Report - Preview.exe

UPX Malicious Library MZP Format PE File
ScreenShot
Created 2023.03.12 21:40 Machine s1_win7_x6401
Filename Preview.exe
Type MS-DOS executable
AI Score Not founds Behavior Score
0.0
ZERO API file : clean
VT API (file)
md5 86257e16e9db1d0740183fa624805d5f
sha256 6842524e26b6a74af7a4254f36c8c6dc2ade1c319d6dca6aaed943cc8f403ea3
ssdeep 24576:AQDwy8cbMtMJjLKRfwaNSkxtkNkYzSYcj0oHyxdpVhNZFGv+56nBb/ExWyoMA3f/:AlrTQnC1QaX4+IQ
imphash
impfuzzy
  Network IP location

Signature (0cnts)

Level Description

Rules (4cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure