File name: | document8439.vbe |
Full analysis: | https://app.any.run/tasks/d0919cf2-582d-4754-8eda-2b30720b6274 |
Verdict: | Malicious activity |
Analysis date: | November 08, 2019, 16:15:22 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | text/plain |
File info: | ASCII text, with CRLF line terminators |
MD5: | 0CF644E5644167001CC9EADEB9066C5E |
SHA1: | 627FAFF48E8AAC5DB76F79171D3D3FEA6D8D01EE |
SHA256: | 3D2E43D7E588E872DB9DC7B735A78FE287C972AA7904491564D0A1FC23367AD9 |
SSDEEP: | 384:vnwQkY9gWQQQQQQQQ1CUPUUUUUUggggHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHh:PaO |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
1888 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\document8439.vbe" | C:\Windows\System32\WScript.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
3116 | "C:\Windows\System32\wscript.exe" C:\Users\admin\AppData\Local\Temp\document8439.vbe ___- | C:\Windows\System32\wscript.exe | — | WScript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
2356 | "C:\Windows\System32\wscript.exe" C:\Users\admin\AppData\Local\Temp\document8439.vbe ___- ___- | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
272 | "C:\Windows\System32\wscript.exe" C:\Users\admin\AppData\Local\Temp\document8439.vbe ___- ___- ___- | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
3084 | "C:\Windows\System32\wscript.exe" C:\Users\admin\AppData\Local\Temp\document8439.vbe ___- ___- ___- ___- | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
940 | "C:\Windows\System32\wscript.exe" C:\Users\admin\AppData\Local\Temp\document8439.vbe ___- ___- ___- ___- ___- | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
4028 | "C:\Windows\System32\wscript.exe" C:\Users\admin\AppData\Local\Temp\document8439.vbe ___- ___- ___- ___- ___- ___- | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
2776 | "C:\Windows\System32\wscript.exe" C:\Users\admin\AppData\Local\Temp\document8439.vbe ___- ___- ___- ___- ___- ___- ___- | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
1708 | "C:\Windows\System32\wscript.exe" C:\Users\admin\AppData\Local\Temp\document8439.vbe ___- ___- ___- ___- ___- ___- ___- ___- | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
2424 | "C:\Windows\System32\wscript.exe" C:\Users\admin\AppData\Local\Temp\document8439.vbe ___- ___- ___- ___- ___- ___- ___- ___- ___- | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 |