ScreenShot
Created | 2023.03.09 18:14 | Machine | s1_win7_x6402 |
Filename | P49A1RKQbr6n5L2G.zip | ||
Type | Zip archive data, at least v2.0 to extract | ||
AI Score | Not founds | Behavior Score |
|
ZERO API | file : clean | ||
VT API (file) | 7 detected (GenKryptik, GHDZ, Emotet, cmtd, Archive, Bomb, ai score=82, suspected of Archive, MailBomb, SwollenFile, CLASSIC) | ||
md5 | 5ed137665b139baccce1abee74282b81 | ||
sha256 | 45efd63ea476b6cb9c7fa9a8f1428475f4dfb5516b77dc4f8d1d6a4af70af553 | ||
ssdeep | 6144:n0ODy+y5fPfnMe6OKYn02Fyrkw6ppGN8OoZf0cK2/KEPi9WR:nE+y5UeQ6okw6WN8OoOcv/KEPn | ||
imphash | |||
impfuzzy |
Network IP location
Signature (4cnts)
Level | Description |
---|---|
danger | Connects to IP addresses that are no longer responding to requests (legitimate services will remain up-and-running usually) |
warning | Generates some ICMP traffic |
watch | Communicates with host for which no DNS query was performed |
notice | File has been identified by 7 AntiVirus engines on VirusTotal as malicious |
Rules (1cnts)
Level | Name | Description | Collection |
---|---|---|---|
info | zip_file_format | ZIP file format | binaries (upload) |
Suricata ids
ET CNC Feodo Tracker Reported CnC Server group 8
ET INFO TLS Handshake Failure
ET CNC Feodo Tracker Reported CnC Server group 5
ET CNC Feodo Tracker Reported CnC Server group 7
ET CNC Feodo Tracker Reported CnC Server group 1
ET INFO TLS Handshake Failure
ET CNC Feodo Tracker Reported CnC Server group 5
ET CNC Feodo Tracker Reported CnC Server group 7
ET CNC Feodo Tracker Reported CnC Server group 1