Report - coder.jpg.ps1

Generic Malware Antivirus
ScreenShot
Created 2023.08.24 09:14 Machine s1_win7_x6401
Filename coder.jpg.ps1
Type UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
AI Score Not founds Behavior Score
1.4
ZERO API file : clean
VT API (file)
md5 9fd5e336e107dff7b6636e4d3c59ab87
sha256 1cc0b3adcf389ebff07291223e8f2c9a9b7091de96baaaf583d1444bc769fb48
ssdeep 6144:tFmg2/a9VcVGAPJazeU3tDbg5/snTh+/3YiIVeGgHa14CrqjXxn6qCMcteWKh4k+:20
imphash
impfuzzy
  Network IP location

Signature (5cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates executable files on the filesystem
info Checks amount of memory in system
info Command line console output was observed
info Queries for the computername

Rules (3cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (download)
watch Antivirus Contains references to security software binaries (download)
watch Antivirus Contains references to security software binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure