Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Drops PE files
Found dropped PE file which has not been started or loaded
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Usage Of Web Request Commands And Cmdlets
Stores files to the Windows start menu directory
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
- System is w10x64
- cmd.exe (PID: 6872 cmdline:
C:\Windows \system32\ cmd.exe /c wget -t 2 -v -T 60 -P "C:\Use rs\user\De sktop\down load" --no -check-cer tificate - -content-d isposition --user-ag ent="Mozil la/5.0 (Wi ndows NT 6 .1; WOW64; Trident/7 .0; AS; rv :11.0) lik e Gecko" " https://gi thub.com/e clipse-eca l/ecal/rel eases/down load/v5.13 .3/ecal_5. 13.3-win64 .exe" > cm dline.out 2>&1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 6896 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - wget.exe (PID: 7036 cmdline:
wget -t 2 -v -T 60 - P "C:\User s\user\Des ktop\downl oad" --no- check-cert ificate -- content-di sposition --user-age nt="Mozill a/5.0 (Win dows NT 6. 1; WOW64; Trident/7. 0; AS; rv: 11.0) like Gecko" "h ttps://git hub.com/ec lipse-ecal /ecal/rele ases/downl oad/v5.13. 3/ecal_5.1 3.3-win64. exe" MD5: 3DADB6E2ECE9C4B3E1E322E617658B60)
- ecal_5.13.3-win64.exe (PID: 4428 cmdline:
"C:\Users\ user\Deskt op\downloa d\ecal_5.1 3.3-win64. exe" MD5: 333C92633D239E787B05DEB077446BCC) - ecal_5.13.3-win64.tmp (PID: 6508 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\is-MCO U1.tmp\eca l_5.13.3-w in64.tmp" /SL5="$204 1C,7015236 6,845824,C :\Users\us er\Desktop \download\ ecal_5.13. 3-win64.ex e" MD5: 2A7019D6551F63D54843D11967E03B91)
- cleanup
System Summary |
