ScreenShot
Created | 2023.12.14 19:03 | Machine | s1_win7_x6401 |
Filename | demon.exe | ||
Type | PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : malware | ||
VT API (file) | 37 detected (AIDetectMalware, malicious, high confidence, score, Havokiz, Marte, unsafe, Havoc, Vugh, Attribute, HighConfidence, AGen, Muj2LsPTQQM, Detected, ai score=87, Ngil, Static AI, Malicious PE, confidence) | ||
md5 | e402b4d496e16fb8e2fc44bf12c9cc4e | ||
sha256 | 3aad93d064d729509e499014d59f0c5b3d290f5d130bcba94e2d8f069d8881dd | ||
ssdeep | 1536:wkJIalOYktfCM83v6pq9UVE/kGE5+Kb+LwoMSJZNx5FOSxdbz:/lITtfCMT2UVE/kOXMSJZDPOSxdb | ||
imphash | |||
impfuzzy | 3:: |
Network IP location
Signature (4cnts)
Level | Description |
---|---|
danger | Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually) |
danger | File has been identified by 37 AntiVirus engines on VirusTotal as malicious |
watch | Communicates with host for which no DNS query was performed |
notice | Checks adapter addresses which can be used to detect virtual network interfaces |
Rules (3cnts)
Level | Name | Description | Collection |
---|---|---|---|
warning | Generic_Malware_Zero | Generic Malware | binaries (upload) |
info | IsPE64 | (no description) | binaries (upload) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |