| File name: | FinancialInvestingDetails.pdf www.skype.vbs |
| Full analysis: | https://app.any.run/tasks/d0b6d1b1-b9a4-4156-b86f-f3aaffeadbbc |
| Verdict: | Malicious activity |
| Analysis date: | January 07, 2024, 09:43:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with CRLF line terminators |
| MD5: | D44BF7D816B38388410BBAAAFDD73CE5 |
| SHA1: | 3E75F8BDFF5817304E11201AAD556C646D371B83 |
| SHA256: | CE0E2C758444AE6E3BE95B83E0F53990E722472E75113D57B18A19CB8E397CA9 |
| SSDEEP: | 6:QSLQ/AHcilT5rPHwOd3qFtEKBNMfLoalNMfLoalNMfLojEmiAFb9nATRHAtIe4H1:Qp/ocA5roOGE02TFAtIe4EJe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1072 | "C:\Windows\System32\cmd.exe" <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>404 Not Found</title> </head><body> <h1>Not Found</h1> <p>The requested URL was not found on this server.</p> <hr> <address>Apache/2.4.29 (Ubuntu) Server at naserviceebaysmman.shop Port 80</address> </body></html> | C:\Windows\System32\cmd.exe | — | wscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2124 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\FinancialInvestingDetails.pdf www.skype.vbs" | C:\Windows\System32\wscript.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| (PID) Process: | (2124) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2124) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2124) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2124) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2124 | wscript.exe | GET | 404 | 5.2.68.76:80 | http://naserviceebaysmman.shop/muanluek | unknown | html | 285 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2124 | wscript.exe | 5.2.68.76:80 | naserviceebaysmman.shop | The Infrastructure Group B.V. | NL | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
naserviceebaysmman.shop |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
2124 | wscript.exe | A Network Trojan was detected | ET MALWARE Suspected Malicious JS Loader Activity (GET) |