Report - test2.ps1

Generic Malware Antivirus
ScreenShot
Created 2025.05.02 09:10 Machine s1_win7_x6401
Filename test2.ps1
Type ASCII text, with very long lines
AI Score Not founds Behavior Score
1.4
ZERO API
VT API (file) 11 detected (powershell, boxter, gen5, Encpe)
md5 8d04a648ac227610708aa5c9230a87b2
sha256 c6c9b307d5bd37a904e3b70009499ac4c5f85658c7f8e9efd1f0af0c15828fac
ssdeep 3072:RkcXHA0yuGH8FrCbSPhcD8IEE6ufS09/ubnferIP:RNacFrPW8IEDuf7/u7eS
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
watch File has been identified by 11 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
info Command line console output was observed
info Uses Windows APIs to generate a cryptographic key

Rules (2cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (download)
watch Antivirus Contains references to security software binaries (download)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure