ScreenShot
Created | 2021.04.29 16:23 | Machine | s1_win7_x6401 |
Filename | cccc.dot | ||
Type | data | ||
AI Score | Not founds | Behavior Score |
|
ZERO API | file : mailcious | ||
VT API (file) | 31 detected (GenericKD, ObfsObjDat, Save, CVE-2017-1188, Camelot, multiple detections, dinbqn, Hacktool, RTFMALFORM, CVE2017, Malformed, Malicious, score, Malform, Probably Heur, RTFBadHeader, Llqw, ai score=100) | ||
md5 | a29a9ab928e578957fed4fb8c67b1e4d | ||
sha256 | 1b7910f1235a93db2e4240c567e2cd831b3ff1b85ee6d54b2d81f67e7f42b510 | ||
ssdeep | 192:RQvj4W+GcAB3vygzutO3i4K8mMNHwTgI0MqgTtnBpKC/JFMpHiFGQWxe364:+vj4XAB3RMn4AuHwsSlVkBiFhWxeq4 | ||
imphash | |||
impfuzzy |
Network IP location
Signature (9cnts)
Level | Description |
---|---|
danger | File has been identified by 31 AntiVirus engines on VirusTotal as malicious |
watch | Communicates with host for which no DNS query was performed |
watch | Libraries known to be associated with a CVE were requested (may be False Positive) |
notice | Allocates read-write-execute memory (usually to unpack itself) |
notice | An application raised an exception which may be indicative of an exploit crash |
notice | Creates hidden or system file |
notice | HTTP traffic contains suspicious features which may be indicative of malware related traffic |
notice | Performs some HTTP requests |
info | One or more processes crashed |
Rules (0cnts)
Level | Name | Description | Collection |
---|
Suricata ids
ET INFO Executable Download from dotted-quad Host
ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile
ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile