Report - file.zip

ZIP Format
ScreenShot
Created 2023.03.15 15:13 Machine s1_win7_x6402
Filename file.zip
Type Zip archive data, at least v2.0 to extract
AI Score Not founds Behavior Score
1.2
ZERO API file : malware
VT API (file) 22 detected (malicious, high confidence, Razy, Save, score, ccnc, Generic ML PUA, Static AI, Malicious Archive, XPACK, ai score=88, R562151, Probably Heur, ExeHeaderL, MBgONq0t6ZN)
md5 e2dbdc78e35b9e2a41fb7a966ddf02dc
sha256 c983a82de63f04867c5c20fad56419d908663a0ab6684420420f20c93cbcccfd
ssdeep 98304:TenezqtcvLbr5efZQC9gtxx1NMxyue2Ovm5SUTCRlkdGPN6b1EEis5nL0h:TenezpHmZ/9gRLiepvmkbRudGPZsFLm
imphash
impfuzzy
  Network IP location

Signature (2cnts)

Level Description
warning File has been identified by 22 AntiVirus engines on VirusTotal as malicious
notice Performs some HTTP requests

Rules (1cnts)

Level Name Description Collection
info zip_file_format ZIP file format binaries (upload)

Network (4cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://don-die.com/hittest.php?a=NH0goI0w1hXW19v&id=110 US CLOUDFLARENET 104.21.50.222 clean
http://don-die.com/hittest.php?a=aElEffzR1gQfbVP&id=110 US CLOUDFLARENET 104.21.50.222 clean
don-die.com US CLOUDFLARENET 172.67.167.162 clean
104.21.50.222 US CLOUDFLARENET 104.21.50.222 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure