ScreenShot
Created | 2024.10.18 10:20 | Machine | s1_win7_x6401 |
Filename | Swift-sleep10-jitter-50-amsiPatch-Breakpoints.dll | ||
Type | PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : malware | ||
VT API (file) | 40 detected (AIDetectMalware, Malicious, score, Havocp, S33873462, Marte, Vxzp, Windows, Havoc, MsfShell, CLASSIC, R002C0DJH24, Static AI, Malicious PE, Detected, Metasploit, Shelma, PikaBot, Rozena, Artemis, Outbreak, CobaltStrike, susgen) | ||
md5 | 68ab6bcbb50fb8f895e92f8c00e350ff | ||
sha256 | e72717c3598893ddb4444f71747b3010171ed14737d63d043ecf9ec7844fd5a5 | ||
ssdeep | 1536:evuO66CQjyU5vgRGHegBARoU9d8jeD+F7n5ULKwJFtwMciaGYOI3lRdgf:evuF6CQ2OgM+e9cCyD+Fj5UL/JjBaGYy | ||
imphash | |||
impfuzzy | 3:: |
Network IP location
Signature (2cnts)
Level | Description |
---|---|
danger | File has been identified by 40 AntiVirus engines on VirusTotal as malicious |
info | One or more processes crashed |
Rules (4cnts)
Level | Name | Description | Collection |
---|---|---|---|
warning | Generic_Malware_Zero | Generic Malware | binaries (upload) |
info | IsDLL | (no description) | binaries (upload) |
info | IsPE32 | (no description) | binaries (upload) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |
Network (0cnts) ?
Request | CC | ASN Co | IP4 | Rule ? | ZERO ? |
---|