ScreenShot
Created | 2024.10.20 10:20 | Machine | s1_win7_x6403 |
Filename | mimi.ps1 | ||
Type | Rich Text Format data, version 1, ANSI | ||
AI Score | Not founds | Behavior Score |
|
ZERO API | file : mailcious | ||
VT API (file) | |||
md5 | ab386df4cc481edfb162c6bee296d486 | ||
sha256 | 92b5c30d0dc79082e817d0ff06a985ead86dfcdff5d067922a027083eb7aba1e | ||
ssdeep | 12288:NyAZ12f9O2Bc8kzpCVYrD6ABwr7ui+N//eFU01Ylbixxn76kjmukmCKZrAiEz6qQ:dZ12fhqlNuFUHbiHn76k5 | ||
imphash | |||
impfuzzy |
Network IP location
Signature (5cnts)
Level | Description |
---|---|
notice | An application raised an exception which may be indicative of an exploit crash |
notice | Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time) |
notice | Creates executable files on the filesystem |
notice | Creates hidden or system file |
info | One or more processes crashed |
Rules (4cnts)
Level | Name | Description | Collection |
---|---|---|---|
danger | Vidar_IN | Vidar | binaries (download) |
danger | Vidar_IN | Vidar | binaries (upload) |
warning | hide_executable_file | Hide executable file | binaries (upload) |
info | OS_Processor_Check_Zero | OS Processor Check | binaries (upload) |
Network (0cnts) ?
Request | CC | ASN Co | IP4 | Rule ? | ZERO ? |
---|