Report - hz.jar

ZIP Format OS Processor Check
ScreenShot
Created 2024.08.14 13:34 Machine s1_win7_x6403
Filename hz.jar
Type Java archive data (JAR)
AI Score Not founds Behavior Score
2.0
ZERO API file : malware
VT API (file) 17 detected (Generic PWS, Java, GenericGBA, many, multiple detections, tutjs, Detected, ai score=87)
md5 785a5628c056701f9a9a73cb0505d3b0
sha256 c1ec07f116ddf1b8ca83021012852ef45ff7e6f1bd0eaef32c82fe5d5ece6915
ssdeep 98304:Ep+GLQqiPDT9RyYyxmNUg1Bx1grkJUAB64RAtYwd3xvV67B:Epd+lHNpgrKfwpyM3xoB
imphash
impfuzzy
  Network IP location

Signature (6cnts)

Level Description
watch File has been identified by 17 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
info Checks amount of memory in system
info Command line console output was observed
info One or more processes crashed

Rules (2cnts)

Level Name Description Collection
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info zip_file_format ZIP file format binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure