Report - 44265.9599178241.dat

Gen
ScreenShot
Created 2021.03.11 18:29 Machine s1_win7_x6401
Filename 44265.9599178241.dat
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
AI Score Not founds Behavior Score
0.6
ZERO API file : malware
VT API (file)
md5 39c4c83a789474b9f1d981164eded0bd
sha256 44db0c8da11873d9c09e12edacb7548cc311ff154dafcef3c14279c93f7b0339
ssdeep 6144:0sStWdMjzXIMROe6sywNsY2lde2KK3Q6lDVtDY/3I+q3:RStsmQe6sxs7ld7BPf44+y
imphash 41134329580843af844f8f2e4b2ba41f
impfuzzy 24:asqT2ZYfVvqPOovnZt5DjMCc+yDWL/JKBv5FQHNRT4nfGvSR:ar2ifVSmethc+N6wcnZR
  Network IP location

Signature (2cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
info This executable has a PDB path

Rules (11cnts)

Level Name Description Collection
danger Win32_Trojan_Gen_1_0904B0_Zero Win32 Trojan Emotet binaries (upload)
info IsDLL (no description) binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature Zero binaries (upload)
info HasDebugData DebugData Check binaries (upload)
info HasDigitalSignature DigitalSignature Check binaries (upload)
info HasOverlay Overlay Check binaries (upload)
info HasRichSignature Rich Signature Check binaries (upload)
info IsWindowsGUI (no description) binaries (upload)
info Win32_Trojan_Gen_2_0904B0_Zero Win32 Trojan Gen binaries (upload)
info win_files_operation Affect private profile binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure