File name:

C:\Users\admin\Desktop\12539__250719.vbs

Full analysis: https://app.any.run/tasks/9995f0b8-b077-4fb1-968f-f49133b48809
Verdict: Malicious activity
Analysis date: July 25, 2019, 17:02:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
Indicators:
MIME: text/plain
File info: ASCII text, with very long lines, with CRLF line terminators
MD5:

FFE443144A8D7CD8EAB983A6A297C946

SHA1:

E383BBDEE69E8A5EB1C1E74E40E4BC5C1A1AACBE

SHA256:

C3C2E94EE15DAC5F64FF63B0ECF1A382072ABFE3E30E73F87509CF7D3B76F49A

SSDEEP:

1536:uJGCakTgICYbtUqpUgSW8EoMLY5la05V5:uRaAzzYZMsbV5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes application which crashes

      • WScript.exe (PID: 3904)
      • WScript.exe (PID: 1708)
      • WScript.exe (PID: 580)
      • WScript.exe (PID: 3188)
      • WScript.exe (PID: 3376)
      • WScript.exe (PID: 2456)
      • WScript.exe (PID: 3304)
      • WScript.exe (PID: 4008)
      • WScript.exe (PID: 988)
      • WScript.exe (PID: 3724)
      • WScript.exe (PID: 1944)
      • WScript.exe (PID: 1764)
      • WScript.exe (PID: 1568)
      • WScript.exe (PID: 3032)
      • WScript.exe (PID: 540)
      • WScript.exe (PID: 2112)
      • WScript.exe (PID: 2940)
      • WScript.exe (PID: 1960)
      • WScript.exe (PID: 2828)
      • WScript.exe (PID: 3388)
      • WScript.exe (PID: 552)
      • WScript.exe (PID: 3960)
      • WScript.exe (PID: 3056)
      • WScript.exe (PID: 1708)
      • WScript.exe (PID: 2264)
      • WScript.exe (PID: 2260)
      • WScript.exe (PID: 3212)
      • WScript.exe (PID: 3212)
      • WScript.exe (PID: 796)
  • INFO

    • Application was crashed

      • ntvdm.exe (PID: 3552)
      • ntvdm.exe (PID: 4004)
      • ntvdm.exe (PID: 2968)
      • ntvdm.exe (PID: 2928)
      • ntvdm.exe (PID: 2712)
      • ntvdm.exe (PID: 2088)
      • ntvdm.exe (PID: 3300)
      • ntvdm.exe (PID: 2284)
      • ntvdm.exe (PID: 2164)
      • ntvdm.exe (PID: 3104)
      • ntvdm.exe (PID: 1480)
      • ntvdm.exe (PID: 1356)
      • ntvdm.exe (PID: 1468)
      • ntvdm.exe (PID: 2468)
      • ntvdm.exe (PID: 2324)
      • ntvdm.exe (PID: 2068)
      • ntvdm.exe (PID: 3404)
      • ntvdm.exe (PID: 1492)
      • ntvdm.exe (PID: 3108)
      • ntvdm.exe (PID: 3164)
      • ntvdm.exe (PID: 3436)
      • ntvdm.exe (PID: 3536)
      • ntvdm.exe (PID: 1892)
      • ntvdm.exe (PID: 1860)
      • ntvdm.exe (PID: 4064)
      • ntvdm.exe (PID: 1672)
      • ntvdm.exe (PID: 552)
      • ntvdm.exe (PID: 2828)
      • ntvdm.exe (PID: 3468)
    • Manual execution by user

      • WScript.exe (PID: 580)
      • WScript.exe (PID: 3188)
      • WScript.exe (PID: 2456)
      • WScript.exe (PID: 3376)
      • WScript.exe (PID: 1708)
      • WScript.exe (PID: 3304)
      • WScript.exe (PID: 4008)
      • WScript.exe (PID: 1944)
      • WScript.exe (PID: 988)
      • WScript.exe (PID: 3724)
      • WScript.exe (PID: 1764)
      • WScript.exe (PID: 1568)
      • WScript.exe (PID: 3032)
      • WScript.exe (PID: 2112)
      • WScript.exe (PID: 540)
      • WScript.exe (PID: 1960)
      • WScript.exe (PID: 2940)
      • WScript.exe (PID: 2828)
      • WScript.exe (PID: 3388)
      • WScript.exe (PID: 3960)
      • WScript.exe (PID: 552)
      • WScript.exe (PID: 3056)
      • WScript.exe (PID: 3212)
      • WScript.exe (PID: 2260)
      • WScript.exe (PID: 2264)
      • WScript.exe (PID: 3212)
      • WScript.exe (PID: 1708)
      • WScript.exe (PID: 796)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
152
Monitored processes
58
Malicious processes
0
Suspicious processes
29

Behavior graph

Click at the process to see the details
start wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe wscript.exe ntvdm.exe

Process information

PID
CMD
Path
Indicators
Parent process
540"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\12539__250719.vbs" C:\Windows\System32\WScript.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
552"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\12539__250719.vbs" C:\Windows\System32\WScript.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
552"C:\Windows\system32\ntvdm.exe" -i1c C:\Windows\system32\ntvdm.exe
WScript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
NTVDM.EXE
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\apphelp.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\winhttp.dll
c:\program files\common files\system\ado\msado15.dll
580"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\12539__250719.vbs" C:\Windows\System32\WScript.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
796"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\12539__250719.vbs" C:\Windows\System32\WScript.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
988"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\12539__250719.vbs" C:\Windows\System32\WScript.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1356"C:\Windows\system32\ntvdm.exe" -ie C:\Windows\system32\ntvdm.exe
WScript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
NTVDM.EXE
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntvdm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1468"C:\Windows\system32\ntvdm.exe" -if C:\Windows\system32\ntvdm.exe
WScript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
NTVDM.EXE
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntvdm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1480"C:\Windows\system32\ntvdm.exe" -id C:\Windows\system32\ntvdm.exe
WScript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
NTVDM.EXE
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntvdm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1492"C:\Windows\system32\ntvdm.exe" -i14 C:\Windows\system32\ntvdm.exe
WScript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
NTVDM.EXE
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntvdm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
1 479
Read events
1 479
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
29
Unknown types
0

Dropped files

PID
Process
Filename
Type
1708WScript.exeC:
MD5:
SHA256:
2456WScript.exeC:
MD5:
SHA256:
4008WScript.exeC:
MD5:
SHA256:
3724WScript.exeC:
MD5:
SHA256:
1764WScript.exeC:
MD5:
SHA256:
1568WScript.exeC:
MD5:
SHA256:
540WScript.exeC:
MD5:
SHA256:
1960WScript.exeC:
MD5:
SHA256:
1944WScript.exeC:\Users\admin\AppData\Local\Temp\NkjLa.exexml
MD5:AB99593EFDF397078F11D9C37DD218A1
SHA256:BEAB79184BF1FCA1F52FF3761F8A533827106FEF3749C6C9C9A3E7EEC619A226
4008WScript.exeC:\Users\admin\AppData\Local\Temp\NkjLa.exexml
MD5:AB99593EFDF397078F11D9C37DD218A1
SHA256:BEAB79184BF1FCA1F52FF3761F8A533827106FEF3749C6C9C9A3E7EEC619A226
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
29
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
580
WScript.exe
GET
404
64.37.52.109:80
http://rajtyagi.com/images/pctools.exe
US
xml
345 b
suspicious
1708
WScript.exe
GET
404
64.37.52.109:80
http://polarisp.com/marina/mytest.exe
US
xml
345 b
suspicious
3304
WScript.exe
GET
404
64.37.52.109:80
http://polarisp.com/marina/mytest.exe
US
xml
345 b
suspicious
3904
WScript.exe
GET
404
64.37.52.109:80
http://qts.com.hk/images/gifanimator.exe
US
xml
345 b
suspicious
988
WScript.exe
GET
404
64.37.52.109:80
http://placertree.org/images/ledview.exe
US
xml
345 b
suspicious
3188
WScript.exe
GET
404
64.37.52.109:80
http://pylypenko.net/email/postmansetup.exe
US
xml
345 b
suspicious
2112
WScript.exe
GET
404
64.37.52.109:80
http://qts.com.hk/images/gifanimator.exe
US
xml
345 b
suspicious
1944
WScript.exe
GET
404
64.37.52.109:80
http://qts.com.hk/images/gifanimator.exe
US
xml
345 b
suspicious
2940
WScript.exe
GET
404
64.37.52.109:80
http://polarisp.com/marina/mytest.exe
US
xml
345 b
suspicious
1764
WScript.exe
GET
404
64.37.52.109:80
http://polarisp.com/marina/mytest.exe
US
xml
345 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
64.37.52.109:80
qts.com.hk
HostDime.com, Inc.
US
suspicious
3376
WScript.exe
64.37.52.109:80
qts.com.hk
HostDime.com, Inc.
US
suspicious
3188
WScript.exe
64.37.52.109:80
qts.com.hk
HostDime.com, Inc.
US
suspicious
3904
WScript.exe
64.37.52.109:80
qts.com.hk
HostDime.com, Inc.
US
suspicious
2456
WScript.exe
64.37.52.109:80
qts.com.hk
HostDime.com, Inc.
US
suspicious
3304
WScript.exe
64.37.52.109:80
qts.com.hk
HostDime.com, Inc.
US
suspicious
4008
WScript.exe
64.37.52.109:80
qts.com.hk
HostDime.com, Inc.
US
suspicious
1944
WScript.exe
64.37.52.109:80
qts.com.hk
HostDime.com, Inc.
US
suspicious
3724
WScript.exe
64.37.52.109:80
qts.com.hk
HostDime.com, Inc.
US
suspicious
1764
WScript.exe
64.37.52.109:80
qts.com.hk
HostDime.com, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
qts.com.hk
  • 64.37.52.109
suspicious
polarisp.com
  • 64.37.52.109
suspicious
rajtyagi.com
  • 64.37.52.109
suspicious
pylypenko.net
  • 64.37.52.109
suspicious
placertree.org
  • 64.37.52.109
suspicious

Threats

No threats detected
No debug info