Report - questioneer-pdf.js

ScreenShot
Created 2021.10.18 10:02 Machine s1_win7_x6403
Filename questioneer-pdf.js
Type ASCII text, with very long lines, with no line terminators
AI Score Not founds Behavior Score
1.6
ZERO API file : clean
VT API (file) 15 detected (Startup, Eldorado, gen52, VSNTJH21, GenericKD, UnclassifiedMalware@0, ai score=81, Tnega)
md5 93b27733d5e46b676eca9cf990652070
sha256 a799700b7e69cf25a7a59b29a10152e1f6daac91c00da3b54b655b69dd5f07be
ssdeep 1536:xEBprfWyvKwuY7FuG3ysXlpkXYFjW1gTc5iJoyGpM/cwua2:xEBprfWyvKwd7FPysXlpkXYFjW1gTEyY
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
watch File has been identified by 15 AntiVirus engines on VirusTotal as malicious
notice Executes one or more WMI queries
notice Executes one or more WMI queries which can be used to identify virtual machines
info Queries for the computername

Rules (0cnts)

Level Name Description Collection

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure