Task Information
Task ID: 1b3b6c6d-57ef-11f0-a223-42010aa4000b
File name: 4d00000.dll
Task parameters: ClamAV scan: True
Unpack: False
Share file: True
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
Rule name: DebuggerCheck__API
Alert
Reference: https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP: TLP:WHITE
Rule name: FreddyBearDropper
Alert
Author: Dwarozh Hoshiar
Description: Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
TLP: TLP:WHITE
Repository: YARAify
Rule name: Indicator_MiniDumpWriteDump
Alert
Author: Obscurity Labs LLC
Description: Detects PE files and PowerShell scripts that use MiniDumpWriteDump either through direct imports or string references
TLP: TLP:WHITE
Rule name: NET
Alert
Author: malware-lu
TLP: TLP:WHITE
Repository:
Rule name: SEH__vectored
Alert
Reference: https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP: TLP:WHITE
Rule name: Sus_CMD_Powershell_Usage
Alert
Author: XiAnzheng
Description: May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
TLP: TLP:WHITE
Repository: YARAify
Rule name: Sus_Obf_Enc_Spoof_Hide_PE
Alert
Author: XiAnzheng
Description: Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
TLP: TLP:WHITE
Repository: YARAify
Rule name: vmdetect
Alert
Author: nex
Description: Possibly employs anti-virtualization techniques
TLP: TLP:WHITE
Repository:
Rule name: win_simda_auto
Alert
Author: Felix Bilstein - yara-signator at cocacoding dot com
Description: Detects win.simda.
TLP: TLP:WHITE
Repository: Malpedia
Rule name: classified
Author: classified
Description: classified
TLP : TLP:GREEN
Rule name: classified
Author: classified
Description: classified
TLP : TLP:GREEN
Rule name: Windows_Trojan_Zeus_e51c60d7
Alert
Author: Elastic Security
Description: Detects strings used in Zeus web injects. Many other malware families are built on Zeus and may hit on this signature.
Reference: https://www.virusbulletin.com/virusbulletin/2014/10/paper-evolution-webinjects
TLP: TLP:WHITE
Repository: elastic
Unpacker
The following YARA rules matched on the unpacked file.
Disabled by submitter
Unpacked Files
The following files could be unpacked from this sample.
Disabled by submitter