Report - cod.pdf.vbs

Antivirus
ScreenShot
Created 2023.10.25 12:19 Machine s1_win7_x6402
Filename cod.pdf.vbs
Type UTF-8 Unicode text, with very long lines, with CRLF line terminators
AI Score Not founds Behavior Score
1.0
ZERO API file : mailcious
VT API (file) 6 detected (PowerShell)
md5 b5ef73339bacf531b3d122ebd9509468
sha256 f98f06e6f8d0d162c37dc5a904321e32b8c4032675470db828ef743c221dbc5b
ssdeep 24576:6aiD80mN5MUpdiLQX+TPWOWDAdyGd85ZI6OrM5M8rhor0B5Lccs83kuMy1xnK2NW:K
imphash
impfuzzy
  Network IP location

Signature (3cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 6 AntiVirus engines on VirusTotal as malicious
info One or more processes crashed

Rules (1cnts)

Level Name Description Collection
watch Antivirus Contains references to security software binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure