redhat-developer / redhat-developer/vscode-xml

lemminx-win32.exe > sandbox Yomi Hunter flags this file as: MALWARE

Open
#983 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
328
Forks
101
Avg merge
1d 17h
Merged PRs (30d)
7

Description

https://www.virustotal.com/gui/file/ddb40e0762f4805d660523ebfadd3ce1d906bfa0f0c2a18db58fd6d4b30d3498/detection

Names
lemminx-win32.exe
sha256 ddb40e0762f4805d660523ebfadd3ce1d906bfa0f0c2a18db58fd6d4b30d3498

Signature info
Signature Verification
File is not signed

Dynamic Analysis Sandbox Detections
The sandbox Yomi Hunter flags this file as: MALWARE

History
Creation Time
2023-07-12 16:36:26 UTC
First Seen In The Wild
2023-07-12 11:46:49 UTC
First Submission
2023-07-13 12:04:00 UTC
Last Submission
2024-01-10 05:13:38 UTC
Last Analysis
2024-03-27 15:01:15 UTC

Matches rule Change PowerShell Policies to an Insecure Level by frack113 at Sigma Integrated Rule Set (GitHub)
Detects use of executionpolicy option to set insecure policies

Matches rule Change PowerShell Policies to an Insecure Level - PowerShell by frack113 at Sigma Integrated Rule Set (GitHub)
Detects use of Set-ExecutionPolicy to set insecure policies

Matches rule Suspicious Get-WmiObject by frack113 at Sigma Integrated Rule Set (GitHub)
The infrastructure for management data and operations that enables local and remote management of Windows personal computers and servers

Matches rule Creation of an Executable by an Executable by frack113 at Sigma Integrated Rule Set (GitHub)
Detects the creation of an executable by another executable

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the linked VirusTotal report for lemminx-win32.exe and verify the SHA-256 ddb40e0762f4805d660523ebfadd3ce1d906bfa0f0c2a18db58fd6d4b30d3498. Review the listed Yomi Hunter and Sigma detections; the issue is complete only when the malware finding is investigated and a clear resolution is documented.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.