Report - i3YFqH6uMO3o8pg2Cbx.zip

ScreenShot
Created 2023.03.09 17:12 Machine s1_win7_x6402
Filename i3YFqH6uMO3o8pg2Cbx.zip
Type Zip archive data, at least v2.0 to extract
AI Score Not founds Behavior Score
3.4
ZERO API file : malware
VT API (file) 6 detected (Archive, Bomb, Heavy, Artemis, ai score=83, suspected of Archive, MailBomb, SwollenFile, CLASSIC)
md5 5a72267343811d8fe7d72c1f96bac927
sha256 17a85317e36cca87611e4e956679cfcfc4777735bc9f23652a5c14582bfd5968
ssdeep 12288:k4DKwKHCjAbD7j9kd1j89Gpm19Fkf7/sw:zevtlkdJe4m19FgD
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
danger Connects to IP addresses that are no longer responding to requests (legitimate services will remain up-and-running usually)
warning Generates some ICMP traffic
watch Communicates with host for which no DNS query was performed
notice File has been identified by 6 AntiVirus engines on VirusTotal as malicious

Rules (0cnts)

Level Name Description Collection

Network (3cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
91.207.28.33 KG Optima Telecom Ltd. 91.207.28.33 mailcious
104.168.155.143 US HOSTWINDS 104.168.155.143 mailcious
91.121.146.47 FR OVH SAS 91.121.146.47 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure