ScreenShot
Created | 2023.07.05 17:25 | Machine | s1_win7_x6401 |
Filename | FA002.exe | ||
Type | PE32 executable (GUI) Intel 80386, for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | |||
VT API (file) | 29 detected (AIDetectMalware, Vise, Attribute, HighConfidence, malicious, high confidence, GenericML, xnet, GenericKD, Generic@AI, RDML, pKGxdQwA8YhB7ENi5DljrQ, RHADAMANTHYS, YXDGDZ, score, Generic Reputation PUA, Wacatac, Artemis, ai score=88, Chgt, Behavior, ZexaCO, Bv0@aub, J3iO, confidence, 100%) | ||
md5 | 4ca5a34884534a5751b8e59d41cecdcb | ||
sha256 | 78a123cbb6dae6d4bb09a82e7c9551e385aee0f5eb8f9a4ff0de8f2fc4dbdd22 | ||
ssdeep | 24576:NxdzBAGMq38k5CtXu/hX2hpQlmwgqyN3t2HnF2890ErDfpBws:Nl7Ou6pTAytt2HF2yfp | ||
imphash | |||
impfuzzy | 3:: |
Network IP location
Signature (3cnts)
Level | Description |
---|---|
warning | File has been identified by 29 AntiVirus engines on VirusTotal as malicious |
notice | The binary likely contains encrypted or compressed data indicative of a packer |
info | One or more processes crashed |
Rules (3cnts)
Level | Name | Description | Collection |
---|---|---|---|
watch | UPX_Zero | UPX packed file | binaries (upload) |
info | IsPE32 | (no description) | binaries (upload) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |
Network (0cnts) ?
Request | CC | ASN Co | IP4 | Rule ? | ZERO ? |
---|
Suricata ids
PE API
IAT(Import Address Table) is none
EAT(Export Address Table) is none
EAT(Export Address Table) is none