Report - ProjectFunding_B496.wsf

ScreenShot
Created 2023.04.28 09:07 Machine s1_win7_x6402
Filename ProjectFunding_B496.wsf
Type UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
AI Score Not founds Behavior Score
1.0
ZERO API file : clean
VT API (file) 2 detected ()
md5 de0e6380f06d01c12e312b58221c1fcd
sha256 1fbca45b85697a0e46cc73caefd77291b1f0c8f5ca25dd0d18330c0bf6b5ec7e
ssdeep 768:r04vjQj2kWoQ1b/9SeIVwJF/uiSxp7gZxI6xI3hKxviF:1sj/tQl/9SeIGH0p0Bxve
imphash
impfuzzy
  Network IP location

Signature (3cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 2 AntiVirus engines on VirusTotal as malicious
info One or more processes crashed

Rules (0cnts)

Level Name Description Collection

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure