Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
jsv.js

Overview

General Information

Sample name:jsv.js
Analysis ID:1530691
MD5:f4da914becc120f5f88ac4a395ada3cb
SHA1:d0fdb88d7bc0c8c2a66fb04ef803550026a36cae
SHA256:4f71f92d33d769dbf2ce31b458e9eac68532bc863d60b4161a31b22f36de272a
Infos:

Detection

Score:22
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Sigma detected: WScript or CScript Dropper
Found WSH timer for Javascript or VBS script (likely evasive script)
Java / VBScript file with very long strings (likely obfuscated code)
Program does not show much activity (idle)
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript

Classification

  • System is w10x64
  • wscript.exe (PID: 6496 cmdline: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\jsv.js" MD5: A47CBE969EA935BDD3AB568BB126BC80)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Process startedAuthor: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: Data: Command: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\jsv.js", CommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\jsv.js", CommandLine|base64offset|contains: , Image: C:\Windows\System32\wscript.exe, NewProcessName: C:\Windows\System32\wscript.exe, OriginalFileName: C:\Windows\System32\wscript.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 2580, ProcessCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\jsv.js", ProcessId: 6496, ProcessName: wscript.exe
Source: Process startedAuthor: Michael Haag: Data: Command: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\jsv.js", CommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\jsv.js", CommandLine|base64offset|contains: , Image: C:\Windows\System32\wscript.exe, NewProcessName: C:\Windows\System32\wscript.exe, OriginalFileName: C:\Windows\System32\wscript.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 2580, ProcessCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\jsv.js", ProcessId: 6496, ProcessName: wscript.exe
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results
Source: wscript.exe, 00000000.00000003.1780321005.00000162F9C6E000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.1780609757.00000162F9C70000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779657602.00000162F9C5F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://aadcdn.msauth.net/shared/1.0/content/images/
Source: wscript.exe, 00000000.00000003.1779588604.00000162F9CBB000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779526252.00000162F9C71000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779888432.00000162F9CAF000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1684101104.00000162FB9D2000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779341162.00000162FB9EF000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779773435.00000162FBB41000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.1780624337.00000162F9CAF000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1780089472.00000162F9CAF000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.1780801603.00000162FBAE0000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779727190.00000162FB9EF000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779421296.00000162FBB42000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1684159276.00000162FB9EF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://aadcdn.msauth.net/shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.s
Source: wscript.exe, 00000000.00000003.1779421296.00000162FBB42000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779773435.00000162FBAE1000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1684159276.00000162FB9EF000.00000004.00000020.00020000.00000000.sdmp, jsv.jsString found in binary or memory: https://aadcdn.msauth.net/shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.
Source: wscript.exe, 00000000.00000003.1779588604.00000162F9CBB000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779526252.00000162F9C71000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1684101104.00000162FB9D2000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1683707906.00000162FB9F0000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779297875.00000162FBB71000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779483421.00000162F9CFA000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779421296.00000162FBB42000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779773435.00000162FBAE1000.00000004.00000020.00020000.00000000.sdmp, jsv.jsString found in binary or memory: https://aadcdn.msauth.net/shared/1.0/content/images/picker_verify_sms_12b7d768ba76f2e782cc74e3281710
Source: wscript.exe, 00000000.00000003.1779773435.00000162FBB9E000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779421296.00000162FBB9E000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.1780801603.00000162FBB9E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://aadcdn.msftauth.net/shared/1.0/content/images/appbackgrounds/49_6ffe0a92d779c878835b40171ffc
Source: wscript.exe, 00000000.00000003.1779588604.00000162F9CBB000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779526252.00000162F9C71000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1684101104.00000162FB9D2000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1683707906.00000162FB9F0000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779773435.00000162FBAE1000.00000004.00000020.00020000.00000000.sdmp, jsv.jsString found in binary or memory: https://google.com
Source: wscript.exe, 00000000.00000003.1779588604.00000162F9CBB000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779526252.00000162F9C71000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1684101104.00000162FB9D2000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1683707906.00000162FB9F0000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779297875.00000162FBB71000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779483421.00000162F9CFA000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779421296.00000162FBB42000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779773435.00000162FBAE1000.00000004.00000020.00020000.00000000.sdmp, jsv.jsString found in binary or memory: https://logincdn.msauth.net/shared/1.0/content/images/arrow_left_7cc096da6aa2dba3f81fcc1c8262157c.pn
Source: jsv.jsString found in binary or memory: https://logincdn.msauth.net/shared/1.0/content/images/arrow_left_a9cc2824ef3517b6c4160dcf8ff7d410.sv
Source: wscript.exe, 00000000.00000003.1684101104.00000162FB9D2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://softwarereviews.s3.amazonaws.com/production/favicons/offerings/3117/original/Sharepoint_icon
Source: jsv.jsInitial sample: Strings found which are bigger than 50
Source: classification engineClassification label: sus22.winJS@1/0@0/0
Source: C:\Windows\System32\wscript.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: sxs.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: jscript.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: amsi.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: msisip.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: wshext.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: scrobj.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\wscript.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\wscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f414c260-6ac0-11cf-b6d1-00aa00bbbb58}\InprocServer32Jump to behavior
Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\wscript.exeWindow found: window name: WSH-TimerJump to behavior
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Windows\System32\wscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information2
Scripting
Valid AccountsWindows Management Instrumentation2
Scripting
1
DLL Side-Loading
1
DLL Side-Loading
OS Credential Dumping2
System Information Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
Boot or Logon Initialization Scripts1
Obfuscated Files or Information
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://softwarereviews.s3.amazonaws.com/production/favicons/offerings/3117/original/Sharepoint_icon0%VirustotalBrowse
https://google.com0%VirustotalBrowse
https://aadcdn.msftauth.net/shared/1.0/content/images/appbackgrounds/49_6ffe0a92d779c878835b40171ffc0%VirustotalBrowse
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://google.comwscript.exe, 00000000.00000003.1779588604.00000162F9CBB000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779526252.00000162F9C71000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1684101104.00000162FB9D2000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1683707906.00000162FB9F0000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779773435.00000162FBAE1000.00000004.00000020.00020000.00000000.sdmp, jsv.jsfalseunknown
https://aadcdn.msftauth.net/shared/1.0/content/images/appbackgrounds/49_6ffe0a92d779c878835b40171ffcwscript.exe, 00000000.00000003.1779773435.00000162FBB9E000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1779421296.00000162FBB9E000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.1780801603.00000162FBB9E000.00000004.00000020.00020000.00000000.sdmpfalseunknown
https://softwarereviews.s3.amazonaws.com/production/favicons/offerings/3117/original/Sharepoint_iconwscript.exe, 00000000.00000003.1684101104.00000162FB9D2000.00000004.00000020.00020000.00000000.sdmpfalseunknown
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1530691
Start date and time:2024-10-10 11:59:48 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 1m 52s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:1
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:jsv.js
Detection:SUS
Classification:sus22.winJS@1/0@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .js
  • Stop behavior analysis, all processes terminated
No simulations
No context
No context
No context
No context
No context
No created / dropped files found
File type:exported SGML document, Unicode text, UTF-8 text, with very long lines (65506)
Entropy (8bit):4.536852504535395
TrID:
    File name:jsv.js
    File size:128'757 bytes
    MD5:f4da914becc120f5f88ac4a395ada3cb
    SHA1:d0fdb88d7bc0c8c2a66fb04ef803550026a36cae
    SHA256:4f71f92d33d769dbf2ce31b458e9eac68532bc863d60b4161a31b22f36de272a
    SHA512:c0b34c485d66d30501549b0456840cb96ba97f9c516d6196cb86eb1ee9af0a2e769e2e6eb2d9511794e105b8527c8f38e22bbf071322c3260d57eb7d295f9ddc
    SSDEEP:3072:Angz3cwtj4+eS6e6+XE3TLc7OfmmmmmUmBs/T+:AnU3cwtj4+eS6e6+XE3TLD+
    TLSH:7BC365E5C550D3BDA307CD116E7E8548E375070795C04B8A34ACF98A8BCDA3BE5AE4B8
    File Content Preview:function _0xb276() {. const _0x5ed944 = ['href', '.phoneotpText', 'readyState', '#playme_big', '@ionos.', '#playme', 'resize', 's2c_restart', '.loaderxBlock11', 's2c', 'complete', 'O365', 'url(\x27https://aadcdn.msauth.net/shared/1.0/content/images/bac
    Icon Hash:68d69b8bb6aa9a86
    No network behavior found

    Click to jump to process

    Click to jump to process

    Click to dive into process behavior distribution

    Target ID:0
    Start time:06:00:40
    Start date:10/10/2024
    Path:C:\Windows\System32\wscript.exe
    Wow64 process (32bit):false
    Commandline:C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\jsv.js"
    Imagebase:0x7ff640570000
    File size:170'496 bytes
    MD5 hash:A47CBE969EA935BDD3AB568BB126BC80
    Has elevated privileges:false
    Has administrator privileges:false
    Programmed in:C, C++ or other language
    Reputation:high
    Has exited:true

    No disassembly