Report - 44285,5327891204.dat

ScreenShot
Created 2021.04.01 09:53 Machine s1_win7_x6401
Filename 44285,5327891204.dat
Type PE32+ executable (DLL) (GUI) x86-64, for MS Windows
AI Score
5
Behavior Score
0.4
ZERO API file : malware
VT API (file)
md5 98878f8d10cfa62b07c0ee51036d22c1
sha256 99741cbd63ef3cbbc189d86e474295eb59bed2134019a1dc4db544c8212d2699
ssdeep 1536:MhQeEn2s56EdRX096SioHkvr+LlXpFyrEU:MqRjH0Eptvr+FzxU
imphash
impfuzzy 3::
  Network IP location

Signature (2cnts)

Level Description
info Checks amount of memory in system
info One or more processes crashed

Rules (8cnts)

Level Name Description Collection
info IsDLL (no description) binaries (upload)
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature Zero binaries (upload)
info HasDebugData DebugData Check binaries (upload)
info HasOverlay Overlay Check binaries (upload)
info HasRichSignature Rich Signature Check binaries (upload)
info ImportTableIsBad ImportTable Check binaries (upload)
info IsWindowsGUI (no description) binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure