| File name: | ORDER-234468.doc.vbs |
| Full analysis: | https://app.any.run/tasks/807fcea2-1145-49f0-997e-0607097a56a5 |
| Verdict: | Malicious activity |
| Analysis date: | May 16, 2023, 11:12:34 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| MIME: | text/plain |
| File info: | ASCII text, with very long lines, with CRLF line terminators |
| MD5: | 57EBBE2E997DBFEA17030286F8993CB4 |
| SHA1: | C5B7745FD561933D84C68B18FFF5A131726034CD |
| SHA256: | A64102AD5032310CB854CD6F68255CBFA61173EF90F88C399BA10A0B15523E18 |
| SSDEEP: | 384:TxmlmlWimcfU4pbuyerHazSVrxXNX8ZW7/z7X9rlPl0X5mu1uEK9y4VKthVf7JDe:a |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2572 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\ORDER-234468.doc.vbs" | C:\Windows\System32\wscript.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
328 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2572 | wscript.exe | 103.50.163.157:443 | grapemundo.com | PUBLIC-DOMAIN-REGISTRY | IN | suspicious |
Domain | IP | Reputation |
|---|---|---|
grapemundo.com |
| suspicious |
PID | Process | Class | Message |
|---|---|---|---|
2572 | wscript.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |