| File name: | cscript.exe |
| Full analysis: | https://app.any.run/tasks/afd5367d-31dc-4a5d-8830-7955fd19d42e |
| Verdict: | Malicious activity |
| Analysis date: | November 30, 2023, 23:31:36 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows |
| MD5: | 16A5CCEADAC88938E627D7EC9A0DCF7F |
| SHA1: | 7821CD004BCA8A52F27FDC9D5BA90E0FD085942B |
| SHA256: | 9DA23BFC87A60275ADF3D0EBDA2CE71FE65D7D03EFA21060E39652F0DF87129A |
| SSDEEP: | 98304:8rkPiI1suDbjR6Y9nCaNOMJYECTJklpS5bPjlYiLonqMnksUKfrC7lORacGp4BLl:hgohNWYDmS66 |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2023:11:30 14:26:29+01:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.37 |
| CodeSize: | 171008 |
| InitializedDataSize: | 115200 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xc1a0 |
| OSVersion: | 5.2 |
| ImageVersion: | - |
| SubsystemVersion: | 5.2 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.812.10240.16384 |
| ProductVersionNumber: | 5.812.10240.16384 |
| FileFlagsMask: | 0x0003 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Microsoft Corporation |
| FileDescription: | Microsoft ® Console Based Script Host |
| FileVersion: | 5.812.10240.16384 |
| InternalName: | cscript.exe |
| LegalCopyright: | © Microsoft Corporation. All rights reserved. |
| OriginalFileName: | cscript.exe |
| ProductName: | Microsoft ® Windows Script Host |
| ProductVersion: | 5.812.10240.16384 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1168 | "C:\Users\admin\AppData\Local\Temp\cscript.exe" | C:\Users\admin\AppData\Local\Temp\cscript.exe | — | cscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Console Based Script Host Exit code: 0 Version: 5.812.10240.16384 Modules
| |||||||||||||||
| 2264 | "C:\Users\admin\AppData\Local\Temp\cscript.exe" | C:\Users\admin\AppData\Local\Temp\cscript.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Console Based Script Host Exit code: 0 Version: 5.812.10240.16384 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2264 | cscript.exe | C:\Users\admin\AppData\Local\Temp\_MEI22642\_bz2.pyd | executable | |
MD5:85C70974FAC8E621ED6E3E9A993FBD6F | SHA256:610983BBCB8EE27963C17EAD15E69AD76EC78FAC64DEB7345CA90D004034CDD6 | |||
| 2264 | cscript.exe | C:\Users\admin\AppData\Local\Temp\_MEI22642\_lzma.pyd | executable | |
MD5:BC2EBD2A95619AB14A16944B0AB8BDE5 | SHA256:AEB3FD8B855B35204B5088C7A1591CC1CA78FFFE707D70E41D99564B6CB617C6 | |||
| 2264 | cscript.exe | C:\Users\admin\AppData\Local\Temp\_MEI22642\_socket.pyd | executable | |
MD5:F6D0876B14BCA5A264EC231895D80072 | SHA256:BCBF9A952473E53F130CE77B0DB69FE08C5845CE10DBE8C320B40F171A15D6A8 | |||
| 2264 | cscript.exe | C:\Users\admin\AppData\Local\Temp\_MEI22642\_hashlib.pyd | executable | |
MD5:C8B153F0BE8569CE2C2DE3D55952D9C7 | SHA256:AF9F39D2A5D762214F6DE2C8FEC0A5BC6BE0B8223EF47164CAA4C6E3D6437A58 | |||
| 2264 | cscript.exe | C:\Users\admin\AppData\Local\Temp\_MEI22642\rar.exe | executable | |
MD5:9C223575AE5B9544BC3D69AC6364F75E | SHA256:90341AC8DCC9EC5F9EFE89945A381EB701FE15C3196F594D9D9F0F67B4FC2213 | |||
| 2264 | cscript.exe | C:\Users\admin\AppData\Local\Temp\_MEI22642\_queue.pyd | executable | |
MD5:FCBB24550F59068A37EA09A490923C8A | SHA256:DE2AC6D99234A28DCF583D90DCA7256DE986FCA9E896C9AAFD1F18BB536978B8 | |||
| 2264 | cscript.exe | C:\Users\admin\AppData\Local\Temp\_MEI22642\blank.aes | binary | |
MD5:686AB9478318E5FCD30C00767BCAA8E9 | SHA256:A3DADD03BF8B4BC1989C04CD58A3CF67B391C4ACC03E742C9C6C8D504B617A7A | |||
| 2264 | cscript.exe | C:\Users\admin\AppData\Local\Temp\_MEI22642\_ssl.pyd | executable | |
MD5:53996068AE9CF68619DA8CB142410D5E | SHA256:CBD320C42277086CD962FD0B25842904CEB436346D380319625F54363F031DCF | |||
| 2264 | cscript.exe | C:\Users\admin\AppData\Local\Temp\_MEI22642\libcrypto-3.dll | executable | |
MD5:27515B5BB912701ABB4DFAD186B1DA1F | SHA256:FE80BD2568F8628032921FE7107BD611257FF64C679C6386EF24BA25271B348A | |||
| 2264 | cscript.exe | C:\Users\admin\AppData\Local\Temp\_MEI22642\libssl-3.dll | executable | |
MD5:6EDA5A055B164E5E798429DCD94F5B88 | SHA256:377DA6175C8A3815D164561350AE1DF22E024BC84C55AE5D2583B51DFD0A19A8 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
324 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |