Report - PDFGOOOOO.HTA

Suspicious_Script_Bin AntiDebug AntiVM MSOffice File
ScreenShot
Created 2024.08.02 09:31 Machine s1_win7_x6401
Filename PDFGOOOOO.HTA
Type HTML document, ASCII text, with very long lines, with CRLF line terminators
AI Score Not founds Behavior Score
10.0
ZERO API file : mailcious
VT API (file) 19 detected (Asthma, GenericKD, SAgent, ai score=87, Detected, Qsmw)
md5 99bbfc2fe6e9742b44c42abf3b9ea18e
sha256 bda545c4d2cc5e3247874f035a9e24b5c9b06eb7ddc5f4b6dd5cd1771e995af1
ssdeep 24576:VSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSd:L
imphash
impfuzzy
  Network IP location

Signature (25cnts)

Level Description
watch Communicates with host for which no DNS query was performed
watch Drops a binary and executes it
watch File has been identified by 19 AntiVirus engines on VirusTotal as malicious
watch Network activity contains more than one unique useragent
watch Network communications indicative of a potential document or script payload download was initiated by the process wscript.exe
watch Resumed a suspended thread in a remote process potentially indicative of process injection
watch The process wscript.exe wrote an executable file to disk
watch Wscript.exe initiated network communications indicative of a script based payload download
watch wscript.exe-based dropper (JScript
notice A process created a hidden window
notice Allocates read-write-execute memory (usually to unpack itself)
notice An application raised an exception which may be indicative of an exploit crash
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Creates a suspicious process
notice Creates executable files on the filesystem
notice Downloads a file or document from Google Drive
notice One or more potentially interesting buffers were extracted
notice Performs some HTTP requests
notice Uses Windows utilities for basic Windows functionality
notice Yara rule detected in process memory
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info Command line console output was observed
info One or more processes crashed
info Queries for the computername

Rules (10cnts)

Level Name Description Collection
warning Suspicious_Obfuscation_Script_2 Suspicious obfuscation script (e.g. executable files) binaries (download)
info anti_dbg Checks if being debugged memory
info DebuggerCheck__GlobalFlags (no description) memory
info DebuggerCheck__QueryInfo (no description) memory
info DebuggerHiding__Active (no description) memory
info DebuggerHiding__Thread (no description) memory
info disable_dep Bypass DEP memory
info Microsoft_Office_File_Zero Microsoft Office File binaries (download)
info SEH__vectored (no description) memory
info ThreadControl__Context (no description) memory

Network (21cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
https://support.google.com/drive/answer/6283888 US GOOGLE 142.251.130.14 clean
https://www.googletagmanager.com/gtag/js?id=G-H30R9PNQFN US GOOGLE 142.250.71.200 clean
https://support.google.com/favicon.ico US GOOGLE 142.251.130.14 clean
https://fonts.gstatic.com/s/googlesans/v16/4UabrENHsxJlGDuGo1OIlLU94YtzCwA.woff US GOOGLE 172.217.24.99 clean
https://docs.google.com/document/d/1F5RULhkoBF-7vdHlyYfHj3e_zEDMCP6lEzhIzBxJ77M/edit US GOOGLE 142.250.76.14 clean
https://fonts.gstatic.com/s/roboto/v18/KFOlCnqEu92Fr1MmEU9fBBc-.woff US GOOGLE 172.217.24.99 clean
https://fonts.gstatic.com/s/roboto/v18/KFOmCnqEu92Fr1Mu4mxM.woff US GOOGLE 172.217.24.99 clean
https://fonts.gstatic.com/s/googlesans/v16/4UaGrENHsxJlGDuGo1OIlL3Owpg.woff US GOOGLE 172.217.24.99 clean
https://www.google-analytics.com/analytics.js US GOOGLE 142.250.76.14 clean
https://fonts.gstatic.com/s/roboto/v18/KFOlCnqEu92Fr1MmWUlfBBc-.woff US GOOGLE 172.217.24.99 clean
www.googletagmanager.com US GOOGLE 142.250.207.104 clean
support.google.com US GOOGLE 142.250.206.206 mailcious
docs.google.com US GOOGLE 172.217.25.174 mailcious
www.newupdatenew.com DE Accelerated IT Services & Consulting GmbH 93.127.201.247 mailcious
www.google-analytics.com US GOOGLE 142.250.76.142 clean
fonts.gstatic.com US GOOGLE 142.250.207.99 clean
142.251.130.14 US GOOGLE 142.251.130.14 clean
142.250.76.14 US GOOGLE 142.250.76.14 clean
172.217.24.99 US GOOGLE 172.217.24.99 clean
142.250.71.200 US GOOGLE 142.250.71.200 clean
93.127.196.158 DE Accelerated IT Services & Consulting GmbH 93.127.196.158 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure