ScreenShot
Created | 2023.12.14 19:05 | Machine | s1_win7_x6403 |
Filename | upsync.exe | ||
Type | PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : malware | ||
VT API (file) | 37 detected (AIDetectMalware, malicious, high confidence, score, Havokiz, Marte, unsafe, Havoc, V5ub, Attribute, HighConfidence, AGen, Muj2LsPTQQM, Detected, ai score=82, Lqil, Static AI, Malicious PE, confidence) | ||
md5 | a5b4a20040379236d168fa0547598a54 | ||
sha256 | 7355962a0b9eb57bbedbec7dd55c7a668a9229f5b9b1a9cdb747f2b5c5f8b974 | ||
ssdeep | 1536:jkIoalOYktfCM83vqrErpVE/kGE5+Kb+LwoMSJZNR5FObvb:LFITtfCMjcVE/kOXMSJZjPObvb | ||
imphash | |||
impfuzzy | 3:: |
Network IP location
Signature (5cnts)
Level | Description |
---|---|
danger | File has been identified by 37 AntiVirus engines on VirusTotal as malicious |
watch | Attempts to create or modify system certificates |
watch | Communicates with host for which no DNS query was performed |
notice | Allocates read-write-execute memory (usually to unpack itself) |
notice | Checks adapter addresses which can be used to detect virtual network interfaces |
Rules (3cnts)
Level | Name | Description | Collection |
---|---|---|---|
warning | Generic_Malware_Zero | Generic Malware | binaries (upload) |
info | IsPE64 | (no description) | binaries (upload) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |