ScreenShot
Created | 2023.10.11 11:30 | Machine | s1_win7_x6402 |
Filename | disruptive.lnk | ||
Type | PDF document, version 1.5 | ||
AI Score | Not founds | Behavior Score |
|
ZERO API | file : clean | ||
VT API (file) | |||
md5 | 70964a6ad358b8e1ed36b1d6ebd3a03b | ||
sha256 | 3ce3b4fc5334ed0ae78be9add21a15cc47e39f4bc9dbe9226bb0e84b78e963fe | ||
ssdeep | 3072:/X/inTK8d8KDVgeBGcrtR5APS7nl8xylP:/X/iG8+KDVgTcrbSS7l8oP | ||
imphash | |||
impfuzzy |
Network IP location
Signature (3cnts)
Level | Description |
---|---|
watch | One or more non-whitelisted processes were created |
notice | Allocates read-write-execute memory (usually to unpack itself) |
notice | Uses Windows utilities for basic Windows functionality |
Rules (1cnts)
Level | Name | Description | Collection |
---|---|---|---|
notice | PDF_Format_Z | PDF Format | binaries (upload) |
Network (0cnts) ?
Request | CC | ASN Co | IP4 | Rule ? | ZERO ? |
---|