Report - Tinamous.vbs

GuLoader Generic Malware Admin Tool (Sysinternals etc ...)
ScreenShot
Created 2024.04.16 15:22 Machine s1_win7_x6403
Filename Tinamous.vbs
Type ASCII text, with very long lines, with CRLF line terminators
AI Score Not founds Behavior Score
0.4
ZERO API file : clean
VT API (file) 4 detected (SAgent, GuLoader, Wacatac)
md5 e8cd41650fecc932f8c00e3d969f09a6
sha256 e6af0be433b90da64b59e5e95282939f042a3fdc00d280c14101eec593498720
ssdeep 6144:LCdAYDLBLW+8A1ytW3xrbjsSFuHeEC57kdmXl45zaoGGqAP3MQ9scOL085aAuFra:OnS2ImUgYqxt
imphash
impfuzzy
  Network IP location

Signature (1cnts)

Level Description
notice File has been identified by 4 AntiVirus engines on VirusTotal as malicious

Rules (3cnts)

Level Name Description Collection
danger GuLoader_IN GuLoader binaries (upload)
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch Admin_Tool_IN_Zero Admin Tool Sysinternals binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure