Report - SI-3023-9552783693PDF.jar

Generic Malware Malicious Packer Malicious Library MSOffice File OS Processor Check
ScreenShot
Created 2021.10.14 17:33 Machine s1_win7_x6402
Filename SI-3023-9552783693PDF.jar
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Code pa
AI Score Not founds Behavior Score
1.8
ZERO API file : mailcious
VT API (file) 7 detected (Java, Kryptik, Eldorado, Appjar, gen1, MalGenrc, GenericGB)
md5 2922d30afb359edde8083596e20601dc
sha256 10b8de549614240e9f6bcdbd5ac7b9a407760d9a882c8bb6a3e2cb978f0aa916
ssdeep 98304:P8dUwWyw2YMWN6CfiqdMH64Sz6QK7RpFz2Haq6EByA:0dUqwYWN16WOQK7lzLdKyA
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
watch One or more non-whitelisted processes were created
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 7 AntiVirus engines on VirusTotal as malicious
notice Uses Windows utilities for basic Windows functionality

Rules (5cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure