| File name: | nitro-cleanup.vbs |
| Full analysis: | https://app.any.run/tasks/4018750d-086d-4099-8153-bfc38569c2db |
| Verdict: | Malicious activity |
| Analysis date: | June 19, 2023, 11:09:57 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with CRLF line terminators |
| MD5: | 9CF549A336C3977FC60C40D7B1CF74B4 |
| SHA1: | D220EA828A96D97EA9BEA30CD2ACD6417C249C31 |
| SHA256: | 18C955698EEC8EC58A277B4550FFB8F08419E7937C33E169E1396A1B748A7E8D |
| SSDEEP: | 384:r5ZOqviIfuP7zNGeNqvqw6Ylljp+bhb1dRurF4G9Q5CdIsqRPblk:reqmNVSqw6Y7jvh |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 292 | REG DELETE "HKCR\Wow6432Node\AppID\NPNitroIE.dll" /f | C:\Windows\System32\reg.exe | — | cscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 596 | REG DELETE "HKCR\AppID\{3A7B4EA1-8CA8-4629-B09A-FB4EE0632BA8}" /f | C:\Windows\System32\reg.exe | — | cscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 976 | REG DELETE "HKCR\Wow6432Node\TypeLib\{73BA4610-4C33-4056-9141-9C3E3DF75428}" /f | C:\Windows\System32\reg.exe | — | cscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1236 | REG DELETE "HKCU\Software\Microsoft\Office\{0}\Outlook\Addins\NitroPDFProfessional.MSOfficeAddin11}" /f | C:\Windows\System32\reg.exe | — | cscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1688 | REG DELETE "HKCR\AppID\NPNitroIE.dll" /f | C:\Windows\System32\reg.exe | — | cscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2000 | "C:\Windows\System32\net.exe" STOP spooler | C:\Windows\System32\net.exe | — | cscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2212 | REG DELETE "HKCR\TypeLib\{73BA4610-4C33-4056-9141-9C3E3DF75428}" /f | C:\Windows\System32\reg.exe | — | cscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2224 | REG DELETE "HKCR\TypeLib\{3422E9DB-7B00-4552-B016-6FBF93C5A2D8}" /f | C:\Windows\System32\reg.exe | — | cscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2436 | REG DELETE "HKCR\Wow6432Node\AppID\{3A7B4EA1-8CA8-4629-B09A-FB4EE0632BA8}" /f | C:\Windows\System32\reg.exe | — | cscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2732 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\nitro-cleanup.vbs" | C:\Windows\System32\wscript.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| (PID) Process: | (2732) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2732) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2732) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2732) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2896) cscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2896) cscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2896) cscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2896) cscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2896 | cscript.exe | C:\Users\admin\Desktop\nitro-cleanup-tool.log | text | |
MD5:5F5709CE53AE6A226ABFB12FB07C0E07 | SHA256:700B0527F5EB4B21E7102CFFB97AFA813DFADF5ADF0266B122049F098039D586 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |