caaed70daa7832952ae93f41131e74dcb6724bb8669d18f28fbed4aa983fdc0c.vbs
Classification: Malicious
caaed70daa7832952ae93f41131e74dcb6724bb8669d18f28fbed4aa983fdc0c.vbs is a malicious file sample. Linked to Turla, Oilrig activity.
Detection summary
- 15 antivirus detections (57% detection ratio)
- 0 IDS alerts
- 2 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2023-05-05 18:15:04 |
2023-05-05 18:15:04 |
|
|
| Turla |
Maltiverse |
2023-03-03 04:26:37 |
2023-03-04 19:42:15 |
malicious-activity
|
G0010 Turla
|
| OilRig |
Maltiverse |
2023-03-03 04:26:38 |
2023-03-04 19:41:59 |
malicious-activity
|
G0049 OilRig
|
| Trojan.Generic |
Hybrid-Analysis |
2019-06-20 13:00:10 |
2019-06-20 13:00:10 |
|
|
Tags
apt
hacktool
metasploit
meterpreter
apt34
Sample information
- Filenames
- caaed70daa7832952ae93f41131e74dcb6724bb8669d18f28fbed4aa983fdc0c.vbs
- File type
- ASCII text, with CRLF line terminators
- Size
- 3489 bytes
- MD5
59e6b97e7a3ada359e84d92302d02dfe
- SHA-1
d80c3be1dcadf22e542275e9e743e4ce4efbdff6
- SHA-256
caaed70daa7832952ae93f41131e74dcb6724bb8669d18f28fbed4aa983fdc0c
- First indexed
- 2019-06-20 13:00:10
- Last updated
- 2023-05-05 18:15:04
Antivirus detections
| Engine | Detection |
| MicroWorld-eScan | Trojan.GenericKD.41338846 |
| AegisLab | Trojan.Script.Generic.4!c |
| NANO-Antivirus | Trojan.Script.Vbs-heuristic.druvzi |
| ESET-NOD32 | VBS/Agent.CB |
| BitDefender | Trojan.GenericKD.41338846 |
| Rising | Trojan.Agent!8.B1E (TOPIS:E0:JMidgyphXxT) |
| Ad-Aware | Trojan.GenericKD.41338846 |
| Emsisoft | Trojan.GenericKD.41338846 (B) |
| FireEye | Trojan.GenericKD.41338846 |
| Ikarus | Trojan.VBS.Agent |
| Cyren | Trojan.YYMW-1 |
| Arcabit | Trojan.Generic.D276C7DE |
| ALYac | Trojan.GenericKD.41338846 |
| MaxSecure | Trojan.Malware.74371100.susgen |
| GData | Trojan.GenericKD.41338846 |
Process list
| Name | Command line |
| wscript.exe | "C:\caaed70daa7832952ae93f41131e74dcb6724bb8669d18f28fbed4aa983fdc0c.vbs" |
| WScript.exe | "C:\caaed70daa7832952ae93f41131e74dcb6724bb8669d18f28fbed4aa983fdc0c.vbs" |