Report - rt.jar

ZIP Format OS Processor Check
ScreenShot
Created 2024.08.14 13:23 Machine s1_win7_x6403
Filename rt.jar
Type Zip archive data, at least v1.0 to extract
AI Score Not founds Behavior Score
2.2
ZERO API file : malware
VT API (file) 22 detected (Java, Malicious, score, Generic PWS, GenericGBA, many, multiple detections, tutjs, Detected, ai score=85, ABRisk, XAJZ, Ratty)
md5 543e736a1f4b4f0cb420b076b478e85b
sha256 7096a90b6c9a8fbe6c56af1dd49e3fe578308fc1bec054bf2572b6ca9b635439
ssdeep 98304:PSVhsnvDr9d1GFobjRvhi65kNC00lP3RBeCQ6z74QT9ky2e:6VhUrHoFoxvmN2RkMzAe
imphash
impfuzzy
  Network IP location

Signature (6cnts)

Level Description
warning File has been identified by 22 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
info Checks amount of memory in system
info Command line console output was observed
info One or more processes crashed

Rules (2cnts)

Level Name Description Collection
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info zip_file_format ZIP file format binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure