Report - aEYnbsDbnQ.zip

ZIP Format
ScreenShot
Created 2023.03.15 13:21 Machine s1_win7_x6402
Filename aEYnbsDbnQ.zip
Type Zip archive data, at least v2.0 to extract
AI Score Not founds Behavior Score
2.2
ZERO API file : clean
VT API (file)
md5 f4bc186107b74715370913c7c37e3e40
sha256 82bee343d8db5ae070fe3bf67415182dffc032e03f630be94c5270e34419caaf
ssdeep 6144:yaLTjsQeEcXqm56bKEY2093cbZStVHCWoR91NMd4TDy1:HLcQjc6qseWZSthCW09W4q
imphash
impfuzzy
  Network IP location

Signature (2cnts)

Level Description
danger Connects to IP addresses that are no longer responding to requests (legitimate services will remain up-and-running usually)
watch Communicates with host for which no DNS query was performed

Rules (1cnts)

Level Name Description Collection
info zip_file_format ZIP file format binaries (upload)

Network (6cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
186.250.48.5 BR Redfox Telecomunicacoes Ltda. 186.250.48.5 mailcious
193.194.92.175 DZ ARN 193.194.92.175 clean
115.178.55.22 ID PT. Simaya Jejaring Mandiri 115.178.55.22 mailcious
218.38.121.17 KR SK Broadband Co Ltd 218.38.121.17 mailcious
93.84.115.205 BY Republican Unitary Telecommunication Enterprise Beltelecom 93.84.115.205 clean
138.197.14.67 US DIGITALOCEAN-ASN 138.197.14.67 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure