File name: | document8439.vbe |
Full analysis: | https://app.any.run/tasks/edaf014f-f046-4775-9128-44850f67f811 |
Verdict: | Malicious activity |
Analysis date: | November 08, 2019, 16:21:34 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | text/plain |
File info: | ASCII text, with CRLF line terminators |
MD5: | 0CF644E5644167001CC9EADEB9066C5E |
SHA1: | 627FAFF48E8AAC5DB76F79171D3D3FEA6D8D01EE |
SHA256: | 3D2E43D7E588E872DB9DC7B735A78FE287C972AA7904491564D0A1FC23367AD9 |
SSDEEP: | 384:vnwQkY9gWQQQQQQQQ1CUPUUUUUUggggHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHh:PaO |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
1848 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\document8439.vbe" | C:\Windows\System32\WScript.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
3320 | "C:\Windows\System32\wscript.exe" C:\Users\admin\Desktop\document8439.vbe ___- | C:\Windows\System32\wscript.exe | — | WScript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
3312 | "C:\Windows\System32\wscript.exe" C:\Users\admin\Desktop\document8439.vbe ___- ___- | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
2352 | "C:\Windows\System32\wscript.exe" C:\Users\admin\Desktop\document8439.vbe ___- ___- ___- | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
2852 | "C:\Windows\System32\wscript.exe" C:\Users\admin\Desktop\document8439.vbe ___- ___- ___- ___- | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
3408 | "C:\Windows\System32\wscript.exe" C:\Users\admin\Desktop\document8439.vbe ___- ___- ___- ___- ___- | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
996 | "C:\Windows\System32\wscript.exe" C:\Users\admin\Desktop\document8439.vbe ___- ___- ___- ___- ___- ___- | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
1636 | "C:\Windows\System32\wscript.exe" C:\Users\admin\Desktop\document8439.vbe ___- ___- ___- ___- ___- ___- ___- | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
3028 | "C:\Windows\System32\wscript.exe" C:\Users\admin\Desktop\document8439.vbe ___- ___- ___- ___- ___- ___- ___- ___- | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
3244 | "C:\Windows\System32\wscript.exe" C:\Users\admin\Desktop\document8439.vbe ___- ___- ___- ___- ___- ___- ___- ___- ___- | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 |