| File name: | banezhteb.com Secure Email Setup(IMAP).vbs |
| Full analysis: | https://app.any.run/tasks/7d18edc8-3b57-467e-a030-f8923ffb2faf |
| Verdict: | Malicious activity |
| Analysis date: | November 03, 2023, 09:17:32 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| MIME: | text/plain |
| File info: | ASCII text, with CRLF line terminators |
| MD5: | EE376BC029C176929AA18E965677E956 |
| SHA1: | F36B7B0A4EFAE98832CEF4ED8E8EE2549448095A |
| SHA256: | BE7D29F555C5228D1DB89C96986A03A2296E42A379962702693C90498DE77988 |
| SSDEEP: | 96:NFhahrkpNctlTlM8knaje4xDNpF8aM8EzhelvsNSOeu975EpdKNA38dao/6C:LkjTik64xDNQxgvsNSOe87Gp4NA3OFiC |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2584 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\banezhteb.com Secure Email Setup(IMAP).vbs" | C:\Windows\System32\wscript.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
324 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |