Summary | ZeroBOX

wL8P9unF.zip

ZIP Format
Category Machine Started Completed
FILE s1_win7_x6402 March 22, 2023, 10:41 a.m. March 22, 2023, 10:44 a.m.
Size 944.9KB
Type Zip archive data, at least v2.0 to extract
MD5 1f5166dbb451fe00af869e50377e286d
SHA256 4e34d62f76eeca9106cabde22921b69e9bbd1ea0364b49ca141855ed2ca5b773
CRC32 3587C5D5
ssdeep 12288:tkf5dOzheNdckFRKluvnRHXdhbDHfXZX1EKdxKmSTH4ded:mXzNdfKluvnRHthzfoYxJlC
Yara
  • zip_file_format - ZIP file format

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
104.168.155.143 Active Moloch
107.170.39.149 Active Moloch
115.68.227.76 Active Moloch
164.124.101.2 Active Moloch
164.90.222.65 Active Moloch
167.172.199.165 Active Moloch
172.105.226.75 Active Moloch
187.63.160.88 Active Moloch
202.129.205.3 Active Moloch
209.126.85.32 Active Moloch
213.239.212.5 Active Moloch
5.135.159.50 Active Moloch
94.23.45.86 Active Moloch

Baidu Archive.Bomb
Kaspersky UDS:Trojan-Banker.Win64.Emotet
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Rising Malware.SwollenFile!1.DDB4 (CLASSIC)
host 104.168.155.143
host 107.170.39.149
host 115.68.227.76
host 164.90.222.65
host 167.172.199.165
host 172.105.226.75
host 187.63.160.88
host 202.129.205.3
host 209.126.85.32
host 213.239.212.5
host 5.135.159.50
host 94.23.45.86
dead_host 202.129.205.3:8080
dead_host 164.90.222.65:443
dead_host 115.68.227.76:8080
dead_host 107.170.39.149:8080
dead_host 5.135.159.50:443
dead_host 104.168.155.143:8080
dead_host 167.172.199.165:8080
dead_host 192.168.56.102:49194
dead_host 192.168.56.102:49195
dead_host 192.168.56.102:49192