Report - ex0sjt.zip

Gen
ScreenShot
Created 2021.03.25 09:19 Machine s1_win7_x6402
Filename ex0sjt.zip
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
AI Score
1
Behavior Score
1.8
ZERO API file : malware
VT API (file) 6 detected (Unsafe, Save, Artemis, Malicious, Wacapew, score)
md5 874fd61c191375f72af292f4fcdbd500
sha256 bc3554e9f0ddb67f6ddb0314bc60d5d66f9e18ed732a5dfa29e731642255ed54
ssdeep 12288:QJ1u+Uyy8L/SVTjxVAhaYY/wKgZK5PQ/PDz/5lO2MskpNLpIObibzS1pZUf/9xEF:Q2+I8Oh1/+IQ/n/+2alIObNPUn9g
imphash 668dd875fa4db6299173db9f11296ee7
impfuzzy 24:4OEvdl9a1POovn8fcxOCqRkaDoJdNOwuRv5FQHOT4zXryx2G0sjMS7:XOdl9a1mVfcx5N/2NczOlP
  Network IP location

Signature (5cnts)

Level Description
watch Communicates with host for which no DNS query was performed
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 6 AntiVirus engines on VirusTotal as malicious
info One or more processes crashed
info This executable has a PDB path

Rules (9cnts)

Level Name Description Collection
danger Win32_Trojan_Gen_1_0904B0_Zero Win32 Trojan Emotet binaries (upload)
info IsDLL (no description) binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature Zero binaries (upload)
info HasDebugData DebugData Check binaries (upload)
info HasRichSignature Rich Signature Check binaries (upload)
info IsWindowsGUI (no description) binaries (upload)
info Win32_Trojan_Gen_2_0904B0_Zero Win32 Trojan Gen binaries (upload)
info win_files_operation Affect private profile binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure