Report - amsi.ps1

Hide_EXE Generic Malware Antivirus
ScreenShot
Created 2024.01.13 19:33 Machine s1_win7_x6403
Filename amsi.ps1
Type ASCII text, with very long lines
AI Score Not founds Behavior Score
1.2
ZERO API file : malware
VT API (file) 27 detected (Disable, AMSI, Save, PwrSh, AmsiBypass, Malicious, score, UnicornBypass, TOPIS, RJFMipMVEMJ, EvaAmsi, Detected, PowerShell, Gflw)
md5 11a2c5a1096a4b63edcd96e578b1138d
sha256 a496456dafc856b87bdc454753aa7e02e10b62801dc4cea5f4eb1c037d00f56d
ssdeep 96:FdvbfVjvxwVuECW9wYCpmBMHogquBjYmyIt83OSXpF7dkaIoAtRFlenvPH:FdvbfVmujW9U1HoMBxyPbNdwoKFenXH
imphash
impfuzzy
  Network IP location

Signature (2cnts)

Level Description
warning File has been identified by 27 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)

Rules (3cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (download)
warning hide_executable_file Hide executable file binaries (upload)
watch Antivirus Contains references to security software binaries (download)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure