Analysis Report https://alltype.zyrosite.com/
Overview
General Information
Sample URL: | https://alltype.zyrosite.com/ |
Analysis ID: | 401611 |
Infos: | |
Most interesting Screenshot: | |
Errors
|
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Sigma detected: Mustang Panda Dropper
Queries the volume information (name, serial number etc) of a device
Sigma detected: MsiExec Web Install
Sigma detected: Suspicious Copy From or To System32
Classification
|
Malware Configuration |
---|
No configs have been found |
---|
Yara Overview |
---|
No yara matches |
---|
Sigma Overview |
---|
System Summary: |
---|
Sigma detected: Mustang Panda Dropper |
Source: | Author: Florian Roth, oscd.community: |
Sigma detected: MsiExec Web Install |
Source: | Author: Florian Roth: |
Sigma detected: Suspicious Copy From or To System32 |
Source: | Author: Florian Roth, Markus Neis: |
Sigma detected: Data Compressed - Powershell |
Source: | Author: Timur Zinniatullin, oscd.community: |