Report - qraken.jar

ZIP Format
ScreenShot
Created 2024.08.14 13:25 Machine s1_win7_x6403
Filename qraken.jar
Type Java archive data (JAR)
AI Score Not founds Behavior Score
1.4
ZERO API file : malware
VT API (file)
md5 e6eb86a620745a444b1c16b2415152b1
sha256 bc5b45e00bffb20eb915b2f7bc3989983e0b05b29425af7938f1bccd27fa171f
ssdeep 12288:1bAQeo4Kss13qU26cOpfbhZiKRU8mBd4PLgCwvsO/4oUE:7516nubrW8mH4PSviE
imphash
impfuzzy
  Network IP location

Signature (5cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
info Checks amount of memory in system
info Command line console output was observed
info One or more processes crashed

Rules (1cnts)

Level Name Description Collection
info zip_file_format ZIP file format binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure