File 3ee2c574fc5d80b281a2592017fc7f56c19819da68aa7b90da748caed91855cd Summary

Analyse score

2 / 14

2 antivirus venders flagged
this file as malicious

Last scanned

First submission

Basic properties

CRC32

0xc83f9b8d

MD5

dbaa68ff4f10ef0a03e2580553342182

Magic

HTML document, ASCII text, with very long lines, with no line terminators

SHA1

0c1e0d48931c50a36329ed6bb70fd8a7c9a76ab4

SHA256

3ee2c574fc5d80b281a2592017fc7f56c19819da68aa7b90da748caed91855cd

SHA512

d8bf290edab5cffd586e747e981c54bac448512bd7c4dfd93896f9cea8f8810c4c9282110fd7ad2ce486a855eb0950ede29fa32bd7aff67e3538784f69b239c4

SSDeep

768:kCatpv+gLv7smL/UKDMt5pM9wyShVYwihYUBdsVWs3YjLKxMivV9:kVtRLv7smpbYWGX

Size

196.61KB

Packer
  • Text: format: plain text
TrID
  • Warning: file seems to be plain text/ASCII
  • TrID is best suited to analyze binary files!
  • Unknown!
Tags

ExifTool File Metadata

ExifToolVersionNumber

12.62

FileSize

201 kB

FileType

TXT

FileTypeExtension

txt

LineCount

1

MimeEncoding

us-ascii

MimeType

text/plain

Newlines

(none)

WordCount

2

Submissions

Published Name Source Country
ATT0821.htm web GB

Indicators

Description Severity Category Module
Malware detection of a yara signature: Win32/WannaCry
malicious
Sandbox Detection Behavior
Communicates over HTTP with a low reputation domain
informational
C2 Behavior
Deletes itself after process termination
suspicious
Stealth Behavior
Write a file to the startup folder
suspicious
Persistence Behavior
Check for the existence of Virtual Machines
suspicious
Signature Yara

🚀 Coming soon!

Virtual Screens

🚀 Coming soon!