caaed70daa7832952ae93f41131e74dcb6724bb8669d18f28fbed4aa983fdc0c.vbs

Classification: Malicious

caaed70daa7832952ae93f41131e74dcb6724bb8669d18f28fbed4aa983fdc0c.vbs is a malicious file sample. Linked to Turla, Oilrig activity.

Detection summary

  • 15 antivirus detections (57% detection ratio)
  • 0 IDS alerts
  • 2 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Intrusion sets: TURLA (G0010) OILRIG (G0049)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2023-05-05 18:15:04 2023-05-05 18:15:04
Turla Maltiverse 2023-03-03 04:26:37 2023-03-04 19:42:15 malicious-activity G0010 Turla
OilRig Maltiverse 2023-03-03 04:26:38 2023-03-04 19:41:59 malicious-activity G0049 OilRig
Trojan.Generic Hybrid-Analysis 2019-06-20 13:00:10 2019-06-20 13:00:10

Tags

apt hacktool metasploit meterpreter apt34

Sample information

Filenames
caaed70daa7832952ae93f41131e74dcb6724bb8669d18f28fbed4aa983fdc0c.vbs
File type
ASCII text, with CRLF line terminators
Size
3489 bytes
MD5
59e6b97e7a3ada359e84d92302d02dfe
SHA-1
d80c3be1dcadf22e542275e9e743e4ce4efbdff6
SHA-256
caaed70daa7832952ae93f41131e74dcb6724bb8669d18f28fbed4aa983fdc0c
First indexed
2019-06-20 13:00:10
Last updated
2023-05-05 18:15:04

Antivirus detections

EngineDetection
MicroWorld-eScanTrojan.GenericKD.41338846
AegisLabTrojan.Script.Generic.4!c
NANO-AntivirusTrojan.Script.Vbs-heuristic.druvzi
ESET-NOD32VBS/Agent.CB
BitDefenderTrojan.GenericKD.41338846
RisingTrojan.Agent!8.B1E (TOPIS:E0:JMidgyphXxT)
Ad-AwareTrojan.GenericKD.41338846
EmsisoftTrojan.GenericKD.41338846 (B)
FireEyeTrojan.GenericKD.41338846
IkarusTrojan.VBS.Agent
CyrenTrojan.YYMW-1
ArcabitTrojan.Generic.D276C7DE
ALYacTrojan.GenericKD.41338846
MaxSecureTrojan.Malware.74371100.susgen
GDataTrojan.GenericKD.41338846

Process list

NameCommand line
wscript.exe"C:\caaed70daa7832952ae93f41131e74dcb6724bb8669d18f28fbed4aa983fdc0c.vbs"
WScript.exe"C:\caaed70daa7832952ae93f41131e74dcb6724bb8669d18f28fbed4aa983fdc0c.vbs"