Report - auz.jar

ZIP Format
ScreenShot
Created 2023.04.07 17:59 Machine s1_win7_x6402
Filename auz.jar
Type Zip archive data, at least v2.0 to extract
AI Score Not founds Behavior Score
4.8
ZERO API file : clean
VT API (file)
md5 fe4b915fc460a3efc2475946a62bc86a
sha256 1eda89d07a5830056d977c89e199e2d1d0e1453d3419de5f9899fc3b1dc0575d
ssdeep 3072:GfWILr3jy2KfQbqKORrQbAkZL6NxERbRXVWxQMEcNP62ZPFyvhYb86j1uaMpay14:ghHOStANx8RlWaMACPQhYwe/MIylI
imphash
impfuzzy
  Network IP location

Signature (13cnts)

Level Description
watch Installs itself for autorun at Windows startup
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Checks adapter addresses which can be used to detect virtual network interfaces
notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
notice Creates a suspicious process
notice Executes one or more WMI queries
notice Performs some HTTP requests
notice Starts servers listening
notice Uses Windows utilities for basic Windows functionality
info Checks amount of memory in system
info One or more processes crashed
info Queries for the computername

Rules (1cnts)

Level Name Description Collection
info zip_file_format ZIP file format binaries (upload)

Network (7cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://www.geoplugin.net/json.gp?ip=175.208.134.152 NL Schuberg Philis B.V. 178.237.33.50 clean
checkmybones.dns.army ES Vodafone Ono, S.A. 185.91.69.172 clean
carrozzeriabalestra.it IT Server Plan S.r.l. 46.16.95.61 clean
www.geoplugin.net NL Schuberg Philis B.V. 178.237.33.50 clean
185.91.69.172 ES Vodafone Ono, S.A. 185.91.69.172 clean
178.237.33.50 NL Schuberg Philis B.V. 178.237.33.50 clean
46.16.95.61 IT Server Plan S.r.l. 46.16.95.61 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure