Report - 44285,5327891204.dat

ScreenShot
Created 2021.04.01 09:51 Machine s1_win7_x6401
Filename 44285,5327891204.dat
Type PE32+ executable (DLL) (GUI) x86-64, for MS Windows
AI Score
5
Behavior Score
0.4
ZERO API file : clean
VT API (file)
md5 6a5564a3b29538dcbdacd63636306521
sha256 2053a9da78f71ae8316e6265f36a2b9dc6b3f4f450bdd7c78be92f22d81eb52a
ssdeep 1536:MhQeEn2s56EdRX096SioHkvr+LlXpFyrEU:MqRjH0Eptvr+FzxU
imphash
impfuzzy 3::
  Network IP location

Signature (2cnts)

Level Description
info Checks amount of memory in system
info One or more processes crashed

Rules (8cnts)

Level Name Description Collection
info IsDLL (no description) binaries (upload)
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature Zero binaries (upload)
info HasDebugData DebugData Check binaries (upload)
info HasOverlay Overlay Check binaries (upload)
info HasRichSignature Rich Signature Check binaries (upload)
info ImportTableIsBad ImportTable Check binaries (upload)
info IsWindowsGUI (no description) binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure