Report - cleareddefencebooks.txt.ps1

ScreenShot
Created 2021.08.11 09:45 Machine s1_win7_x6403
Filename cleareddefencebooks.txt.ps1
Type ASCII text, with very long lines, with CRLF line terminators
AI Score Not founds Behavior Score
1.2
ZERO API file : clean
VT API (file) 2 detected (PowerShell)
md5 703ee05b31a78bfda345fca295465315
sha256 66a3ed915457bac2c725eafe2ad9b8520c122d884af1bf0a7031cdf92254f5ad
ssdeep 48:kAi55ioi7Ng1lJQFUolxeG9gNmoeyMkQpnFwey0:kAa5ioi7IlqFxlxexNmr9k4zL
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 2 AntiVirus engines on VirusTotal as malicious
info Command line console output was observed
info Uses Windows APIs to generate a cryptographic key

Rules (0cnts)

Level Name Description Collection

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure