Report - minddd.exe

PE File PE64
ScreenShot
Created 2025.02.19 11:41 Machine s1_win7_x6401
Filename minddd.exe
Type PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
AI Score
7
Behavior Score
3.0
ZERO API
VT API (file)
md5 cae5f3774bbda4a4fa5f58e42395829a
sha256 c0b27c4857b4a6ef6a010bb556a96a0cb6449a3d17766f5324e45c1397515e50
ssdeep 3072:m4vwNUfzbspKNMOccF6l3iMAelbWTz6DLYXDMxM:mowNUMyMOUIGbWqS
imphash
impfuzzy 3::
  Network IP location

Signature (7cnts)

Level Description
danger Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually)
watch Communicates with host for which no DNS query was performed
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks adapter addresses which can be used to detect virtual network interfaces
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info Collects information to fingerprint the system (MachineGuid

Rules (2cnts)

Level Name Description Collection
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
196.251.92.64 SC Web4Africa 196.251.92.64

Suricata ids

PE API

IAT(Import Address Table) is none

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure