Report - Photo.scr

PE File PE32
ScreenShot
Created 2024.06.20 09:26 Machine s1_win7_x6401
Filename Photo.scr
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
5
Behavior Score
0.6
ZERO API file : clean
VT API (file) 3 detected (Ymacco, Detected)
md5 e16c628c4b2be310f75780fdeef94a75
sha256 d18f87c4b237ee2fe8cd55a09036a74de1234304072e0ae718b756ae8bb28e47
ssdeep 48:jXWae+lEpWzRdIw8UNUaNg4OGfeg8TK/j5PNBltENsfI+wGs:hq4zRdIwrXNWO18TmjRNBltq+vs
imphash
impfuzzy 3::
  Network IP location

Signature (2cnts)

Level Description
notice File has been identified by 3 AntiVirus engines on VirusTotal as malicious
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (2cnts)

Level Name Description Collection
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure