Report - 745584778.js

ScreenShot
Created 2021.03.29 17:59 Machine s1_win7_x3201
Filename 745584778.js
Type ASCII text, with very long lines, with CRLF line terminators
AI Score Not founds Behavior Score
5.0
ZERO API file : clean
VT API (file)
md5 65f5e916c44ce0e15b66dc940c1e70c1
sha256 00113d155f28b4bcdf2e251c176c8d3119ebea1e85280aafa4d2eee38989eb01
ssdeep 192:d2UPZsrcWYtt3UOtjuFm4vxb0og4qPoC6aAUGI8ZvLbEYkdwM+Lo9Rrkllmin2dh:d2isrouFAtQaDGIO37kCkreoyTAg0BJx
imphash
impfuzzy
  Network IP location

Signature (10cnts)

Level Description
danger The process wscript.exe wrote an executable file to disk which it then attempted to execute
watch Creates or sets a registry key to a long series of bytes
watch Installs itself for autorun at Windows startup
watch One or more non-whitelisted processes were created
notice A process created a hidden window
notice Creates a suspicious process
notice Creates executable files on the filesystem
notice Uses Windows utilities for basic Windows functionality
info Command line console output was observed
info Queries for the computername

Rules (1cnts)

Level Name Description Collection
info IsSuspicious Might be PE Virus binaries (upload)

Network (3cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://192.168.56.103:2869/upnphost/udhisapi.dll?content=uuid:d96d86f3-ac35-41f2-9523-f4e50073f2f3 Unknown 192.168.56.103 clean
http://192.168.56.103:5357/da8ea474-550f-433d-b444-54d2081d1d24/ Unknown 192.168.56.103 clean
http://192.168.56.103:2869/upnphost/udhisapi.dll?content=uuid:2d284ad3-5648-4376-8360-b0559e35418f Unknown 192.168.56.103 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure