Report - 44270.7073414352.dat

ScreenShot
Created 2021.03.16 12:12 Machine s1_win7_x3201
Filename 44270.7073414352.dat
Type PE32+ executable (DLL) (GUI) x86-64, for MS Windows
AI Score
5
Behavior Score
0.6
ZERO API
VT API (file) 11 detected (Artemis, Kryptik, MalwareX, IcedID, IWZZKK, Outbreak, BazarBackdoor, HggASQ0A)
md5 997340ab32077836c7a055f52ab148de
sha256 f175d5883a0958f8ce10c387fef6c6750d26089e7413bf7b9a3767b655e61417
ssdeep 768:1nNm1j0LxiiU0SLtaK5aaSqts0uVUVi42mWhlzS8q8zOhD1:1nN6wAi6ayBFnoUV/3Az9cD
imphash 2c242ad4a4ada5a092b4cd4c64888b0d
impfuzzy 3:PNXuwSHXXLCbAJSHXX0AbXxcHAw9XbXJkDhXRWD3zM/MDn:FXuxebVUAzxcHAijOBwDD7D
  Network IP location

Signature (1cnts)

Level Description
watch File has been identified by 11 AntiVirus engines on VirusTotal as malicious

Rules (6cnts)

Level Name Description Collection
info IsDLL (no description) binaries (upload)
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature Zero binaries (upload)
info HasDebugData DebugData Check binaries (upload)
info HasRichSignature Rich Signature Check binaries (upload)
info IsWindowsGUI (no description) binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure