ffa785a32458a958973e3474
ssdeep 3072:E6E6K65DBmuSH2/mtSaSESpS3S8S5SfALG9qF8OGF4KSkOqSES9glhGSnSVqSBS9:3Bme/folh+HcW0X
imphash
impfuzzy
  Network IP location

Signature (7cnts)

Level Description
watch Resumed a suspended thread in a remote process potentially indicative of process injection
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Creates executable files on the filesystem
notice Performs some HTTP requests
notice Uses Windows utilities for basic Windows functionality
notice Yara rule detected in process memory

Rules (10cnts)

Level Name Description Collection
notice Javascript_Blob use blob(Binary Large Objec) javascript binaries (download)
info anti_dbg Checks if being debugged memory
info DebuggerCheck__GlobalFlags (no description) memory
info DebuggerCheck__QueryInfo (no description) memory
info DebuggerHiding__Active (no description) memory
info DebuggerHiding__Thread (no description) memory
info disable_dep Bypass DEP memory
info Microsoft_Office_File_Zero Microsoft Office File binaries (download)
info SEH__vectored (no description) memory
info ThreadControl__Context (no description) memory

Network (11cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
https://static.xx.fbcdn.net/rsrc.php/v4ikYC4/ye/l/pl_PL/4UJPryDl6vQ.js US FACEBOOK 157.240.215.14 clean
https://static.xx.fbcdn.net/rsrc.php/v4/yf/r/1Fs8rBQNSz9.js US FACEBOOK 157.240.215.14 clean
https://static.xx.fbcdn.net/rsrc.php/v4ii3Z4/yC/l/pl_PL/yosNSWC8z_t.js US FACEBOOK 157.240.215.14 clean
https://static.xx.fbcdn.net/rsrc.php/v4iiH84/y-/l/pl_PL/gYR6XdR5Jlz.js US FACEBOOK 157.240.215.14 clean
https://static.xx.fbcdn.net/rsrc.php/v4ih9w4/yH/l/pl_PL/u5eNGFq3WhgRnT2Z3dd70t0BUXE7BctrMPOyxLFPsfmEuk8vLtdffcjlUV7BVDeuTY5KnvPi9YnXpZxNQZM-9qQm9FNo6EWfQ8TbUQ5LoxjLorwy1DKBSsTAnxMKEPueP2LsGoiMt_RY_Bx4ZxpRYeCkYXwettdgmkSZ1wuvR42D6xbRi0SBmuDjByG_AXEDxgHlco1 US FACEBOOK 157.240.215.14 clean
https://static.xx.fbcdn.net/rsrc.php/v4i3Z54/y-/l/pl_PL/QI6a6eMB_Rd.js US FACEBOOK 157.240.215.14 clean
https://static.xx.fbcdn.net/rsrc.php/v5/yP/l/0,cross/hdizZSl7vs1pXN_QbzK5g5.css US FACEBOOK 157.240.215.14 clean
https://static.xx.fbcdn.net/rsrc.php/v4i1hI4/yB/l/pl_PL/iZlynKqupyeJxZpg7m_h7q81-kCxOHvH-jJTXU6VJG0Kqf4IO3ef2VeaNyM5x7xjrVVSiB1Bshw99hbqzKu9tM7F_Y7Xk1cp1ZY2YkxqMpyzfiubWjH6HmqBA3tJbBUoPL58XEhTixJo7zxRE8M1ZFyQWnT9xFtruSNYVw8-m6b_Uv7ObcEfnFd0zmg_Lq0Ssl_q8so US FACEBOOK 157.240.215.14 clean
https://static.xx.fbcdn.net/rsrc.php/v4ioN94/ys/l/pl_PL/NuW542bho60.js US FACEBOOK 157.240.215.14 clean
static.xx.fbcdn.net IE FACEBOOK 31.13.82.7 clean
157.240.215.14 US FACEBOOK 157.240.215.14 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure