ScreenShot
Created | 2021.03.19 14:54 | Machine | s1_win7_x6402 |
Filename | 44272.8138383102.dat | ||
Type | PE32+ executable (DLL) (GUI) x86-64, for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : malware | ||
VT API (file) | 35 detected (Razy, Unsafe, TurtleLoader, malicious, confidence, score, Ligooc, Kryptik, CLOUD, DownLoader37, Artemis, kcloud, IcedID, ai score=80, R002H09CI21, HggASRAA) | ||
md5 | a1c342d9ea0214e9e7b881a3b136f133 | ||
sha256 | 5eacd6657ad91ddbf8a3da91e44cf0c7bf828cda31e26949f4b7d9aa808f9275 | ||
ssdeep | 1536:PbpxmzQrkmZdtYJPZY0DERcagb0MfjEM9ly/0EdHtD:dxmzQrkmZdtYJPZY0DERk0cja0EdHt | ||
imphash | df5504c1c67b4885da4f7997a05bf0c0 | ||
impfuzzy | 3:PNXuwdX0JSHXX0AbXw9XbXxl:FXuoBUAzijxl |
Network IP location
Signature (1cnts)
Level | Description |
---|---|
danger | File has been identified by 35 AntiVirus engines on VirusTotal as malicious |
Rules (6cnts)
Level | Name | Description | Collection |
---|---|---|---|
info | IsDLL | (no description) | binaries (upload) |
info | IsPE64 | (no description) | binaries (upload) |
info | PE_Header_Zero | PE File Signature Zero | binaries (upload) |
info | HasDebugData | DebugData Check | binaries (upload) |
info | HasRichSignature | Rich Signature Check | binaries (upload) |
info | IsWindowsGUI | (no description) | binaries (upload) |
Network (0cnts) ?
Request | CC | ASN Co | IP4 | Rule ? | ZERO ? |
---|