ScreenShot
Created | 2023.05.26 17:44 | Machine | s1_win7_x6402 |
Filename | 646ff88cd208a.zip | ||
Type | Zip archive data, at least v2.0 to extract | ||
AI Score | Not founds | Behavior Score |
|
ZERO API | file : clean | ||
VT API (file) | |||
md5 | 9aecd71a5365d68f8b4956239956a45b | ||
sha256 | 3f7f569a845361ccafe9118054951df745662a323db2b39eac0a71ac5f49cd6d | ||
ssdeep | 49152:6Q6J3WM202p5GutgAJuIxyxWCIZsS85PWZ5FvcBC:p89i7JDmWgzP+UC | ||
imphash | |||
impfuzzy |
Network IP location
Signature (2cnts)
Level | Description |
---|---|
notice | HTTP traffic contains suspicious features which may be indicative of malware related traffic |
notice | Performs some HTTP requests |
Rules (1cnts)
Level | Name | Description | Collection |
---|---|---|---|
info | zip_file_format | ZIP file format | binaries (upload) |
Network (6cnts) ?
Suricata ids
ET POLICY NetSupport GeoLocation Lookup Request
ET INFO NetSupport Remote Admin Checkin
ET MALWARE NetSupport RAT with System Information
ET INFO NetSupport Remote Admin Checkin
ET MALWARE NetSupport RAT with System Information