Summary | ZeroBOX

runrunlastrun.vbs

Antivirus
Category Machine Started Completed
FILE s1_win7_x6402 May 19, 2023, 10:28 a.m. May 19, 2023, 10:31 a.m.
Size 1.9KB
Type ASCII text, with CRLF line terminators
MD5 9e2d09f47cc48dd3e84205376a8f9ecb
SHA256 9e42c9b206789a24fdf3655af190d1612a1d5a38171cacddbc4fb475d4b56efc
CRC32 0B3C40B2
ssdeep 24:1n1WibHAvio4kBkmZoPHmEdqeA50ikCeQxHecoVRRfVPH/UVUMhFEOxWCQjTPiyT:NiZteol5oszFpQZdzFeMcmCB9dFL7rXS
Yara
  • Antivirus - Contains references to security software

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: SUCCESS: The scheduled task "GoogleUpdateTaskMachineUAB" has successfully been created.
console_handle: 0x0000000000000007
1 1 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 1776
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fefa1b7000
process_handle: 0xffffffffffffffff
1 0 0
file C:\ProgramData\WindowsAppCertification\conf.ps1
file C:\ProgramData\WindowsAppCertification\runps.vbs
cmdline cmd /c schtasks /create /sc hourly /mo 2 /tn "GoogleUpdateTaskMachineUAB" /tr "C:\ProgramData\WindowsAppCertification\wscript.exe //b C:\ProgramData\WindowsAppCertification\runps.vbs"
cmdline schtasks /create /sc hourly /mo 2 /tn "GoogleUpdateTaskMachineUAB" /tr "C:\ProgramData\WindowsAppCertification\wscript.exe //b C:\ProgramData\WindowsAppCertification\runps.vbs"
cmdline "C:\Windows\System32\cmd.exe" /c schtasks /create /sc hourly /mo 2 /tn "GoogleUpdateTaskMachineUAB" /tr "C:\ProgramData\WindowsAppCertification\wscript.exe //b C:\ProgramData\WindowsAppCertification\runps.vbs"
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: cmd
parameters: /c schtasks /create /sc hourly /mo 2 /tn "GoogleUpdateTaskMachineUAB" /tr "C:\ProgramData\WindowsAppCertification\wscript.exe //b C:\ProgramData\WindowsAppCertification\runps.vbs"
filepath: cmd
1 1 0
cmdline cmd /c schtasks /create /sc hourly /mo 2 /tn "GoogleUpdateTaskMachineUAB" /tr "C:\ProgramData\WindowsAppCertification\wscript.exe //b C:\ProgramData\WindowsAppCertification\runps.vbs"
cmdline schtasks /create /sc hourly /mo 2 /tn "GoogleUpdateTaskMachineUAB" /tr "C:\ProgramData\WindowsAppCertification\wscript.exe //b C:\ProgramData\WindowsAppCertification\runps.vbs"
cmdline "C:\Windows\System32\cmd.exe" /c schtasks /create /sc hourly /mo 2 /tn "GoogleUpdateTaskMachineUAB" /tr "C:\ProgramData\WindowsAppCertification\wscript.exe //b C:\ProgramData\WindowsAppCertification\runps.vbs"
cmdline cmd /c schtasks /create /sc hourly /mo 2 /tn "GoogleUpdateTaskMachineUAB" /tr "C:\ProgramData\WindowsAppCertification\wscript.exe //b C:\ProgramData\WindowsAppCertification\runps.vbs"
cmdline schtasks /create /sc hourly /mo 2 /tn "GoogleUpdateTaskMachineUAB" /tr "C:\ProgramData\WindowsAppCertification\wscript.exe //b C:\ProgramData\WindowsAppCertification\runps.vbs"
cmdline "C:\Windows\System32\cmd.exe" /c schtasks /create /sc hourly /mo 2 /tn "GoogleUpdateTaskMachineUAB" /tr "C:\ProgramData\WindowsAppCertification\wscript.exe //b C:\ProgramData\WindowsAppCertification\runps.vbs"
FireEye Dropped:Trojan.Agent.ELAT
ALYac Dropped:Trojan.Agent.ELAT
Arcabit Trojan.Agent.ELAT
Symantec Trojan.Gen.NPE
ESET-NOD32 PowerShell/TrojanDownloader.Agent.FUK
Avast Script:SNH-gen [Drp]
Kaspersky HEUR:Trojan.Script.Generic
BitDefender Dropped:Trojan.Agent.ELAT
MicroWorld-eScan Dropped:Trojan.Agent.ELAT
Ad-Aware Dropped:Trojan.Agent.ELAT
Emsisoft Dropped:Trojan.Agent.ELAT (B)
VIPRE Dropped:Trojan.Agent.ELAT
McAfee-GW-Edition BehavesLike.VBS.Dropper.zp
MAX malware (ai score=89)
Microsoft Trojan:Script/Wacatac.B!ml
GData Dropped:Trojan.Agent.ELAT
Rising Dropper.Agent/VBS!1.E3C2 (CLASSIC)
AVG Script:SNH-gen [Drp]
parent_process wscript.exe martian_process "C:\Windows\System32\cmd.exe" /c schtasks /create /sc hourly /mo 2 /tn "GoogleUpdateTaskMachineUAB" /tr "C:\ProgramData\WindowsAppCertification\wscript.exe //b C:\ProgramData\WindowsAppCertification\runps.vbs"
parent_process wscript.exe martian_process cmd /c schtasks /create /sc hourly /mo 2 /tn "GoogleUpdateTaskMachineUAB" /tr "C:\ProgramData\WindowsAppCertification\wscript.exe //b C:\ProgramData\WindowsAppCertification\runps.vbs"
Time & API Arguments Status Return Repeated

IWbemServices_ExecMethod

inargs.CurrentDirectory: None
inargs.CommandLine: wscript.exe //e:vbscript //b C:\ProgramData\WindowsAppCertification\winappversion.ini
inargs.ProcessStartupInformation: None
outargs.ProcessId: 1776
outargs.ReturnValue: 0
flags: 0
method: Create
class: Win32_Process
1 0 0
file C:\Windows\System32\cmd.exe