| File name: | predator-blurayrip-ac3-5-1.torrent.vbe |
| Full analysis: | https://app.any.run/tasks/edbde4c4-882d-4ac4-bd06-8038a4ca5aa6 |
| Verdict: | No threats detected |
| Analysis date: | December 23, 2018, 16:06:22 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/octet-stream |
| File info: | data |
| MD5: | A1B2A2AA8EED485D09673DE47E1858A1 |
| SHA1: | C57B546BF2A12E670122D22A18D0BB60C5AB6F6B |
| SHA256: | B055CC17AD023F907B179678D04B9B8C06D8B43057B0F533D11572634A5BC469 |
| SSDEEP: | 24576:I4MUuMbIB1Os0UDDqFy6LSyHmxhWbeGDD2cJJoUvHM2cdFUWIwE4PEl:QbMU9Ju6EiGDD2FUGFawkl |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1520 | "C:\mklrcvnmwi__\vxcafmfvbx.exe" C:\mklrcvnmwi__\test.au3 | C:\mklrcvnmwi__\vxcafmfvbx.exe | — | WScript.exe | |||||||||||
User: admin Company: AutoIt Team Integrity Level: MEDIUM Description: AutoIt v3 Script Exit code: 0 Version: 3, 3, 14, 2 Modules
| |||||||||||||||
| 2868 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\predator-blurayrip-ac3-5-1.torrent.vbe" | C:\Windows\System32\WScript.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 3520 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe | — | vxcafmfvbx.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Visual Basic Command Line Compiler Exit code: 0 Version: 8.0.50727.5420 Modules
| |||||||||||||||
| (PID) Process: | (2868) WScript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2868) WScript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2868 | WScript.exe | C:\mklrcvnmwi__\shell.txt | binary | |
MD5:— | SHA256:— | |||
| 2868 | WScript.exe | C:\mklrcvnmwi__\pe.bin | text | |
MD5:— | SHA256:— | |||
| 2868 | WScript.exe | C:\mklrcvnmwi__\test.au3 | binary | |
MD5:— | SHA256:— | |||
| 2868 | WScript.exe | C:\mklrcvnmwi__\vxcafmfvbx.exe | executable | |
MD5:B06E67F9767E5023892D9698703AD098 | SHA256:8498900E57A490404E7EC4D8159BEE29AED5852AE88BD484141780EAADB727BB | |||