Task Information
Task ID: 6369e125-3b58-11f0-9b97-42010aa4000b
File name: 400000.USBSafelyRemove.exe
Task parameters: ClamAV scan: True
Unpack: False
Share file: True
ClamAV Results
The file matched the following open source and commercial ClamAV rules.
No matches
YARA Results
Static Analysis
The following YARA rules matched on the file (static analysis).
Rule name: APT_DustSquad_PE_Nov19_1
Alert
Author: Arkbird_SOLG
Description: Detection Rule for APT DustSquad campaign Nov19
Reference: https://twitter.com/Rmy_Reserve/status/1197448735422238721
TLP: TLP:WHITE
Repository: StrangerealIntel
Rule name: BLOWFISH_Constants
Alert
Author: phoul (@phoul)
Description: Look for Blowfish constants
TLP: TLP:WHITE
Repository:
Rule name: Borland
Alert
Author: malware-lu
TLP: TLP:WHITE
Repository:
Rule name: DebuggerCheck__API
Alert
Reference: https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP: TLP:WHITE
Rule name: DebuggerCheck__QueryInfo
Alert
Reference: https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
TLP: TLP:WHITE
Rule name: classified
Author: classified
Description: classified
Reference: classified
TLP : TLP:AMBER
Rule name: MD5_Constants
Alert
Author: phoul (@phoul)
Description: Look for MD5 constants
TLP: TLP:WHITE
Repository:
Rule name: NET
Alert
Author: malware-lu
TLP: TLP:WHITE
Repository:
Rule name: RIPEMD160_Constants
Alert
Author: phoul (@phoul)
Description: Look for RIPEMD-160 constants
TLP: TLP:WHITE
Repository:
Rule name: SHA1_Constants
Alert
Author: phoul (@phoul)
Description: Look for SHA1 constants
TLP: TLP:WHITE
Repository:
Rule name: shellcode
Alert
Author: nex
Description: Matched shellcode byte patterns
TLP: TLP:WHITE
Repository: MalwareBazaar
Rule name: win_numando_auto
Alert
Author: Felix Bilstein - yara-signator at cocacoding dot com
Description: autogenerated rule brought to you by yara-signator
TLP: TLP:WHITE
Repository: Malpedia
Rule name: classified
Author: classified
Description: classified
TLP : TLP:AMBER
Unpacker
The following YARA rules matched on the unpacked file.
Disabled by submitter
Unpacked Files
The following files could be unpacked from this sample.
Disabled by submitter