Report - LATH.ps1

Formbook Hide_EXE Generic Malware Antivirus
ScreenShot
Created 2023.06.27 07:39 Machine s1_win7_x6403
Filename LATH.ps1
Type ASCII text, with very long lines, with no line terminators
AI Score Not founds Behavior Score
1.4
ZERO API file : clean
VT API (file) 1 detected (Kryptik, AGQQ)
md5 45d5e30ed69d3ef0e2a5d558afee3c6b
sha256 daab8414c732f29a4909fb72d61d2e92fc6b958c91dc270b040ca700a25d68a7
ssdeep 49152:VY1wOeTfeinwRg0Yd0YtWdR2++BqkPiblNmBZOqsHtL3rdyW6JKHINYMpnkq/3+W:3
imphash
impfuzzy
  Network IP location

Signature (5cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by one AntiVirus engine on VirusTotal as malicious
info Checks amount of memory in system
info Command line console output was observed
info Uses Windows APIs to generate a cryptographic key

Rules (4cnts)

Level Name Description Collection
danger Win_Trojan_Formbook_Zero Used Formbook binaries (upload)
warning Generic_Malware_Zero Generic Malware binaries (download)
warning hide_executable_file Hide executable file binaries (upload)
watch Antivirus Contains references to security software binaries (download)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure