Report - jd1262ru.zip

ScreenShot
Created 2021.04.02 09:01 Machine s1_win7_x6401
Filename jd1262ru.zip
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
AI Score
2
Behavior Score
2.0
ZERO API file : clean
VT API (file) 45 detected (GenericKD, Dridex, malicious, confidence, 100%, Eldorado, Attribute, HighConfidence, TrojanX, CLOUD, R + Troj, Malware@#1gfpdu46j67by, R057C0DCJ21, susgen, kcloud, score, R372644, BScope, Zbot, ai score=80, GdSda, HgkASQ4A)
md5 9da3ac5eeb02e9e4afd27b1744af5c67
sha256 5b965759f9af66ad12e3fcbf71481799926417240c8cfbd1445d4867238631b8
ssdeep 12288:Rqdbh4CmnCnGeFkc0gajgAEvK9VBG6OearhLp46Y/lSRfs1q:497nXFGgiCU/oY6q
imphash aea7cd92e8d54732bbabf352b513d261
impfuzzy 24:zS55GxJGfBxzcV2py5Ll9jfz8duzPOovpDc/JbKnauyvD6FQ8lRT4Rst9:zS55cJwBxAVL5LnfwEmZXDgcRst9
  Network IP location

Signature (4cnts)

Level Description
danger File has been identified by 45 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
info One or more processes crashed
info This executable has a PDB path

Rules (6cnts)

Level Name Description Collection
info IsDLL (no description) binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature Zero binaries (upload)
info HasDebugData DebugData Check binaries (upload)
info HasRichSignature Rich Signature Check binaries (upload)
info IsWindowsGUI (no description) binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure