analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

dokument.vbe

Full analysis: https://app.any.run/tasks/5c8b81ef-15dc-48f5-88d5-304af6ca86f8
Verdict: Malicious activity
Analysis date: August 13, 2019, 17:58:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/plain
File info: ASCII text, with CRLF line terminators
MD5:

8A0FE9AAA66923AFF57410115891A632

SHA1:

16FBCA1A780D9FD0CFF1EAB5D7FA66A8C5C9396A

SHA256:

A6F8F1D019DDFC984128CD5B8C4F5A540B878251613B693C9733885459926A00

SSDEEP:

384:2UNQHVeOdCfffffffffffffffffffffffaaaabbbbsbaauuuuuuuuuuueuuuuuux:2UN34J

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Application launched itself

      • wscript.exe (PID: 2668)
      • wscript.exe (PID: 3276)
      • wscript.exe (PID: 2464)
      • wscript.exe (PID: 1912)
      • wscript.exe (PID: 3816)
      • WScript.exe (PID: 3348)
      • wscript.exe (PID: 1544)
      • wscript.exe (PID: 3268)
      • wscript.exe (PID: 2156)
      • wscript.exe (PID: 3260)
      • wscript.exe (PID: 2740)
      • wscript.exe (PID: 2324)
    • Executes scripts

      • wscript.exe (PID: 2072)
      • wscript.exe (PID: 3044)
      • wscript.exe (PID: 796)
      • wscript.exe (PID: 1596)
      • wscript.exe (PID: 3816)
      • WScript.exe (PID: 3348)
      • wscript.exe (PID: 2668)
      • wscript.exe (PID: 2464)
      • wscript.exe (PID: 2232)
      • wscript.exe (PID: 3276)
      • wscript.exe (PID: 3400)
      • wscript.exe (PID: 1912)
      • wscript.exe (PID: 3268)
      • wscript.exe (PID: 2364)
      • wscript.exe (PID: 3260)
      • wscript.exe (PID: 3080)
      • wscript.exe (PID: 2324)
      • wscript.exe (PID: 1544)
      • wscript.exe (PID: 2156)
      • wscript.exe (PID: 2740)
      • wscript.exe (PID: 1208)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
22
Malicious processes
14
Suspicious processes
5

Behavior graph

Click at the process to see the details
start wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3348"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\dokument.vbe"C:\Windows\System32\WScript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
796"C:\Windows\System32\wscript.exe" C:\Users\admin\Desktop\dokument.vbe |C:\Windows\System32\wscript.exeWScript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
3044"C:\Windows\System32\wscript.exe" C:\Users\admin\Desktop\dokument.vbe | |C:\Windows\System32\wscript.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
1912"C:\Windows\System32\wscript.exe" C:\Users\admin\Desktop\dokument.vbe | | |C:\Windows\System32\wscript.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
2668"C:\Windows\System32\wscript.exe" C:\Users\admin\Desktop\dokument.vbe | | | |C:\Windows\System32\wscript.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
2232"C:\Windows\System32\wscript.exe" C:\Users\admin\Desktop\dokument.vbe | | | | |C:\Windows\System32\wscript.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
2464"C:\Windows\System32\wscript.exe" C:\Users\admin\Desktop\dokument.vbe | | | | | |C:\Windows\System32\wscript.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
2072"C:\Windows\System32\wscript.exe" C:\Users\admin\Desktop\dokument.vbe | | | | | | |C:\Windows\System32\wscript.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
3816"C:\Windows\System32\wscript.exe" C:\Users\admin\Desktop\dokument.vbe | | | | | | | |C:\Windows\System32\wscript.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
3400"C:\Windows\System32\wscript.exe" C:\Users\admin\Desktop\dokument.vbe | | | | | | | | |C:\Windows\System32\wscript.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Total events
1 627
Read events
1 543
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info