ScreenShot
Created | 2021.03.16 12:12 | Machine | s1_win7_x6401 |
Filename | mon75_cr.dll | ||
Type | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | |||
VT API (file) | 47 detected (malicious, high confidence, Razy, Trickbotcrypt, confidence, 100%, NSSC, Attribute, HighConfidence, Trickpak, inlsgv, BankerX, Sudt, VSNTBO21, FTJO, TrickBot, Static AI, Malicious PE, Kryptik, HJQZ, jualt, ai score=85, score, Unsafe, 1239c4crYYR, Krypt, susgen, HJLB, ZedlaF, vq4@aiNcEEg, GdSda, Hx4CgxsA) | ||
md5 | 5091a400a52fa02348af0d2077d2be51 | ||
sha256 | 051859a76d64d4bdeec4bb43cad7d6301f83a62b5b716393af5f3d7b80440b41 | ||
ssdeep | 6144:2LAMibxy5iv9BD/zFxznh3DmzrBuno6bpnUFd5gUHq:qAfbxbvDjNTmzrBunofFds | ||
imphash | 61a0ecfcf6fd30fcdee45e90e04a32c9 | ||
impfuzzy | 24:aLjSjthhlJnc+pl3eDoTYoSXaOovbOPZsvwjMM:aLjSjth5c+pp/YT3ck |
Network IP location
Signature (2cnts)
Level | Description |
---|---|
danger | File has been identified by 47 AntiVirus engines on VirusTotal as malicious |
notice | The binary likely contains encrypted or compressed data indicative of a packer |
Rules (10cnts)
Level | Name | Description | Collection |
---|---|---|---|
danger | Win_Trojan_Trickbot_Zero | Used Trickbot | binaries (upload) |
info | IsDLL | (no description) | binaries (upload) |
info | IsPE32 | (no description) | binaries (upload) |
info | OS_Processor_Check_Zero | OS Processor Check Signature Zero | binaries (upload) |
info | PE_Header_Zero | PE File Signature Zero | binaries (upload) |
info | HasDebugData | DebugData Check | binaries (upload) |
info | HasRichSignature | Rich Signature Check | binaries (upload) |
info | IsPacked | Entropy Check | binaries (upload) |
info | IsWindowsGUI | (no description) | binaries (upload) |
info | win_files_operation | Affect private profile | binaries (upload) |
Network (0cnts) ?
Request | CC | ASN Co | IP4 | Rule ? | ZERO ? |
---|