File name:

cscript.exe

Full analysis: https://app.any.run/tasks/afd5367d-31dc-4a5d-8830-7955fd19d42e
Verdict: Malicious activity
Analysis date: November 30, 2023, 23:31:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

16A5CCEADAC88938E627D7EC9A0DCF7F

SHA1:

7821CD004BCA8A52F27FDC9D5BA90E0FD085942B

SHA256:

9DA23BFC87A60275ADF3D0EBDA2CE71FE65D7D03EFA21060E39652F0DF87129A

SSDEEP:

98304:8rkPiI1suDbjR6Y9nCaNOMJYECTJklpS5bPjlYiLonqMnksUKfrC7lORacGp4BLl:hgohNWYDmS66

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • cscript.exe (PID: 2264)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • cscript.exe (PID: 2264)
    • The process drops C-runtime libraries

      • cscript.exe (PID: 2264)
    • Application launched itself

      • cscript.exe (PID: 2264)
    • Loads Python modules

      • cscript.exe (PID: 1168)
  • INFO

    • Create files in a temporary directory

      • cscript.exe (PID: 2264)
    • Reads the computer name

      • cscript.exe (PID: 2264)
    • Checks supported languages

      • cscript.exe (PID: 2264)
      • cscript.exe (PID: 1168)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2023:11:30 14:26:29+01:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.37
CodeSize: 171008
InitializedDataSize: 115200
UninitializedDataSize: -
EntryPoint: 0xc1a0
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 5.812.10240.16384
ProductVersionNumber: 5.812.10240.16384
FileFlagsMask: 0x0003
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Microsoft ® Console Based Script Host
FileVersion: 5.812.10240.16384
InternalName: cscript.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: cscript.exe
ProductName: Microsoft ® Windows Script Host
ProductVersion: 5.812.10240.16384
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
34
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start cscript.exe no specs cscript.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1168"C:\Users\admin\AppData\Local\Temp\cscript.exe" C:\Users\admin\AppData\Local\Temp\cscript.execscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\users\admin\appdata\local\temp\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll
2264"C:\Users\admin\AppData\Local\Temp\cscript.exe" C:\Users\admin\AppData\Local\Temp\cscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\users\admin\appdata\local\temp\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll
Total events
13
Read events
13
Write events
0
Delete events
0

Modification events

No data
Executable files
18
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2264cscript.exeC:\Users\admin\AppData\Local\Temp\_MEI22642\_bz2.pydexecutable
MD5:85C70974FAC8E621ED6E3E9A993FBD6F
SHA256:610983BBCB8EE27963C17EAD15E69AD76EC78FAC64DEB7345CA90D004034CDD6
2264cscript.exeC:\Users\admin\AppData\Local\Temp\_MEI22642\_lzma.pydexecutable
MD5:BC2EBD2A95619AB14A16944B0AB8BDE5
SHA256:AEB3FD8B855B35204B5088C7A1591CC1CA78FFFE707D70E41D99564B6CB617C6
2264cscript.exeC:\Users\admin\AppData\Local\Temp\_MEI22642\_socket.pydexecutable
MD5:F6D0876B14BCA5A264EC231895D80072
SHA256:BCBF9A952473E53F130CE77B0DB69FE08C5845CE10DBE8C320B40F171A15D6A8
2264cscript.exeC:\Users\admin\AppData\Local\Temp\_MEI22642\_hashlib.pydexecutable
MD5:C8B153F0BE8569CE2C2DE3D55952D9C7
SHA256:AF9F39D2A5D762214F6DE2C8FEC0A5BC6BE0B8223EF47164CAA4C6E3D6437A58
2264cscript.exeC:\Users\admin\AppData\Local\Temp\_MEI22642\rar.exeexecutable
MD5:9C223575AE5B9544BC3D69AC6364F75E
SHA256:90341AC8DCC9EC5F9EFE89945A381EB701FE15C3196F594D9D9F0F67B4FC2213
2264cscript.exeC:\Users\admin\AppData\Local\Temp\_MEI22642\_queue.pydexecutable
MD5:FCBB24550F59068A37EA09A490923C8A
SHA256:DE2AC6D99234A28DCF583D90DCA7256DE986FCA9E896C9AAFD1F18BB536978B8
2264cscript.exeC:\Users\admin\AppData\Local\Temp\_MEI22642\blank.aesbinary
MD5:686AB9478318E5FCD30C00767BCAA8E9
SHA256:A3DADD03BF8B4BC1989C04CD58A3CF67B391C4ACC03E742C9C6C8D504B617A7A
2264cscript.exeC:\Users\admin\AppData\Local\Temp\_MEI22642\_ssl.pydexecutable
MD5:53996068AE9CF68619DA8CB142410D5E
SHA256:CBD320C42277086CD962FD0B25842904CEB436346D380319625F54363F031DCF
2264cscript.exeC:\Users\admin\AppData\Local\Temp\_MEI22642\libcrypto-3.dllexecutable
MD5:27515B5BB912701ABB4DFAD186B1DA1F
SHA256:FE80BD2568F8628032921FE7107BD611257FF64C679C6386EF24BA25271B348A
2264cscript.exeC:\Users\admin\AppData\Local\Temp\_MEI22642\libssl-3.dllexecutable
MD5:6EDA5A055B164E5E798429DCD94F5B88
SHA256:377DA6175C8A3815D164561350AE1DF22E024BC84C55AE5D2583B51DFD0A19A8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info