04ad737a...0a07 | VMRay Analyzer Report
Try VMRay Analyzer
VTI SCORE: 92/100
Dynamic Analysis Report
Classification: Dropper

VMRay Threat Indicators (9 rules, 10 matches)

Severity Category Operation Count Classification
4/5
Process Creates an unusually large number of processes 1 -
  • Above average number of processes were monitored.
4/5
Process Executes encoded PowerShell script 1 -
  • Executes encoded PowerShell script to possibly hide malicious payload.
3/5
Network Reads network adapter information 1 -
2/5
Network Performs DNS request 1 -
2/5
Network Connects to HTTP server 1 -
2/5
PE Drops PE file 1 Dropper
1/5
Process Creates system object 2 -
  • Creates mutex with name "Global\.net clr networking".
1/5
Process Enumerates running processes 1 -
1/5
Network Connects to remote host 1 -
  • Outgoing TCP connection to host "212.73.150.207:443".

Screenshots

Monitored Processes

Sample Information

ID #632978
MD5 c0b9640880d94923f8aeb1b7944a4f69 Copy to Clipboard
SHA1 2dddc57a59b07449a052167218bc3a198c8cd82c Copy to Clipboard
SHA256 04ad737a63367cfb492597ba86fd3509eb7340f2b762d830c05dfd9fe9870a07 Copy to Clipboard
SSDeep 96:MvS4P8h6j2Fm1hxe777TTppp7TTCpYhhhhhhhtJ4vB7PkoJeJXJMNMf8AiMHB5Qe:MOo7IH9 Copy to Clipboard
Filename dokumentacja_92622.vbe
File Size 7.13 KB
Sample Type VBScript

Analysis Information

Creation Time 2019-04-30 12:37 (UTC+2)
Analysis Duration 00:16:29
Number of Monitored Processes 277
Execution Successful True
Reputation Enabled True
WHOIS Enabled True
Local AV Enabled True
YARA Enabled True
Number of AV Matches 0
Number of YARA Matches 0
Termination Reason Timeout
Tags
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image