File e7e7fc4346c9f2a0db1035db0c657260f9b30e6b9c7d4eb792c04af9523057d8 Summary

Analyse score

4 / 14

4 antivirus venders flagged
this file as malicious

Last scanned

First submission

File type

vbs

vbs

Basic properties

CRC32

0x18889a41

MD5

f5c19415a77d0138e8ae77180c214a66

Magic

ASCII text

SHA1

e201dbf85011263fee550dcbc5889f0ce71610ac

SHA256

e7e7fc4346c9f2a0db1035db0c657260f9b30e6b9c7d4eb792c04af9523057d8

SHA512

8587962f10668be9085dd63028a50c1a9168c0902b5f72affa1fa6c299530934d3db062d97b784336aaa2650c7d7d7fe5407234481cdd150cb8be85d781197f6

SSDeep

Size

1.75KB

Packer
  • Text: format: plain text[LF]
TrID
  • Warning: file seems to be plain text/ASCII
  • TrID is best suited to analyze binary files!
  • Unknown!
Tags

ExifTool File Metadata

ExifToolVersionNumber

12.62

FileSize

1797 bytes

FileType

TXT

FileTypeExtension

txt

LineCount

70

MimeEncoding

us-ascii

MimeType

text/plain

Newlines

Unix LF

WordCount

166

Submissions

Published Name Source Country
e7e7fc4346c9f2a0db1035db0c657260f9b30e6b9c7d4eb792c04af9523057d8.vbs web IT

Indicators

Description Severity Category Module
Malware detection of a yara signature: Win32/WannaCry
malicious
Sandbox Detection Behavior
Communicates over HTTP with a low reputation domain
informational
C2 Behavior
Deletes itself after process termination
suspicious
Stealth Behavior
Write a file to the startup folder
suspicious
Persistence Behavior
Check for the existence of Virtual Machines
suspicious
Signature Yara

🚀 Coming soon!

Virtual Screens

🚀 Coming soon!