Task Information
Task ID: abd805df-1033-11f0-b4a6-42010aa4000b
File name: 35bc3ee1f0b003e47c26fc75c566b014
Task parameters: ClamAV scan: True
Unpack: False
Share file: True
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
Rule name: CHM_File_Executes_JS_Via_PowerShell
Alert
Author: daniyyell
Description: Detects a Microsoft Compiled HTML Help (CHM) file that executes embedded JavaScript to launch a messagebox via PowerShell
TLP: TLP:WHITE
Repository: YARAify
Rule name: detect_powershell
Alert
Author: daniyyell
Description: Detects suspicious PowerShell activity related to malware execution
TLP: TLP:WHITE
Repository: YARAify
Rule name: Detect_PowerShell_Obfuscation
Alert
Author: daniyyell
Description: Detects obfuscated PowerShell commands commonly used in malicious scripts.
TLP: TLP:WHITE
Repository: YARAify
Rule name: Detect_Remcos_RAT
Alert
Author: daniyyell
Description: Detects Remcos RAT payloads and commands
TLP: TLP:WHITE
Repository: YARAify
Rule name: Jupyter_infostealer
Alert
Author: CD_R0M_
Description: Rule for Jupyter Infostealer/Solarmarker malware from september 2021-December 2022
TLP: TLP:WHITE
Repository: CD-R0M
Rule name: NET
Alert
Author: malware-lu
TLP: TLP:WHITE
Repository:
Rule name: Njrat
Alert
Author: botherder https://github.com/botherder
Description: Njrat
TLP: TLP:WHITE
Repository:
Rule name: RIPEMD160_Constants
Alert
Author: phoul (@phoul)
Description: Look for RIPEMD-160 constants
TLP: TLP:WHITE
Repository:
Rule name: SHA1_Constants
Alert
Author: phoul (@phoul)
Description: Look for SHA1 constants
TLP: TLP:WHITE
Repository:
Rule name: Sus_Obf_Enc_Spoof_Hide_PE
Alert
Author: XiAnzheng
Description: Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
TLP: TLP:WHITE
Repository: YARAify
Rule name: classified
Author: classified
Description: classified
TLP : TLP:AMBER
Unpacker
The following YARA rules matched on the unpacked file.
Disabled by submitter
Unpacked Files
The following files could be unpacked from this sample.
Disabled by submitter