Task Information
Task ID: a661dac4-4249-11f1-badc-42010aa4000b
File name: 0a9638148dc88ebe97cd69b1816ccfcf
Task parameters: ClamAV scan: True
Unpack: False
Share file: True
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
No matches
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
Rule name: CP_Script_Inject_Detector
Alert
Author: DiegoAnalytics
Description: Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP: TLP:WHITE
Repository: YARAify
Rule name: DebuggerCheck__API
Alert
Reference: https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP: TLP:WHITE
Rule name: DebuggerCheck__RemoteAPI
Alert
Reference: https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP: TLP:WHITE
Rule name: DebuggerHiding__Thread
Alert
Reference: https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP: TLP:WHITE
Rule name: Destructive_Ransomware_Gen1
Alert
Author: Florian Roth (Nextron Systems)
Description: Detects destructive malware
Reference: http://blog.talosintelligence.com/2018/02/olympic-destroyer.html
TLP: TLP:WHITE
Repository: Neo23x0
Rule name: Destructive_Ransomware_Gen1_RID31CB
Alert
Author: Florian Roth
Description: Detects destructive malware
Reference: http://blog.talosintelligence.com/2018/02/olympic-destroyer.html
TLP: TLP:WHITE
Rule name: DetectEncryptedVariants
Alert
Author: Zinyth
Description: Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
TLP: TLP:WHITE
Repository: YARAify
Rule name: Disable_Defender
Alert
Author: iam-py-test
Description: Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
TLP: TLP:WHITE
Repository: MalwareBazaar
Rule name: Sus_CMD_Powershell_Usage
Alert
Author: XiAnzheng
Description: May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
TLP: TLP:WHITE
Repository: YARAify
Rule name: SUSP_VBS_Wscript_Shell
Alert
Author: SECUINFRA Falcon Team
Description: Detects the definition of 'Wscript.Shell' which is often used by Malware, FPs are possible and commmon
TLP: TLP:WHITE
Repository: SIFalcon
Rule name: VECT_Ransomware
Alert
Author: Mustafa Bakhit
Description: Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
TLP: TLP:WHITE
Repository: YARAify
Rule name: classified
Author: classified
Description: classified
TLP : TLP:AMBER
Rule name: classified
Author: classified
Description: classified
TLP : TLP:AMBER
Rule name: classified
Author: classified
Description: classified
TLP : TLP:AMBER
Unpacker
The following YARA rules matched on the unpacked file.
Disabled by submitter
Unpacked Files
The following files could be unpacked from this sample.
Disabled by submitter