Report - FORM_PIX EYMVDUI.msi

Gen2 Generic Malware Malicious Packer Malicious Library OS Processor Check MSOffice File
ScreenShot
Created 2021.10.26 14:53 Machine s1_win7_x6402
Filename FORM_PIX EYMVDUI.msi
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.3, MSI Installer, Last Pr
AI Score Not founds Behavior Score
1.4
ZERO API file : clean
VT API (file) 21 detected (GenericKD, Bomber, a variant of Generik, BHNHRYC, ydkps@0, ai score=80, PossibleThreat)
md5 f2836216ca554dfdc8a300decb644911
sha256 951c2f341e914601140aa9ead05895f6957d5cbfda80b81be99015d2be02d44f
ssdeep 24576:zRvtkeYe9oWVRT7FOfOBffR0YcBTTpVtp+GHABYP:zRj9oWVRT7FygfR0YwT1Vtp+GHABY
imphash
impfuzzy
  Network IP location

Signature (3cnts)

Level Description
warning File has been identified by 21 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
info One or more processes crashed

Rules (6cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info Win32_Trojan_Gen_2_0904B0_Zero Win32 Trojan Gen binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure