Report - Payment_Slip.jar

Antivirus MSOffice File
ScreenShot
Created 2023.12.14 10:15 Machine s1_win7_x6401
Filename Payment_Slip.jar
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Microsoft Software Update for Web Folders (English) 14, Author: Microsoft Corporation, Keywords: Installe
AI Score Not founds Behavior Score
2.4
ZERO API file : mailcious
VT API (file) 20 detected (Java, GenericGB, AppendedJar, csrvpr, Siggen, Eldorado, Wacatac, many, Detected, Strrat, ai score=88, Etecer, bZ57dt, AZAV)
md5 39396afaa066833586662903487761f2
sha256 55a7d34967643cac705a6ad2f9e5d7f755bf4c5297cb0f360a8ff3b30bd2fd1d
ssdeep 6144:01kCiJBBUnKAFMZMzV2qVJx9Y3kBlBOz1hPkoVsdVhacijUK:06C4AuZMzQqVH9YUB+zLZydV7gZ
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
danger A potential heapspray has been detected. 724 megabytes was sprayed onto the heap of the java.exe process
warning File has been identified by 20 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
info Checks amount of memory in system

Rules (2cnts)

Level Name Description Collection
watch Antivirus Contains references to security software binaries (upload)
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure