ScreenShot
Created | 2023.03.09 17:12 | Machine | s1_win7_x6402 |
Filename | i3YFqH6uMO3o8pg2Cbx.zip | ||
Type | Zip archive data, at least v2.0 to extract | ||
AI Score | Not founds | Behavior Score |
|
ZERO API | file : malware | ||
VT API (file) | 6 detected (Archive, Bomb, Heavy, Artemis, ai score=83, suspected of Archive, MailBomb, SwollenFile, CLASSIC) | ||
md5 | 5a72267343811d8fe7d72c1f96bac927 | ||
sha256 | 17a85317e36cca87611e4e956679cfcfc4777735bc9f23652a5c14582bfd5968 | ||
ssdeep | 12288:k4DKwKHCjAbD7j9kd1j89Gpm19Fkf7/sw:zevtlkdJe4m19FgD | ||
imphash | |||
impfuzzy |
Network IP location
Signature (4cnts)
Level | Description |
---|---|
danger | Connects to IP addresses that are no longer responding to requests (legitimate services will remain up-and-running usually) |
warning | Generates some ICMP traffic |
watch | Communicates with host for which no DNS query was performed |
notice | File has been identified by 6 AntiVirus engines on VirusTotal as malicious |
Rules (0cnts)
Level | Name | Description | Collection |
---|
Suricata ids
ET CNC Feodo Tracker Reported CnC Server group 7
ET INFO TLS Handshake Failure
ET CNC Feodo Tracker Reported CnC Server group 5
ET CNC Feodo Tracker Reported CnC Server group 1
ET CNC Feodo Tracker Reported CnC Server group 8
ET INFO TLS Handshake Failure
ET CNC Feodo Tracker Reported CnC Server group 5
ET CNC Feodo Tracker Reported CnC Server group 1
ET CNC Feodo Tracker Reported CnC Server group 8