Report - P49A1RKQbr6n5L2G.zip

ZIP Format
ScreenShot
Created 2023.03.09 18:14 Machine s1_win7_x6402
Filename P49A1RKQbr6n5L2G.zip
Type Zip archive data, at least v2.0 to extract
AI Score Not founds Behavior Score
3.4
ZERO API file : clean
VT API (file) 7 detected (GenKryptik, GHDZ, Emotet, cmtd, Archive, Bomb, ai score=82, suspected of Archive, MailBomb, SwollenFile, CLASSIC)
md5 5ed137665b139baccce1abee74282b81
sha256 45efd63ea476b6cb9c7fa9a8f1428475f4dfb5516b77dc4f8d1d6a4af70af553
ssdeep 6144:n0ODy+y5fPfnMe6OKYn02Fyrkw6ppGN8OoZf0cK2/KEPi9WR:nE+y5UeQ6okw6WN8OoOcv/KEPn
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
danger Connects to IP addresses that are no longer responding to requests (legitimate services will remain up-and-running usually)
warning Generates some ICMP traffic
watch Communicates with host for which no DNS query was performed
notice File has been identified by 7 AntiVirus engines on VirusTotal as malicious

Rules (1cnts)

Level Name Description Collection
info zip_file_format ZIP file format binaries (upload)

Network (3cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
91.207.28.33 KG Optima Telecom Ltd. 91.207.28.33 mailcious
104.168.155.143 US HOSTWINDS 104.168.155.143 mailcious
91.121.146.47 FR OVH SAS 91.121.146.47 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure