Task Information
Task ID: e82bdd18-4247-11f1-badc-42010aa4000b
File name: 0bff78b3fc6e6a2f20b2f2eb6d36acdd
Task parameters: ClamAV scan: True
Unpack: False
Share file: True
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
No matches
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
Rule name: classified
Author: classified
Description: classified
TLP : TLP:AMBER
Rule name: APT_Sandworm_ArguePatch_Apr_2022_1
Alert
Author: Arkbird_SOLG
Description: Detect ArguePatch loader used by Sandworm group for load CaddyWiper
Reference: https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/
TLP: TLP:WHITE
Rule name: AutoIT_Compiled
Alert
Author: @bartblaze
Description: Identifies compiled AutoIT script (as EXE). This rule by itself does NOT necessarily mean the detected file is malicious.
TLP: TLP:WHITE
Repository: bartblaze
Rule name: Bolonyokte
Alert
Author: Jean-Philippe Teissier / @Jipe_
Description: UnknownDotNet RAT - Bolonyokte
TLP: TLP:WHITE
Rule name: command_and_control
Alert
Author: CD_R0M_
Description: This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
TLP: TLP:WHITE
Repository: CD-R0M
Rule name: CP_Script_Inject_Detector
Alert
Author: DiegoAnalytics
Description: Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP: TLP:WHITE
Repository: YARAify
Rule name: DebuggerCheck__API
Alert
Reference: https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP: TLP:WHITE
Rule name: DebuggerCheck__QueryInfo
Alert
Reference: https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP: TLP:WHITE
Rule name: Detect_Go_GOMAXPROCS
Alert
Author: Obscurity Labs LLC
Description: Detects Go binaries by the presence of runtime.GOMAXPROCS in the runtime metadata
TLP: TLP:WHITE
Repository: YARAify
Rule name: classified
Author: classified
Description: classified
Rule name: Detect_PowerShell_Obfuscation
Alert
Author: daniyyell
Description: Detects obfuscated PowerShell commands commonly used in malicious scripts.
TLP: TLP:WHITE
Repository: YARAify
Rule name: DetectEncryptedVariants
Alert
Author: Zinyth
Description: Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
TLP: TLP:WHITE
Repository: YARAify
Rule name: DetectGoMethodSignatures
Alert
Author: Wyatt Tauber
Description: Detects Go method signatures in unpacked Go binaries
TLP: TLP:WHITE
Repository: YARAify
Rule name: FreddyBearDropper
Alert
Author: Dwarozh Hoshiar
Description: Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
TLP: TLP:WHITE
Repository: YARAify
Rule name: MD5_Constants
Alert
Author: phoul (@phoul)
Description: Look for MD5 constants
TLP: TLP:WHITE
Repository:
Rule name: ProgramLanguage_Golang
Alert
Author: albertzsigovits
Description: Application written in Golang programming language
TLP: TLP:WHITE
Repository:
Rule name: RIPEMD160_Constants
Alert
Author: phoul (@phoul)
Description: Look for RIPEMD-160 constants
TLP: TLP:WHITE
Repository:
Rule name: SEH__vectored
Alert
Reference: https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP: TLP:WHITE
Rule name: SHA1_Constants
Alert
Author: phoul (@phoul)
Description: Look for SHA1 constants
TLP: TLP:WHITE
Repository:
Rule name: SHA512_Constants
Alert
Author: phoul (@phoul)
Description: Look for SHA384/SHA512 constants
TLP: TLP:WHITE
Repository:
Rule name: skip20_sqllang_hook
Alert
Author: Mathieu Tartare <mathieu.tartare@eset.com>
Description: YARA rule to detect if a sqllang.dll version is targeted by skip-2.0. Each byte pattern corresponds to a function hooked by skip-2.0. If $1_0 or $1_1 match, it is probably targeted as it corresponds to the hook responsible for bypassing the authentication.
Reference: https://www.welivesecurity.com/
TLP: TLP:WHITE
Repository:
Rule name: Sus_CMD_Powershell_Usage
Alert
Author: XiAnzheng
Description: May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
TLP: TLP:WHITE
Repository: YARAify
Rule name: Suspicious_Golang_Binary
Alert
Author: Tim Machac
Description: Triage: Golang-compiled binary with suspicious OS/persistence/network strings (not family-specific)
TLP: TLP:WHITE
Repository: YARAify
Rule name: ThreadControl__Context
Alert
Reference: https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP: TLP:WHITE
Rule name: classified
Author: classified
Description: classified
TLP : TLP:AMBER
Unpacker
The following YARA rules matched on the unpacked file.
Disabled by submitter
Unpacked Files
The following files could be unpacked from this sample.
Disabled by submitter