Task Information
Task ID: a4275bc8-abf6-11f1-b69f-42010aa4000b
File name: 5f50000.exe
Task parameters: ClamAV scan: True
Unpack: False
Share file: True
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
No matches
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
Rule name: aix
Alert
Author: Tim Brown @timb_machine
Description: AIX binary
TLP: TLP:WHITE
Repository: MalwareBazaar
Rule name: classified
Author: classified
Description: classified
TLP : TLP:AMBER
Rule name: backdoor_mul_sparkrat
Alert
Author: Sekoia.io
Description: Detect SparkRAT using string found in the source code
Reference: https://github.com/XZB-1248/Spark
TLP: TLP:WHITE
Repository:
Rule name: command_and_control
Alert
Author: CD_R0M_
Description: This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
TLP: TLP:WHITE
Repository: CD-R0M
Rule name: CP_Script_Inject_Detector
Alert
Author: DiegoAnalytics
Description: Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
TLP: TLP:WHITE
Repository: YARAify
Rule name: DebuggerCheck__QueryInfo
Alert
Reference: https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP: TLP:WHITE
Rule name: Detect_Go_GOMAXPROCS
Alert
Author: Obscurity Labs LLC
Description: Detects Go binaries by the presence of runtime.GOMAXPROCS in the runtime metadata
TLP: TLP:WHITE
Repository: YARAify
Rule name: classified
Author: classified
Description: classified
Rule name: DetectEncryptedVariants
Alert
Author: Zinyth
Description: Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
TLP: TLP:WHITE
Repository: YARAify
Rule name: DetectGoMethodSignatures
Alert
Author: Wyatt Tauber
Description: Detects Go method signatures in unpacked Go binaries
TLP: TLP:WHITE
Repository: YARAify
Rule name: FreddyBearDropper
Alert
Author: Dwarozh Hoshiar
Description: Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
TLP: TLP:WHITE
Repository: YARAify
Rule name: classified
Author: classified
Description: classified
Reference: classified
TLP : TLP:AMBER
Rule name: ldpreload
Alert
Author: xorseed
Reference: https://stuff.rop.io/
TLP: TLP:WHITE
Repository:
Rule name: MD5_Constants
Alert
Author: phoul (@phoul)
Description: Look for MD5 constants
TLP: TLP:WHITE
Repository:
Rule name: ProgramLanguage_Golang
Alert
Author: albertzsigovits
Description: Application written in Golang programming language
TLP: TLP:WHITE
Repository:
Rule name: reverse_http
Alert
Author: CD_R0M_
Description: Identify strings with http reversed (ptth)
TLP: TLP:WHITE
Repository: CD-R0M
Rule name: RIPEMD160_Constants
Alert
Author: phoul (@phoul)
Description: Look for RIPEMD-160 constants
TLP: TLP:WHITE
Repository:
Rule name: SEH__vectored
Alert
Reference: https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP: TLP:WHITE
Rule name: SHA1_Constants
Alert
Author: phoul (@phoul)
Description: Look for SHA1 constants
TLP: TLP:WHITE
Repository:
Rule name: SHA512_Constants
Alert
Author: phoul (@phoul)
Description: Look for SHA384/SHA512 constants
TLP: TLP:WHITE
Repository:
Rule name: SparkRAT
Alert
Author: t-mtsmt
Description: SparkRAT Payload
TLP: TLP:WHITE
Repository: CAPE
Rule name: Sus_All_Windows_PE_Malware
Alert
Author: DiegoAnalytics
Description: Detects Windows PE malware of all types, avoids non-executables like .html
TLP: TLP:WHITE
Repository: YARAify
Rule name: Sus_CMD_Powershell_Usage
Alert
Author: XiAnzheng
Description: May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
TLP: TLP:WHITE
Repository: YARAify
Rule name: Suspicious_Golang_Binary
Alert
Author: Tim Machac
Description: Triage: Golang-compiled binary with suspicious OS/persistence/network strings (not family-specific)
TLP: TLP:WHITE
Repository: YARAify
Rule name: Suspicious_Process
Alert
Author: Security Research Team
Description: Suspicious process creation
TLP: TLP:WHITE
Repository: YARAify
Rule name: test_Malaysia
Alert
Author: rectifyq
Description: Detects file containing malaysia string
TLP: TLP:WHITE
Repository: YARAify
Rule name: ThreadControl__Context
Alert
Reference: https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP: TLP:WHITE
Rule name: unixredflags3
Alert
Author: Tim Brown @timb_machine
Description: Hunts for UNIX red flags
TLP: TLP:WHITE
Repository: MalwareBazaar
Unpacker
The following YARA rules matched on the unpacked file.
Disabled by submitter
Unpacked Files
The following files could be unpacked from this sample.
Disabled by submitter