analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Invalid swift_pdf.vbs

Full analysis: https://app.any.run/tasks/433847b2-ff47-4775-9e7b-f1ad5d413213
Verdict: Malicious activity
Analysis date: May 15, 2019, 12:18:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/plain
File info: ASCII text, with very long lines, with CRLF line terminators
MD5:

B315AA2457C2CC1DE2CB40017D981BB7

SHA1:

A04D5F1124F09F10260550E091BC1A71B540CAF2

SHA256:

F876AACF39D44F86748BAC0C0DDCAAEC27DC5CB095CA1037E16E0A0F104702B5

SSDEEP:

1536:ejT4iF7BAAOe65McfV0NAHV0bKG8tC1z3/V0BF7BQF7BQF7BVWF7BQF7B7:ejT4i1BAAOe65hfV0NAHV0bKhCF/V0BL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • wscript.exe (PID: 2256)
      • WScript.exe (PID: 1212)
    • Writes to a start menu file

      • WScript.exe (PID: 1212)
      • wscript.exe (PID: 2256)
  • SUSPICIOUS

    • Executes scripts

      • WScript.exe (PID: 1212)
    • Application launched itself

      • WScript.exe (PID: 1212)
    • Creates files in the user directory

      • WScript.exe (PID: 1212)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
34
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wscript.exe wscript.exe

Process information

PID
CMD
Path
Indicators
Parent process
1212"C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\Invalid swift_pdf.vbs"C:\Windows\System32\WScript.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
2256"C:\Windows\System32\wscript.exe" //B "C:\Users\admin\AppData\Roaming\Invalid swift_pdf.vbs"C:\Windows\System32\wscript.exe
WScript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Version:
5.8.7600.16385
Total events
281
Read events
248
Write events
33
Delete events
0

Modification events

(PID) Process:(1212) WScript.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Invalid swift_pdf
Operation:writeName:
Value:
false - 5/15/2019
(PID) Process:(1212) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Invalid swift_pdf
Value:
wscript.exe //B "C:\Users\admin\AppData\Roaming\Invalid swift_pdf.vbs"
(PID) Process:(1212) WScript.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Invalid swift_pdf
Value:
wscript.exe //B "C:\Users\admin\AppData\Roaming\Invalid swift_pdf.vbs"
(PID) Process:(1212) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1212) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2256) wscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Invalid swift_pdf
Value:
wscript.exe //B "C:\Users\admin\AppData\Roaming\Invalid swift_pdf.vbs"
(PID) Process:(2256) wscript.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Invalid swift_pdf
Value:
wscript.exe //B "C:\Users\admin\AppData\Roaming\Invalid swift_pdf.vbs"
(PID) Process:(2256) wscript.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wscript_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2256) wscript.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wscript_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2256) wscript.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wscript_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
Executable files
0
Suspicious files
0
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
1212WScript.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Invalid swift_pdf.vbstext
MD5:B315AA2457C2CC1DE2CB40017D981BB7
SHA256:F876AACF39D44F86748BAC0C0DDCAAEC27DC5CB095CA1037E16E0A0F104702B5
2256wscript.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Invalid swift_pdf.vbstext
MD5:B315AA2457C2CC1DE2CB40017D981BB7
SHA256:F876AACF39D44F86748BAC0C0DDCAAEC27DC5CB095CA1037E16E0A0F104702B5
1212WScript.exeC:\Users\admin\AppData\Roaming\Invalid swift_pdf.vbstext
MD5:B315AA2457C2CC1DE2CB40017D981BB7
SHA256:F876AACF39D44F86748BAC0C0DDCAAEC27DC5CB095CA1037E16E0A0F104702B5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2256
wscript.exe
194.5.99.53:5732
FR
malicious

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info