Report - 44285,5327891204.dat

Created 2021.04.03 10:41 Machine s1_win7_x6402
Filename 44285,5327891204.dat
Type PE32+ executable (DLL) (GUI) x86-64, for MS Windows
AI Score
Behavior Score
ZERO API file : malware
VT API (file)
md5 c158fc170ee9e86e01731354363238e5
sha256 1ed55afbd8222bebb642f6b70bee728c331ca7d335a2c5024f29919f307dceb0
ssdeep 1536:caCAzXz8T6rLXah8lI+Idu+B3XbuF6dRiF:n/gTkXayetu+BbuUQ
imphash eb10ff98c4adb7472a591c82bd2ff673
impfuzzy 3:ssD76BJO7aC:pUA2C
  Network IP location

Signature (4cnts)

Level Description
watch Communicates with host for which no DNS query was performed
info Checks amount of memory in system
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (8cnts)

Level Name Description Collection
info IsDLL (no description) binaries (upload)
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature Zero binaries (upload)
info HasDebugData DebugData Check binaries (upload)
info HasOverlay Overlay Check binaries (upload)
info HasRichSignature Rich Signature Check binaries (upload)
info IsWindowsGUI (no description) binaries (upload)
info win_files_operation Affect private profile binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

Similarity measure (PE file only) - Checking for service failure