Report - Albion.ps1

Generic Malware Antivirus
ScreenShot
Created 2025.04.02 10:09 Machine s1_win7_x6403
Filename Albion.ps1
Type UTF-8 Unicode text, with CRLF line terminators
AI Score Not founds Behavior Score
4.4
ZERO API file : mailcious
VT API (file) 2 detected (PowerShell)
md5 c498ec828bc8f082a5f43215db42a4b6
sha256 5720662d40be94b68735a96ef056f5a777c879db3af470c01ad2297a15a1d06a
ssdeep 48:c4kjd6jyjIf3SgzgZFvmfZHCkUNO807wmANO5+Djbx:0i6iv8AwmrQDjl
imphash
impfuzzy
  Network IP location

Signature (8cnts)

Level Description
danger Connects to IP addresses that are no longer responding to requests (legitimate services will remain up-and-running usually)
watch A process attempted to delay the analysis task.
watch Communicates with host for which no DNS query was performed
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks adapter addresses which can be used to detect virtual network interfaces
notice File has been identified by 2 AntiVirus engines on VirusTotal as malicious
info Queries for the computername
info Uses Windows APIs to generate a cryptographic key

Rules (2cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (download)
watch Antivirus Contains references to security software binaries (download)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
213.209.150.191 Unknown 213.209.150.191 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure