Analyse score
4
/ 14
4 antivirus venders flagged
this file as malicious
4 antivirus venders flagged
this file as malicious
CRC32 | 0x18889a41 |
---|---|
MD5 | f5c19415a77d0138e8ae77180c214a66 |
Magic | ASCII text |
SHA1 | e201dbf85011263fee550dcbc5889f0ce71610ac |
SHA256 | e7e7fc4346c9f2a0db1035db0c657260f9b30e6b9c7d4eb792c04af9523057d8 |
SHA512 | 8587962f10668be9085dd63028a50c1a9168c0902b5f72affa1fa6c299530934d3db062d97b784336aaa2650c7d7d7fe5407234481cdd150cb8be85d781197f6 |
SSDeep |
|
Size | 1.75KB |
Packer |
|
TrID |
|
Tags |
ExifToolVersionNumber | 12.62 |
---|---|
FileSize | 1797 bytes |
FileType | TXT |
FileTypeExtension | txt |
LineCount | 70 |
MimeEncoding | us-ascii |
MimeType | text/plain |
Newlines | Unix LF |
WordCount | 166 |
Published | Name | Source | Country |
---|---|---|---|
e7e7fc4346c9f2a0db1035db0c657260f9b30e6b9c7d4eb792c04af9523057d8.vbs | web | IT |
Description | Severity | Category | Module |
---|---|---|---|
Malware detection of a yara signature: Win32/WannaCry | malicious
|
Sandbox Detection | Behavior |
Communicates over HTTP with a low reputation domain | informational
|
C2 | Behavior |
Deletes itself after process termination | suspicious
|
Stealth | Behavior |
Write a file to the startup folder | suspicious
|
Persistence | Behavior |
Check for the existence of Virtual Machines | suspicious
|
Signature | Yara |
🚀 Coming soon!
🚀 Coming soon!