ScreenShot
Created 2025.04.15 09:45 Machine s1_win7_x6401
Filename loader.hta
Type HTML document, UTF-8 Unicode text, with very long lines
AI Score Not founds Behavior Score
1.6
ZERO API file : clean
VT API (file)
md5 3d38ab222579d17632acd5d383490a05
sha256 7ac6f0e34ab766fbb5b199db456aa924bee38561da2d6ea18afd82cdcab06bd2
ssdeep 6144:bTsrzp8c/saqk3V97HILqgIDSF5Ig9bvZJT3CqbMrhryf65NRPaCieMjAkvCJv1P:3srzp8c/saqk3V97HILqgIDSF5Ig9bvA
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
watch Communicates with host for which no DNS query was performed
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
info Checks amount of memory in system

Rules (0cnts)

Level Name Description Collection

Network (3cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
github.githubassets.com US FASTLY 185.199.108.154 clean
185.199.110.154 US FASTLY 185.199.110.154 clean
92.255.85.2 Unknown 92.255.85.2 malware

Suricata ids



Similarity measure (PE file only) - Checking for service failure