ScreenShot
Created | 2021.04.02 10:43 | Machine | s1_win7_x6402 |
Filename | ................................................................................................................dot | ||
Type | Rich Text Format data, unknown version | ||
AI Score | Not founds | Behavior Score |
|
ZERO API | file : mailcious | ||
VT API (file) | 22 detected (RTFObfustream, ObfsObjDat, multiple detections, dinbqn, Obfuscated, RTFMALFORM, BadFile, OLE2, Malform, Probably Heur, RTFBadVersion, ai score=87, objupdate) | ||
md5 | 5a0a86f08f57c385df9626f26e1a3bc9 | ||
sha256 | cdfb17843f16222331c67ee433ed5692f2eaa53d0490f7ab3fd606c82124f332 | ||
ssdeep | 384:PDgwA8OzV1UVyxM1Z0Ie8KrnTeQP1Ka8dwPpVpAuWD5:PDgwROzV2YyDKrniQE3dwP/2 | ||
imphash | |||
impfuzzy |
Network IP location
Signature (9cnts)
Level | Description |
---|---|
warning | File has been identified by 22 AntiVirus engines on VirusTotal as malicious |
watch | Communicates with host for which no DNS query was performed |
notice | Allocates read-write-execute memory (usually to unpack itself) |
notice | An application raised an exception which may be indicative of an exploit crash |
notice | Creates hidden or system file |
notice | HTTP traffic contains suspicious features which may be indicative of malware related traffic |
notice | Performs some HTTP requests |
notice | RTF file has an unknown version |
info | One or more processes crashed |
Rules (0cnts)
Level | Name | Description | Collection |
---|