Questo report è stato generato il {{now}}.
{{ if ge .Score .Threshold}}
Il file è stato contrassegnato come RANSOMWARE.
{{ end }}
{{ $thresholds := divide .Threshold 2}}
{{ if and (ge .Score $thresholds) (le .Score .Threshold) }}
Il file presenta caratteristiche molto simili ai malware. Prestare attenzione.
{{ end }}
Punteggio: {{.Score}}
In questa sezione si riassumono tutte le anomalie trovate all'interno del file compatibile con il comportamento di un ransowmare.
| Parameter |
Value |
| Type |
{{ .ELFInterface.Header.Type }} |
| Machine |
{{ .ELFInterface.Header.Machine }} {{.ELFInterface.Header.Machine | ELFprintMachine }} |
| Version |
{{ .ELFInterface.Header.Version }} |
| Entry |
{{ .ELFInterface.Header.Entry }} |
| ProgramHeaderFileOffset |
{{ .ELFInterface.Header.ProgramHeaderFileOffset }} |
| SectionHeaderFileOffset |
{{ .ELFInterface.Header.SectionHeaderFileOffset }} |
| Flags |
{{ .ELFInterface.Header.Flags }} |
| HeaderSize |
{{ .ELFInterface.Header.HeaderSize }} |
| ProgramEntrySize |
{{ .ELFInterface.Header.ProgramEntrySize }} |
| ProgramEntryNumbers |
{{ .ELFInterface.Header.ProgramEntryNumbers }} |
| SectionEntryNumbers |
{{ .ELFInterface.Header.SectionEntryNumbers }} |
| SectionEntrySize |
{{ .ELFInterface.Header.SectionEntrySize }} |
| StringSectionsName |
{{ .ELFInterface.Header.StringSectionsName }} |
| Name |
Value |
| MajorLinkerVersion |
{{.PEInterface.OptionalHeader.MajorLinkerVersion}} |
| MinorLinkerVersion |
{{.PEInterface.OptionalHeader.MinorLinkerVersion}} |
| SizeOfCode |
{{.PEInterface.OptionalHeader.SizeOfCode}} |
| SizeOfInitializedData |
{{.PEInterface.OptionalHeader.SizeOfInitializedData}} |
| SizeOfUninitializedData |
{{.PEInterface.OptionalHeader.SizeOfUninitializedData}} |
| AddressOfEntryPoint |
{{.PEInterface.OptionalHeader.AddressOfEntryPoint}} |
| BaseOfCode |
{{.PEInterface.OptionalHeader.BaseOfCode}} |
{{ if not .PEInterface.Is64bit }}
| BaseOfData |
{{.PEInterface.OptionalHeader.BaseOfCode}} |
{{ end }}
| ImageBase |
{{.PEInterface.OptionalHeader.ImageBase}} |
| SectionAlignment |
{{.PEInterface.OptionalHeader.SectionAlignment}} |
| FileAlignment |
{{.PEInterface.OptionalHeader.FileAlignment}} |
| MajorOperatingSystemVersion |
{{.PEInterface.OptionalHeader.MajorOperatingSystemVersion | PEprintMajorOperatingVersion }} |
| MinorOperatingSystemVersion |
{{.PEInterface.OptionalHeader.MinorOperatingSystemVersion}} |
| MajorImageVersion |
{{.PEInterface.OptionalHeader.MajorImageVersion}} |
| MinorImageVersion |
{{.PEInterface.OptionalHeader.MinorImageVersion}} |
| MajorSubsystemVersion |
{{.PEInterface.OptionalHeader.MajorSubsystemVersion}} |
| MinorSubsystemVersion |
{{.PEInterface.OptionalHeader.MajorSubsystemVersion}} |
| Win32VersionValue |
{{.PEInterface.OptionalHeader.Win32VersionValue}} |
| SizeOfImage |
{{.PEInterface.OptionalHeader.SizeOfImage}} |
| SizeOfHeaders |
{{.PEInterface.OptionalHeader.SizeOfHeaders}} |
| Checksum |
{{.PEInterface.OptionalHeader.Checksum}} |
| Subsystem |
{{ .PEInterface.OptionalHeader.Subsystem }} {{.PEInterface.OptionalHeader.Subsystem | PEprintSubsystem}} |
| DllCharacteristics |
{{.PEInterface.OptionalHeader.DllCharacteristics}} |
| SizeOfStackReserve |
{{.PEInterface.OptionalHeader.SizeOfStackReserve}} |
| SizeOfStackCommit |
{{.PEInterface.OptionalHeader.SizeOfStackCommit}} |
| SizeOfHeapReserve |
{{.PEInterface.OptionalHeader.SizeOfHeapReserve}} |
| SizeOfHeapCommit |
{{.PEInterface.OptionalHeader.SizeOfHeapCommit}} |
| LoaderFlags |
{{.PEInterface.OptionalHeader.LoaderFlags}} |
| NumberOfRvaAndSize |
{{.PEInterface.OptionalHeader.NumberOfRvaAndSizes}} |
{{ end }}
{{ end }}
{{ if .PEInterface.RichHeader }}