File name:

notepad.vbe

Full analysis: https://app.any.run/tasks/a25c6c89-fc28-4ced-8354-d1d787a79c05
Verdict: Malicious activity
Analysis date: March 19, 2025, 17:32:19
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/octet-stream
File info: data
MD5:

9FFE72C88ADA6AA9580AD9AB685D5561

SHA1:

4258642F9DFFBBEA6AA6F1FE7B727F29112686D6

SHA256:

A022A4E730DABCBD9B4D3F3192F9C489AB714679C1CE7FF644FB33D82B2C8598

SSDEEP:

1536:0y08EhDlLIHjwDumceN4YVlbq5hkmc3nrrZiiZQUqdy0xRnWT+X7nrLUpPl6oj5v:0xrhbzr+lc5X1z

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates internet connection object (SCRIPT)

      • wscript.exe (PID: 7452)
      • wscript.exe (PID: 7512)
    • Creates a new folder (SCRIPT)

      • wscript.exe (PID: 7452)
      • wscript.exe (PID: 7512)
    • Modifies registry startup key (SCRIPT)

      • wscript.exe (PID: 7452)
      • wscript.exe (PID: 7512)
    • Creates a new registry key or changes the value of an existing one (SCRIPT)

      • wscript.exe (PID: 7452)
      • wscript.exe (PID: 7512)
    • Copies file to a new location (SCRIPT)

      • wscript.exe (PID: 7452)
      • wscript.exe (PID: 7512)
  • SUSPICIOUS

    • Creates FileSystem object to access computer's file system (SCRIPT)

      • wscript.exe (PID: 7452)
      • wscript.exe (PID: 7512)
    • Gets full path of the running script (SCRIPT)

      • wscript.exe (PID: 7452)
      • wscript.exe (PID: 7512)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 7452)
      • wscript.exe (PID: 7512)
    • Application launched itself

      • wscript.exe (PID: 7452)
    • Executes application which crashes

      • wscript.exe (PID: 7512)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wscript.exe no specs wscript.exe werfault.exe no specs sppextcomobj.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
7452"C:\WINDOWS\System32\WScript.exe" C:\Users\admin\AppData\Local\Temp\notepad.vbeC:\Windows\System32\wscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7512"C:\Windows\System32\wscript.exe" //B "C:\Users\admin\AppData\Roaming\notepad\\notepad.vbe"C:\Windows\System32\wscript.exe
wscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
3221225477
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7680C:\WINDOWS\system32\WerFault.exe -u -p 7512 -s 1100C:\Windows\System32\WerFault.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
7864C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7896"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
3 318
Read events
3 315
Write events
3
Delete events
0

Modification events

(PID) Process:(7452) wscript.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:notepad
Value:
wscript.exe //B "C:\Users\admin\AppData\Roaming\notepad\\notepad.vbe"
(PID) Process:(7512) wscript.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:notepad
Value:
wscript.exe //B "C:\Users\admin\AppData\Roaming\notepad\\notepad.vbe"
Executable files
0
Suspicious files
4
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
7680WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_wscript.exe_158a35e2ae135cb5cc23185ec7683ce9a8c4ad0_2a4c609f_a7a0dec7-18b8-4bf8-be4f-0d220a04529c\Report.wer
MD5:
SHA256:
7680WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERC556.tmp.WERInternalMetadata.xmlxml
MD5:313A494C7F8667747F971D4EA7B605AD
SHA256:6E1ED449D7E4F1D4013884417AA30EF3A71E84DBA00AE46F6B99CA85F2FE1BB1
7512wscript.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\notepad.lnkbinary
MD5:36DE6D7C63F41295647EC16FA514BE64
SHA256:7165EC0FED9A1657D4F36D5F96CADF4BAF05271736A17262A5EE12448DA226AE
7680WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\wscript.exe.7512.dmpbinary
MD5:9BAAC589232C7C65A6FBBA2E0E8F4942
SHA256:4153F959460CF187351BEFD029F24F3A70F6BD481A7555F5ACC4C5E7D2268BDE
7680WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERC586.tmp.xmlxml
MD5:66800B643C10C0E8C8FC06AB61089C53
SHA256:820C3AB9189E900D47246236F851551880329BD502F6469F0947872E00A56FD9
7452wscript.exeC:\Users\admin\AppData\Roaming\notepad\notepad.vbebinary
MD5:9FFE72C88ADA6AA9580AD9AB685D5561
SHA256:A022A4E730DABCBD9B4D3F3192F9C489AB714679C1CE7FF644FB33D82B2C8598
7680WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERC18D.tmp.dmpbinary
MD5:8AD7BB448F51B1D9F634763FA205B745
SHA256:1BF154381709D6B671CF1DC9876243BF0F657F1DAFB3DC283F1A610582458E5E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
18
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7800
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
184.24.77.24:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
184.24.77.24:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4208
RUXIMICS.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
20.190.159.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.206
whitelisted
crl.microsoft.com
  • 184.24.77.24
  • 184.24.77.34
  • 184.24.77.39
  • 184.24.77.26
  • 184.24.77.27
  • 184.24.77.33
  • 184.24.77.25
  • 184.24.77.29
  • 184.24.77.38
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 20.190.159.130
  • 40.126.31.73
  • 40.126.31.69
  • 20.190.159.131
  • 40.126.31.71
  • 20.190.159.73
  • 20.190.159.128
  • 20.190.159.23
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info