File name:

malware.vbs

Full analysis: https://app.any.run/tasks/f0dfa227-fc12-406e-8898-34c742c5da85
Verdict: Malicious activity
Threats:

Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.

Analysis date: May 14, 2020, 22:24:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
latentbot
trojan
Indicators:
MIME: text/plain
File info: ASCII text
MD5:

D413868C9DA164CA655CA0C502A92568

SHA1:

9C7FAF14537DAB125C3A385882D1EA304563275C

SHA256:

A087BD5FB0558BC8F96FFEBBA95CAAC2A171F3EC3553CC7A2A7FFAB4BC1D1193

SSDEEP:

96:lrzMIog4MN++b0nlqyt6WniwTLcrq8deazc9oVqflyCFOIGGOxwdgAK:FY9g4MD0nlqyt6ciTq8Ya0cqImK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • LATENTBOT was detected

      • blkoiunder.exe (PID: 2976)
    • Changes the autorun value in the registry

      • blkoiunder.exe (PID: 2976)
  • SUSPICIOUS

    • Reads Internet Cache Settings

      • WScript.exe (PID: 848)
    • Creates files in the user directory

      • WScript.exe (PID: 848)
    • Checks for external IP

      • blkoiunder.exe (PID: 2976)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
848"C:\Windows\System32\WScript.exe" "C:\Users\admin\Downloads\malware.vbs"C:\Windows\System32\WScript.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2976C:\Users\admin\AppData\Roaming\nvreadm\blkoiunder.exeC:\Users\admin\AppData\Roaming\nvreadm\blkoiunder.exe
WScript.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\nvreadm\blkoiunder.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
768
Read events
755
Write events
13
Delete events
0

Modification events

(PID) Process:(848) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(848) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(848) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(848) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A1000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(848) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(848) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(848) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(848) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Operation:writeName:Implementing
Value:
1C00000001000000E407050004000E00160019000400BE0200000000
(PID) Process:(848) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Operation:writeName:Implementing
Value:
1C00000001000000E407050004000E00160019000400CD0200000000
(PID) Process:(2976) blkoiunder.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
blkoiunder.exe
Executable files
0
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
848WScript.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\blkoiunder[1].iso
MD5:
SHA256:
848WScript.exeC:\Users\admin\AppData\Roaming\nvreadm\blkoiunder.exe
MD5:
SHA256:
848WScript.exeC:\Users\admin\AppData\Roaming\nvreadm\A99449C3092CE70964CE715CF7BB75B.zipcompressed
MD5:C05F2018B125E4F2013453BA3BA0AC2C
SHA256:4D47712861E0C3BC1EAA1428AD62FF340754F680BDF492618E51E6342F715006
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
3
DNS requests
1
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
848
WScript.exe
GET
200
152.67.44.175:80
http://152.67.44.175/blkoiunder.iso
US
text
6.20 Mb
suspicious
2976
blkoiunder.exe
POST
200
152.67.44.175:9010
http://152.67.44.175:9010/$rdgate?ACTION=HELLO
US
binary
7.08 Kb
suspicious
2976
blkoiunder.exe
POST
200
152.67.44.175:9010
http://152.67.44.175:9010/$rdgate?ACTION=START&ID=30277E5BCDD148DBAD2FBE9DB2D374A0
US
binary
7.08 Kb
suspicious
2976
blkoiunder.exe
POST
200
152.67.44.175:9010
http://152.67.44.175:9010/$rdgate?ID=30277E5BCDD148DBAD2FBE9DB2D374A0
US
binary
36 b
suspicious
2976
blkoiunder.exe
GET
429
216.239.38.21:80
http://ipinfo.io/json
US
text
192 b
shared
2976
blkoiunder.exe
POST
200
152.67.44.175:9010
http://152.67.44.175:9010/$rdgate?ID=30277E5BCDD148DBAD2FBE9DB2D374A0
US
binary
13 b
suspicious
2976
blkoiunder.exe
POST
200
152.67.44.175:9010
http://152.67.44.175:9010/$rdgate?ID=30277E5BCDD148DBAD2FBE9DB2D374A0
US
binary
12 b
suspicious
2976
blkoiunder.exe
POST
200
152.67.44.175:9010
http://152.67.44.175:9010/$rdgate?ID=30277E5BCDD148DBAD2FBE9DB2D374A0
US
binary
12 b
suspicious
2976
blkoiunder.exe
POST
200
152.67.44.175:9010
http://152.67.44.175:9010/$rdgate?ID=30277E5BCDD148DBAD2FBE9DB2D374A0
US
binary
20.0 Kb
suspicious
2976
blkoiunder.exe
POST
200
152.67.44.175:9010
http://152.67.44.175:9010/$rdgate?ID=30277E5BCDD148DBAD2FBE9DB2D374A0
US
binary
13 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
848
WScript.exe
152.67.44.175:80
Oracle Corporation
US
suspicious
216.239.38.21:80
ipinfo.io
Google Inc.
US
whitelisted
2976
blkoiunder.exe
152.67.44.175:9010
Oracle Corporation
US
suspicious

DNS requests

Domain
IP
Reputation
ipinfo.io
  • 216.239.38.21
shared

Threats

PID
Process
Class
Message
2976
blkoiunder.exe
Potential Corporate Privacy Violation
ET POLICY Possible External IP Lookup ipinfo.io
2976
blkoiunder.exe
A Network Trojan was detected
REMOTE [PTsecurity] Malicious Remote Desktop Connection (LatentBot)
2976
blkoiunder.exe
A Network Trojan was detected
REMOTE [PTsecurity] Possible Malicious Remote Desktop Connection (LatentBot)
2 ETPRO signatures available at the full report
No debug info