Report - W10DigitalActivation_x64.iso

AntiDebug AntiVM
ScreenShot
Created 2024.08.18 10:15 Machine s1_win7_x6401
Filename W10DigitalActivation_x64.iso
Type ISO 9660 CD-ROM filesystem data 'DISC'
AI Score Not founds Behavior Score
1.2
ZERO API file : clean
VT API (file)
md5 89bd10832539a85ef8557b8976a38207
sha256 79b2e146fe7a0eb57623f424684d8bc0ef696b92ef45d60aaca4f23ea96d8432
ssdeep 49152:PW7o5tEJPYiyqHMJrFQ5YkWrn1NH5suxg0MHsxjFR:ec5tA/y3rFQ5Yken1d5u0MHsxpR
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice Yara rule detected in process memory
info Checks amount of memory in system
info Checks if process is being debugged by a debugger

Rules (8cnts)

Level Name Description Collection
info anti_dbg Checks if being debugged memory
info DebuggerCheck__GlobalFlags (no description) memory
info DebuggerCheck__QueryInfo (no description) memory
info DebuggerHiding__Active (no description) memory
info DebuggerHiding__Thread (no description) memory
info disable_dep Bypass DEP memory
info SEH__vectored (no description) memory
info ThreadControl__Context (no description) memory

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure