Report - shell.ps1

Generic Malware Antivirus PE File DLL PE32 .NET DLL
ScreenShot
Created 2024.10.20 09:17 Machine s1_win7_x6401
Filename shell.ps1
Type ASCII text, with very long lines, with CRLF line terminators
AI Score Not founds Behavior Score
3.8
ZERO API file : clean
VT API (file) 28 detected (Powershell, rozena, MPreter, Save, Hacktool, Rexershell, Malicious, score, PShell, Venom, Detected, HNAB, Camelot, Gkjl, Meterpreter)
md5 8b5569d5eade5245351fe555ea35463d
sha256 9664717f5d5aea7a7be8547894b94fad6cb76fecb39e556ca196a2d6070418df
ssdeep 96:shRGTpcIpmTHIhfSd8nJVPGbIzPk91BOwI6B7aT:shCKIpmTsio16haT
imphash
impfuzzy
  Network IP location

Signature (8cnts)

Level Description
warning File has been identified by 28 AntiVirus engines on VirusTotal as malicious
watch Deletes executed files from disk
watch One or more non-whitelisted processes were created
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates executable files on the filesystem
notice Drops an executable to the user AppData folder
notice Uses Windows utilities for basic Windows functionality
info Uses Windows APIs to generate a cryptographic key

Rules (6cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (download)
watch Antivirus Contains references to security software binaries (download)
info Is_DotNET_DLL (no description) binaries (download)
info IsDLL (no description) binaries (download)
info IsPE32 (no description) binaries (download)
info PE_Header_Zero PE File Signature binaries (download)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure