ScreenShot
Created 2021.11.02 17:45 Machine s1_win7_x6402
Filename ziy.hta
Type HTML document, ASCII text, with very long lines
AI Score Not founds Behavior Score
1.0
ZERO API file : clean
VT API (file) 1 detected (amhb)
md5 5c88bf7225ed953a328bf598abfd9ce6
sha256 1a5f35c150f5277966c76cd5883c2e976191fd2af66d7148047e0bb6997e16c0
ssdeep 192:s/4bSbnzV9mJZ4ELnkhKdOrMnOzu2SuR2Y1R5phUqUYff1bXppmitGgyLC/:VOp9oZ4PhKwrSOq2SA5P17DkrC/
imphash
impfuzzy
  Network IP location

Signature (3cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by one AntiVirus engine on VirusTotal as malicious
info One or more processes crashed

Rules (0cnts)

Level Name Description Collection

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure