Report - invkmc.jpg.vbs

Hide_EXE Antivirus
ScreenShot
Created 2023.10.16 11:51 Machine s1_win7_x6402
Filename invkmc.jpg.vbs
Type ASCII text, with very long lines, with CRLF line terminators
AI Score Not founds Behavior Score
1.4
ZERO API file : clean
VT API (file) 23 detected (GenericKD, PowerShell, PwrSh, Obfuscated, Cryp, Malicious, score, Kryptik, Lcnw, PSRunner, MulDrop, Casdet, Detected, TOPIS, 24WVkx8SUpJ, ai score=80)
md5 7b47208b9424d4beff846d5942f6e384
sha256 f3359a5b250b314013b682313c1d76000171e3381db39b2f66babb21286136b6
ssdeep 1536:ePnzZK1gUbptkcqnIv415PI31kGvEThfes/blXEXmSnjKhSTBn82lu6fVxPRpO63:4gGYtjNE59r2n82dBxX43ApTXmTWJ
imphash
impfuzzy
  Network IP location

Signature (3cnts)

Level Description
warning File has been identified by 23 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
info One or more processes crashed

Rules (2cnts)

Level Name Description Collection
warning hide_executable_file Hide executable file binaries (upload)
watch Antivirus Contains references to security software binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure