analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

po1.vbs

Full analysis: https://app.any.run/tasks/9f4e6b6a-1106-4895-8977-79c8efb0d645
Verdict: Malicious activity
Threats:

Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.

Analysis date: February 19, 2019, 06:41:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
dunihi
Indicators:
MIME: text/plain
File info: ASCII text, with very long lines
MD5:

E4D0D415849A72A4A6791F3A75C333BC

SHA1:

4CFF20165D1CB336A0193F597AAC10616E31F2B5

SHA256:

CFE4094FA8131E32E23658B77C8E221B887AF56010F328A772A1FBB11F3AC556

SSDEEP:

1536:zqU5+TuTkzgqFL3BMr5F/kLUGmm7auF2y9AdWisg+:jWsYOrPflm7bAsd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • wscript.exe (PID: 2212)
      • WScript.exe (PID: 3052)
    • Writes to a start menu file

      • wscript.exe (PID: 2212)
      • WScript.exe (PID: 3052)
    • Connects to CnC server

      • WScript.exe (PID: 3052)
      • wscript.exe (PID: 2212)
    • DUNIHI was detected

      • WScript.exe (PID: 3052)
      • wscript.exe (PID: 2212)
  • SUSPICIOUS

    • Creates files in the user directory

      • wscript.exe (PID: 2212)
      • WScript.exe (PID: 3052)
    • Application launched itself

      • WScript.exe (PID: 3052)
    • Executes scripts

      • WScript.exe (PID: 3052)
    • Connects to unusual port

      • WScript.exe (PID: 3052)
      • wscript.exe (PID: 2212)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
32
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #DUNIHI wscript.exe #DUNIHI wscript.exe

Process information

PID
CMD
Path
Indicators
Parent process
3052"C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\po1.vbs"C:\Windows\System32\WScript.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Version:
5.8.7600.16385
2212"C:\Windows\System32\wscript.exe" //B "C:\Users\admin\AppData\Roaming\eDdUCtzNWK.vbs"C:\Windows\System32\wscript.exe
WScript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Version:
5.8.7600.16385
Total events
350
Read events
272
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
3052WScript.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\po1.vbstext
MD5:E4D0D415849A72A4A6791F3A75C333BC
SHA256:CFE4094FA8131E32E23658B77C8E221B887AF56010F328A772A1FBB11F3AC556
3052WScript.exeC:\Users\admin\AppData\Roaming\eDdUCtzNWK.vbstext
MD5:6ABED75AFCB8CCD7239870D1460AB7F2
SHA256:A7A2B71492A6883A7AD78EC70E1A00D2C57D5FECD2380D83E61E5D3192C5257C
2212wscript.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\eDdUCtzNWK.vbstext
MD5:6ABED75AFCB8CCD7239870D1460AB7F2
SHA256:A7A2B71492A6883A7AD78EC70E1A00D2C57D5FECD2380D83E61E5D3192C5257C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
24
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3052
WScript.exe
POST
404
185.247.228.122:1991
http://brothersjoy.nl:1991/is-ready
unknown
xml
345 b
malicious
3052
WScript.exe
POST
404
185.247.228.122:1991
http://brothersjoy.nl:1991/is-ready
unknown
xml
345 b
malicious
2212
wscript.exe
POST
404
185.247.228.122:2021
http://brothersjoy.nl:2021/is-ready
unknown
xml
345 b
malicious
3052
WScript.exe
POST
404
185.247.228.122:1991
http://brothersjoy.nl:1991/is-ready
unknown
xml
345 b
malicious
3052
WScript.exe
POST
404
185.247.228.122:1991
http://brothersjoy.nl:1991/is-ready
unknown
xml
345 b
malicious
2212
wscript.exe
POST
404
185.247.228.122:2021
http://brothersjoy.nl:2021/is-ready
unknown
xml
345 b
malicious
3052
WScript.exe
POST
404
185.247.228.122:1991
http://brothersjoy.nl:1991/is-ready
unknown
xml
345 b
malicious
2212
wscript.exe
POST
404
185.247.228.122:2021
http://brothersjoy.nl:2021/is-ready
unknown
xml
345 b
malicious
3052
WScript.exe
POST
404
185.247.228.122:1991
http://brothersjoy.nl:1991/is-ready
unknown
xml
345 b
malicious
2212
wscript.exe
POST
404
185.247.228.122:2021
http://brothersjoy.nl:2021/is-ready
unknown
xml
345 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2212
wscript.exe
185.247.228.122:2021
brothersjoy.nl
malicious
3052
WScript.exe
185.247.228.122:1991
brothersjoy.nl
malicious

DNS requests

Domain
IP
Reputation
brothersjoy.nl
  • 185.247.228.122
unknown

Threats

PID
Process
Class
Message
2212
wscript.exe
A Network Trojan was detected
ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
2212
wscript.exe
A Network Trojan was detected
ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin UA
2212
wscript.exe
A Network Trojan was detected
MALWARE [PTsecurity] Dunihi VBS.Downloader.Trojan
3052
WScript.exe
A Network Trojan was detected
ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3052
WScript.exe
A Network Trojan was detected
ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin UA
3052
WScript.exe
A Network Trojan was detected
MALWARE [PTsecurity] Dunihi VBS.Downloader.Trojan
3052
WScript.exe
A Network Trojan was detected
ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3052
WScript.exe
A Network Trojan was detected
ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin UA
3052
WScript.exe
A Network Trojan was detected
MALWARE [PTsecurity] Dunihi VBS.Downloader.Trojan
2212
wscript.exe
A Network Trojan was detected
ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
No debug info