File name: | document9924.vbe |
Full analysis: | https://app.any.run/tasks/6a032ae7-50cf-4be2-85bd-5dbdd0f95636 |
Verdict: | Malicious activity |
Analysis date: | December 02, 2019, 16:28:22 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | text/plain |
File info: | ASCII text, with CRLF line terminators |
MD5: | 48628462FA7F0669176BCA093D7E5CD3 |
SHA1: | 822585C1F381FB529CB7711D7FEC4E6399FDC839 |
SHA256: | D816AFDCCFEB4BA8301E68E1CAEAD91E53F1D0BE89BE8A660D00B272E5846DF7 |
SSDEEP: | 96:t44kXk+/rgogEY+yD2rZZZQ2Jh5T3k7fAztE/EwKQe:t6X9Q9SmyfRaNKt |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2696 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\document9924.vbe" | C:\Windows\System32\WScript.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
1756 | "C:\Windows\System32\wscript.exe" C:\Users\admin\AppData\Local\Temp\document9924.vbe - | C:\Windows\System32\wscript.exe | — | WScript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
3404 | "C:\Windows\System32\wscript.exe" C:\Users\admin\AppData\Local\Temp\document9924.vbe - - | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
1048 | "C:\Windows\System32\wscript.exe" C:\Users\admin\AppData\Local\Temp\document9924.vbe - - - | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
1188 | "C:\Windows\System32\wscript.exe" C:\Users\admin\AppData\Local\Temp\document9924.vbe - - - - | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
3060 | "C:\Windows\System32\wscript.exe" C:\Users\admin\AppData\Local\Temp\document9924.vbe - - - - - | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
2432 | "C:\Windows\System32\wscript.exe" C:\Users\admin\AppData\Local\Temp\document9924.vbe - - - - - - | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
820 | "C:\Windows\System32\wscript.exe" C:\Users\admin\AppData\Local\Temp\document9924.vbe - - - - - - - | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
3016 | "C:\Windows\System32\wscript.exe" C:\Users\admin\AppData\Local\Temp\document9924.vbe - - - - - - - - | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
516 | "C:\Windows\System32\wscript.exe" C:\Users\admin\AppData\Local\Temp\document9924.vbe - - - - - - - - - | C:\Windows\System32\wscript.exe | — | wscript.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 |