SUSPICIOUS — ac37b8347e06593e9c8c06b60782b3560a85dd2a02f694bc43c6b05fa09e67bc.vbs
SUSPICIOUS — ac37b8347e06593e9c8c06b60782b3560a85dd2a02f694bc43c6b05fa09e67bc.vbs is a script sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (65/100). 2 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
ac37b8347e06593e9c8c06b60782b3560a85dd2a02f694bc43c6b05fa09e67bc - SHA-1:
9fe34abdae9bac8711ec2e3793426d1f3f8d600c - MD5:
7936699d4629dd47e74d3e6a60476a3b - ssdeep:
12288:3J9K/CuxnJ3R76vSWgn4iyifij2RI5rCB02:3PKlP7cStXfij2MX2 - TLSH:
T1904B01130CC6E5D9D6DD64D15EA08D36E8C0A80EAF1809985B978890AFFDCB527DBCC4 - Submitted as: ac37b8347e06593e9c8c06b60782b3560a85dd2a02f694bc43c6b05fa09e67bc.vbs
- File type: script · Size: 481094 bytes
- Verdict: suspicious (65/100)
Detections (2 of 53 engines)
- capa (capabilities): capability:execution/powershell
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 65/100 is the fusion of 3 weighted signals:
- Obfuscated powershell script: dynamic-exec, encoded-command, persistence, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Registry keys
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Rundc34c238
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Svc37264031
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report