Click to jump to signature section
Source: mYX4N3FRJj.vbs | Virustotal: Detection: 21% | Perma Link |
Source: mYX4N3FRJj.vbs | ReversingLabs: Detection: 25% |
Source: Submited Sample | Neural Call Log Analysis: 95.1% |
Source: C:\Windows\System32\wscript.exe | File opened: C:\Users\user\AppData\Local\Microsoft\ | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | File opened: C:\Users\user\AppData\Local\ | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | File opened: C:\Users\user\AppData\Local\Microsoft\Windows\ | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | File opened: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\ | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | File opened: C:\Users\user\AppData\ | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | File opened: C:\Users\user\ | Jump to behavior |
Source: | Initial file: inStream.SaveToFile(fn) |
Source: C:\Windows\System32\wscript.exe | COM Object queried: Windows Script Host Shell Object HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | COM Object queried: WBEM Locator HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | COM Object queried: Windows Management and Instrumentation HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} | Jump to behavior |
Source: mYX4N3FRJj.vbs | Initial sample: Strings found which are bigger than 50 |
Source: classification engine | Classification label: mal64.winVBS@1/0@0/0 |
Source: unknown | Process created: C:\Windows\System32\wscript.exe C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\mYX4N3FRJj.vbs" |
Source: C:\Windows\System32\wscript.exe | Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers | Jump to behavior |
Source: mYX4N3FRJj.vbs | Virustotal: Detection: 21% |
Source: mYX4N3FRJj.vbs | ReversingLabs: Detection: 25% |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: vbscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\InprocServer32 | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Window found: window name: WSH-Timer | Jump to behavior |
Source: all processes | Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected |
Source: C:\Windows\System32\wscript.exe | File opened: C:\Users\user\AppData\Local\Microsoft\ | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | File opened: C:\Users\user\AppData\Local\ | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | File opened: C:\Users\user\AppData\Local\Microsoft\Windows\ | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | File opened: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\ | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | File opened: C:\Users\user\AppData\ | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | File opened: C:\Users\user\ | Jump to behavior |
Source: all processes | Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected |
Source: C:\Windows\System32\wscript.exe | Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid | Jump to behavior |