Report - user4.tx.ps1

Generic Malware Antivirus
ScreenShot
Created 2021.10.28 10:24 Machine s1_win7_x6403
Filename user4.tx.ps1
Type ASCII text, with very long lines, with CRLF line terminators
AI Score Not founds Behavior Score
2.6
ZERO API file : clean
VT API (file) 12 detected (PowerShell, GenericKDZ, ai score=82)
md5 af2bec1985c781dc79389c9d63b6d8c5
sha256 0e6307820c99d145f3cec29e7c09c6871171abd6f9b9096f2cddfd89c3b9cff6
ssdeep 96:g2+dz8qVsVulmO7UIO1mWO7UI3myA2+rz42+Jz2CHDuCXDWVsVt2NBWMG:IWAmVI8y
imphash
impfuzzy
  Network IP location

Signature (8cnts)

Level Description
watch File has been identified by 12 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks adapter addresses which can be used to detect virtual network interfaces
notice Connects to a Dynamic DNS Domain
info Checks amount of memory in system
info Command line console output was observed
info Queries for the computername
info Uses Windows APIs to generate a cryptographic key

Rules (2cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (download)
watch Antivirus Contains references to security software binaries (download)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
user1.redirectme.net Unknown 0.0.0.0 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure