Report - mimi.ps1

Vidar Hide_EXE OS Processor Check
ScreenShot
Created 2024.10.20 10:20 Machine s1_win7_x6403
Filename mimi.ps1
Type Rich Text Format data, version 1, ANSI
AI Score Not founds Behavior Score
1.8
ZERO API file : mailcious
VT API (file)
md5 ab386df4cc481edfb162c6bee296d486
sha256 92b5c30d0dc79082e817d0ff06a985ead86dfcdff5d067922a027083eb7aba1e
ssdeep 12288:NyAZ12f9O2Bc8kzpCVYrD6ABwr7ui+N//eFU01Ylbixxn76kjmukmCKZrAiEz6qQ:dZ12fhqlNuFUHbiHn76k5
imphash
impfuzzy
  Network IP location

Signature (5cnts)

Level Description
notice An application raised an exception which may be indicative of an exploit crash
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Creates executable files on the filesystem
notice Creates hidden or system file
info One or more processes crashed

Rules (4cnts)

Level Name Description Collection
danger Vidar_IN Vidar binaries (download)
danger Vidar_IN Vidar binaries (upload)
warning hide_executable_file Hide executable file binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure