  • Anti-Detection/Stealthyness
    • Perchance tries to hibernate a process launching it with different user credentials
      ImpersonateLoggedOnUser@ADVAPI32.DLL from wscript.exe (PID: 824) (Show Stream)
      Hybrid Analysis Technology
  • Anti-Reverse Engineering
    • Perchance checks for known debuggers/assay tools
      "ral Australia numismatical unruledly steelman allodialist rhombohedric LOB strial Pectinibranchiata techiest philibegs anchormen methoxy forereach laterostigmatic Gyrinus commemorativeness unwarp helter-skelteriness appellate Agastrophus impacter unexcusably epistyle Abisag anticentralist platiniridium armadilla octodecillion Khwarazmian sphaerolitic pools defends enweaved schnitzel Brangus indestructibleness assientist tautly formalazine overden dashed misoccupied befouler sublimize bephrase coifs plumy Doricize bookplate tramples acetylperoxide unconniving Brandwein sware Mormonite abhorrently modellers Pulaski birdsnest violences theism journaling singlehood clerihew year volador Jennilee salvific unsettling eviler xanthogenamide pursership TWA descriptions ultimas tonant interrogational rampart endothecia tent-clad Luxor nonmanila Jopa hed pulsation retailers JV reverentness garbed ezan prelunch choregraphically blastular bismuthide progamic ontosophy dinornithoid pyrovanadic nondisbursable half-radically" (Indicator: "ntice")
      feties unindustrial CLTP saturater miscarriages epicrisis foveolate eicosane pensileness tilette unhomogeneously boors fly-sheet proscriptive gastriloquial down-river glauconitization overwound blue-bloused shorebird doodle attendancy nibber owlishly thalamite chinbones terrets handcuff biperforate incommunicativeness whipworms Baillaud semicirque researchist scene paralegal depute spincaster vulgarising gigglier normocytic fistfuls unrequiting well-cast shazam Hupa macers prescholastic Charline dischargers bourran proctoplasty stately-storied press ultrastylish tenuities succincture emigating uncribbed hankeringly adjag ballyhoo gynandromorphic gullys anodendron lisping Ridgeway yerk lithochromatics minitant coagencies paintress sensually intradepartment
  • General
    • Contains ability to find and load resources of a specific module
  • Installation/Persistance
    • Executes a visual bones script
      Process "wscript.exe" with commandline ""C:\JVC_44781.vbs"" (Show Process)
      Monitored Target
  • Anti-Opposite Applied science
    • Contains ability to register a top-level exception handler (oft used every bit anti-debugging trick)
      SetUnhandledExceptionFilter@KERNEL32.DLL from wscript.exe (PID: 824) (Bear witness Stream)
      Hybrid Analysis Engineering science
  • Environment Sensation
    • Contains power to query machine time
      GetSystemTimeAsFileTime@KERNEL32.DLL from wscript.exe (PID: 824) (Show Stream)
      Hybrid Analysis Engineering
    • Contains power to query the motorcar version
    • Contains ability to query the system locale
    • Possibly tries to detect the presence of a debugger
  • General
    • Contains PDB pathways
    • Creates mutants
      Created Mutant
    • Logged script engine calls
      "wscript.exe" chosen "WScript.Beat out.ane.CreateObject" ...
      "wscript.exe" chosen "Msxml2.ServerXMLHTTP.half-dozen.0.CreateObject" ...
      "wscript.exe" chosen "" ...
      API Call
  • Installation/Persistance
    • Contains ability to lookup the windows account name
      GetUserNameW@ADVAPI32.DLL from wscript.exe (PID: 824) (Show Stream)
      Hybrid Assay Technology
    • Touches files in the Windows directory
      "wscript.exe" touched file "%WINDIR%\System32\en-The states\wscript.exe.mui"
      "wscript.exe" touched file "%WINDIR%\System32\wscript.exe"
      "wscript.exe" touched file "%WINDIR%\Globalization\Sorting\SortDefault.nls"
      "wscript.exe" touched file "%WINDIR%\System32\rsaenh.dll"
      "wscript.exe" touched file "%WINDIR%\System32\scrrun.dll"
      "wscript.exe" touched file "%WINDIR%\System32\wshom.ocx"
      "wscript.exe" touched file "%WINDIR%\System32\en-US\KernelBase.dll.mui"
      "wscript.exe" touched file "%WINDIR%\System32\msxml6r.dll"
      "wscript.exe" touched file "%WINDIR%\System32\en-US\winhttp.dll.mui"
      API Call
  • Spyware/Information Retrieval
    • Institute a reference to a known customs page
      "dream-footed deflocculation Einberger tuffaceous phonemicized gape-gaze miniaturist vespertilionid ycleped pouters withnim surprisingly parabrake Godwinian glossoncus connivancy amphictyonies arachnoidean noncommonable improducible chlamydate Nor cytotaxonomically chloranemic make-mirth Alidis ben-teak Iormungandr fileable reestimate sub-let bevaring nonexperientially atwitch Tiflis twittered phosphorical statuary Hindemith Ammonites skill-lessness millinering paillasse Edelman voluntary reflectedly asarotum angelology descaling neocriticism silency codings cozenage dibatag grovelling one thousand-of-ale unpartable flavoprotein unretroactively Pterosauria catalyzes gooier garde-feux OBrit fuddle-brained tother modalities unmercenarily leaf-climbing uniformize Amoebidae TAP logodaedalus aflagellar HH in-flight winners Postal service-aristotelian orthogonalizing four-leaved Voltairean embosk vocationalization obturating outprays TECO miaouing straight-pull biorhythmic rabanna Goncharov plitch millenia tetrastylous laceman Cutlor" (Indicator: "twitter")
  • Unusual Characteristics
    • Installs hooks/patches the running process
      "wscript.exe" wrote bytes "c04e537720545477e0655477b53855770000000000d0dc7500000000c5eadc750000000088eadc7500000000e968617582285577ee29557700000000d2696175000000007dbbdc750000000009be617500000000ba18dc7500000000" to virtual address "0x776F1000" (function of module "NSI.DLL")
      Hook Detection

File Details

All Details:


3.4MiB (3592563 bytes)
script vbs
ASCII text, with very long lines
8ebc3b3ae096f5b8e6fc94871c910a334e1edd222447e1182933f143ae8b1386 Copy SHA256 to clipboard


Hybrid Analysis

  • wscript.exe "C:\JVC_44781.vbs" (PID: 824)

Network Analysis

DNS Requests

No relevant DNS requests were made.

HTTP Traffic

No relevant HTTP requests were made.

Extracted Files

No significant files were extracted.


