MALICIOUS — loveletter.VBS
MALICIOUS — loveletter.VBS is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Coolnote family. 5 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bb9f9fcea94271478da1e6fda01d089979a152eee642fa711e2a81990518d3b7 - SHA-1:
9551126c62a692c090d35757292664fd09db4680 - MD5:
5a0411399830eeb50fd69f31d0f8c574 - ssdeep:
48:e/hM3eVu+a7fpfN+oxsk/Z4Vw9J3tVXVVVVgOwW0wBZANdBdxvvrzXBBGRXB/cXx:eCuVYNLxsWZKYJ3tVXVVVVJ9BZ+B/vrJ - TLSH:
T19A1661F23A94252FE3B52837824BE95B961C84FF0DA524BD3681120358B5437FC0D99E - Submitted as: loveletter.VBS
- File type: script · Size: 2957 bytes
- Verdict: malicious (99/100) · Family: Coolnote
Detections (5 of 51 engines)
- ClamAV (daily): {HEX}bin.trojan.generic.coolnote.44.UNOFFICIAL
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- Microsoft Defender: Virus:VBS/CoolNote.B
- Emsisoft (Emergency Kit): Generic.ScriptWorm.294CEFDE
- Kaspersky (KVRT): Email-Worm.VBS.LoveLetter
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged {HEX}bin.trojan.generic.coolnote.44.UNOFFICIAL (rule
{HEX}bin.trojan.generic.coolnote.44.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Virus:VBS/CoolNote.B (rule
Virus:VBS/CoolNote.B) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Generic.ScriptWorm.294CEFDE (rule
Generic.ScriptWorm.294CEFDE) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Email-Worm.VBS.LoveLetter (rule
Email-Worm.VBS.LoveLetter) - engine signal, weight 0.55, confidence 0.85 - Obfuscated vbscript script: persistence (rule
script-deobfuscation) - static signal, weight 0.35, confidence 0.75 - YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Contacted 3 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
844 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- _dosvc._tcp.local
- desktop-hsgcbep._dosvc._tcp.local
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- desktop-hsgcbep(1)._dosvc._tcp.local
- ntp.ubuntu.com
- 250.255.255.239.in-addr.arpa
- ff02::1:3
- 224.0.0.252
- ff02::fb
- 224.0.0.251
- 10.240.0.1
- 91.189.91.157
- 239.255.255.250
- 224.0.0.22
- ff02::16
- ff02::1:2
- ff02::2
Dropped files
- tmp_tmp.VV4J0tjt3m -
5e09be6e7c76e79e6956e21863dbdfcbb19f1812cc40ff7520a0af8b5848fcf7
Embedded IP addresses
- 203.26.79.13
- 20.190.167.66
Registry keys
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Prinz_Charles_Are_Die
- HKEY_CURRENT_USER\Software\Microsoft\WAB\
File paths
- C:\Program
More Coolnote samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report