| File name: | comprobativo.vbs |
| Full analysis: | https://app.any.run/tasks/d9dead20-6e57-4174-a169-28727f096c75 |
| Verdict: | Malicious activity |
| Analysis date: | August 29, 2024, 17:33:03 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| MIME: | text/plain |
| File info: | ASCII text, with very long lines (388), with CRLF line terminators |
| MD5: | 85767CFBD60F36A38AC87509A2696FF8 |
| SHA1: | 7192EB9B2C9D283E21F5F2BE0B161607E4A1B621 |
| SHA256: | 02882EB0BBF798C89F94F625AEE7269BDA5B707F9CA37257DC5C0015D49E2B88 |
| SSDEEP: | 24576:8+EZt9TTJST35N64IqBENXGhFJ8jIQNxh7TRW6jHhfrnelfTg0jOYeP6ax1JzdLI:WTTPbV9CohAMYePHrRM81m5/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3304 | "C:\WINDOWS\System32\WScript.exe" C:\Users\admin\Desktop\comprobativo.vbs | C:\Windows\System32\wscript.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.812.10240.16384 Modules
| |||||||||||||||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | — | 16.12.66.146:443 | https://sunligthm.s3.us-east-2.amazonaws.com/aIikQNpfiIzxTOQMWC | unknown | — | — | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3304 | wscript.exe | 3.5.128.121:443 | sunligthm.s3.us-east-2.amazonaws.com | AMAZON-02 | US | shared |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
sunligthm.s3.us-east-2.amazonaws.com |
| shared |