File name:

a.txt

Full analysis: https://app.any.run/tasks/dc4873db-50b2-44ca-baad-1beb5ec9eab0
Verdict: Malicious activity
Analysis date: October 03, 2025, 18:02:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
oietif
killmbr
Indicators:
MIME: text/x-msdos-batch
File info: DOS batch file, ASCII text, with CRLF line terminators
MD5:

EEA9C923DE21CC5BFAACE99C094F9B85

SHA1:

CED567456CC21F84C42F9562E7AE00A336EBEE7F

SHA256:

38701663F3C4DCF7303103D1317BAB4032E0F8B1F8E2B2EE42B9EDB229FA442A

SSDEEP:

96:jrhrhrhrhrhrhrhrhrhrhrhrhrhrhrhrhrhrhrhrhrhrhrhrhrhrhrhrhrhrhrhp:jrhrhrhrhrhrhrhrhrhrhrhrhrhrhrhJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Uses base64 encoding (SCRIPT)

      • cscript.exe (PID: 1932)
      • cscript.exe (PID: 2856)
      • cscript.exe (PID: 3428)
    • Gets a file object corresponding to the file in a specified path (SCRIPT)

      • cscript.exe (PID: 1932)
      • cscript.exe (PID: 3428)
      • cscript.exe (PID: 2856)
    • OIETIF has been detected

      • cmd.exe (PID: 2892)
      • cmd.exe (PID: 3440)
  • SUSPICIOUS

    • Sets XML DOM element text (SCRIPT)

      • cscript.exe (PID: 1932)
      • cscript.exe (PID: 2856)
      • cscript.exe (PID: 3428)
    • Creates XML DOM element (SCRIPT)

      • cscript.exe (PID: 1932)
      • cscript.exe (PID: 2856)
      • cscript.exe (PID: 3428)
    • Script creates XML DOM node (SCRIPT)

      • cscript.exe (PID: 1932)
      • cscript.exe (PID: 2856)
      • cscript.exe (PID: 3428)
    • The process executes JS scripts

      • cmd.exe (PID: 2604)
      • cmd.exe (PID: 2892)
      • cmd.exe (PID: 3440)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • cscript.exe (PID: 1932)
      • cscript.exe (PID: 3428)
      • cscript.exe (PID: 2856)
    • Creates a Stream, which may work with files, input/output devices, pipes, or TCP/IP sockets (SCRIPT)

      • cscript.exe (PID: 1932)
      • cscript.exe (PID: 2856)
      • cscript.exe (PID: 3428)
    • Saves data to a binary file (SCRIPT)

      • cscript.exe (PID: 1932)
      • cscript.exe (PID: 2856)
      • cscript.exe (PID: 3428)
    • Writes binary data to a Stream object (SCRIPT)

      • cscript.exe (PID: 1932)
      • cscript.exe (PID: 2856)
      • cscript.exe (PID: 3428)
    • Executable content was dropped or overwritten

      • cscript.exe (PID: 1932)
    • Creates a Folder object (SCRIPT)

      • cscript.exe (PID: 1932)
      • cscript.exe (PID: 2856)
      • cscript.exe (PID: 3428)
    • Reads the Internet Settings

      • cscript.exe (PID: 1932)
  • INFO

    • Creates files or folders in the user directory

      • cscript.exe (PID: 1932)
      • cscript.exe (PID: 2856)
      • cscript.exe (PID: 3428)
    • Reads security settings of Internet Explorer

      • cscript.exe (PID: 1932)
      • cscript.exe (PID: 2856)
      • cscript.exe (PID: 3428)
    • Manual execution by a user

      • notepad.exe (PID: 456)
      • cmd.exe (PID: 2892)
      • cmd.exe (PID: 3440)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
64
Monitored processes
7
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
456"C:\Windows\System32\NOTEPAD.EXE" C:\Users\admin\Desktop\a.batC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1932cscript x.jsC:\Windows\System32\cscript.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2604C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\a.txt.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2856cscript x.jsC:\Windows\System32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2892"C:\Windows\System32\cmd.exe" /C "C:\Users\admin\Desktop\a.bat" C:\Windows\System32\cmd.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3428cscript x.jsC:\Windows\System32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3440"C:\Windows\System32\cmd.exe" /C "C:\Users\admin\Desktop\a.bat" C:\Windows\System32\cmd.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
3 484
Read events
3 476
Write events
8
Delete events
0

Modification events

(PID) Process:(1932) cscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1932) cscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1932) cscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1932) cscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
1
Suspicious files
3
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
456notepad.exeC:\Users\admin\Desktop\a.battext
MD5:84600BBE3ABA4D168A1185E6759FE6DE
SHA256:1D66467E129A550CF4DE4952B8A619D55A04D85A5D2C6051CF5087C8C8105DFC
1932cscript.exeC:\Users\admin\AppData\Roaming\s.exeexecutable
MD5:0C197A0CD4799BE5B1BB564B11E5FF4B
SHA256:6A57A60FA6ED7CAA3FE572F3B91EB76C3C1CDF1513FAC03F6552463606779A49
2604cmd.exeC:\Users\admin\AppData\Roaming\xtext
MD5:00B5B0EC0518F07508D97789F6D9A432
SHA256:236AAE281C70B13B0D56667AEBF8104361ECCD946A71216FC5AA3673E51CAB3A
1932cscript.exeC:\Users\admin\AppData\Roaming\z.zipcompressed
MD5:BAB18C442D5CA7D3C10FB659CC3E3876
SHA256:4E8C1230A770EAE593DE85F70BD68E93BADC14D85028835A07D76C1F582DBAE5
2604cmd.exeC:\Users\admin\AppData\Roaming\x.jstext
MD5:D94C93F882CF030ED9D66CC35796731D
SHA256:F7941E6BE49D757B46B9D6FB5ECB15392EC36A64E8906692D2EEB2BA9FC67CB6
2892cmd.exeC:\Users\admin\AppData\Roaming\xtext
MD5:071CAB6CD47F74B26A69DBF476C737E3
SHA256:880D79DB811912514E42D4FACB847CFD27B78CEBCE94015BF5BB5EA8473A87F6
2892cmd.exeC:\Users\admin\AppData\Roaming\x.jstext
MD5:D94C93F882CF030ED9D66CC35796731D
SHA256:F7941E6BE49D757B46B9D6FB5ECB15392EC36A64E8906692D2EEB2BA9FC67CB6
2856cscript.exeC:\Users\admin\AppData\Roaming\z.zipcompressed
MD5:164F50D9DBD6E2B7F73CD9C02332A429
SHA256:02A9069BB3E11B66D7C369C6CF3EEC71417B5F8495FA6F9C7E6E7C89E9546706
3440cmd.exeC:\Users\admin\AppData\Roaming\xtext
MD5:071CAB6CD47F74B26A69DBF476C737E3
SHA256:880D79DB811912514E42D4FACB847CFD27B78CEBCE94015BF5BB5EA8473A87F6
3440cmd.exeC:\Users\admin\AppData\Roaming\x.jstext
MD5:D94C93F882CF030ED9D66CC35796731D
SHA256:F7941E6BE49D757B46B9D6FB5ECB15392EC36A64E8906692D2EEB2BA9FC67CB6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1076
svchost.exe
224.0.0.252:5355
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.46
whitelisted

Threats

No threats detected
No debug info