Skip to content

VirusTotal 4/71 security vendors flagged this file as malicious #3

Description

@essento11

This Widget doesn't seem safe at all ! by VirusTotal

https://www.virustotal.com/gui/file/f4db1bdfd357ec38845cfe465099650b9ac82de87eddd40b2e2feb2462653bf5

Matches rule SUSP_Imphash_Mar23_3 from ruleset gen_imphash_detection at https://github.com/Neo23x0/signature-base by Arnim Rupp (https://github.com/ruppde)
Detects imphash often found in malware samples (Maximum 0,25% hits with search for 'imphash:x p:0' on Virustotal) = 99,75% hits - 2 months ago
Matches rule SUSP_Imphash_Mar23_3 from ruleset gen_imphash_detection at https://github.com/Neo23x0/signature-base by Arnim Rupp (https://github.com/ruppde)
Detects imphash often found in malware samples (Maximum 0,25% hits with search for 'imphash:x p:0' on Virustotal) = 99,75% hits
Matches rule PyInstaller from ruleset PyInstaller at https://github.com/bartblaze/Yara-rules by @bartblaze
Identifies executable converted using PyInstaller. This rule by itself does NOT necessarily mean the detected file is malicious. - 6 days ago
Matches rule PyInstaller from ruleset PyInstaller at https://github.com/bartblaze/Yara-rules by @bartblaze
Identifies executable converted using PyInstaller. This rule by itself does NOT necessarily mean the detected file is malicious.


Matches are settled Change PowerShell policies to an unsafe level. by frack113 at Sigma Integrated Ruleset (GitHub) Detects PowerShell script execution policy modification to a potentially unsafe level using the "-ExecutionPolicy" flag.
Matches are settled Suspicious DNS Query for IP Lookup Service APIs by Brandon George (blog post), Thomas Patzke at Sigma Integrated Rule Set (GitHub) Detects DNS queries for IP lookup services such as "api.ipify.org" coming from a process other than a browser.
Matches are settled Loading Python images by non-Python process by Patrick St. John, OTR (Open Threat Research) at Sigma Integrated Rule Set (GitHub) Detects loading of the "Python Core" image by a non-Python process. This may indicate the presence of a Python script included in Py2Exe.
Matches are settled Suspicious network connection to IP Lookup Service APIs by Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems) at Sigma Integrated Rule Set (GitHub) Detects external IP address lookups performed by non-browser processes via services such as "api.ipify.org". This could be indicative of potential Internet testing activity following a system compromise.


Matches rule ET POLICY External IP Lookup ip-api.com at Proofpoint Emerging Threats Open
Device Retrieving External IP Address Detected
Unique rule identifier:
This rule belongs to a private collection.

The sandbox Yomi Hunter flags this file as: MALWARE


Security vendors' analysis

Arctic Wolf Unsafe
McAfee Scanner Ti!F4DB1BDFD357
Palo Alto Networks Generic.ml
SecureAge Malicious
​

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions