Report - oig

ZIP Format
ScreenShot
Created 2023.05.31 22:26 Machine s1_win7_x6403
Filename oig
Type Zip archive data, at least v2.0 to extract
AI Score Not founds Behavior Score
0.6
ZERO API file : clean
VT API (file)
md5 ff7e3106b49aed84ccf0cc485ddb5ee8
sha256 60c29a70fca45f7384c3e78906e0e5ea64b109f192eb1624007d2f22ed4f43dd
ssdeep 24:92XoHAzxOFW/lu7X1hWGyuFgmhMD2f7KSby4jz5jadirqUCEntX6dCUVR3rDN1QM:92XoHA0cluT1gQKCjdqirRHXtU/N1YeT
imphash
impfuzzy
  Network IP location

Signature (1cnts)

Level Description
watch Communicates with host for which no DNS query was performed

Rules (1cnts)

Level Name Description Collection
info zip_file_format ZIP file format binaries (upload)

Network (18cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
89.161.136.188 PL home.pl S.A. 89.161.136.188 mailcious
164.92.82.47 Unknown 164.92.82.47 clean
153.122.24.177 JP GMO CLOUD K.K. 153.122.24.177 mailcious
135.125.108.170 US AVAYA 135.125.108.170 mailcious
13.225.131.58 US AMAZON-02 13.225.131.58 clean
91.201.52.102 RU Internet-Pro LLC 91.201.52.102 clean
99.86.207.125 US AMAZON-02 99.86.207.125 clean
77.78.104.3 CZ Casablanca INT 77.78.104.3 phishing
153.122.170.15 JP GMO CLOUD K.K. 153.122.170.15 clean
79.96.161.192 PL home.pl S.A. 79.96.161.192 clean
49.12.155.123 DE Hetzner Online GmbH 49.12.155.123 clean
5.134.13.210 GB UKDedicated LTD 5.134.13.210 mailcious
216.177.137.32 US 1P-WSS 216.177.137.32 mailcious
62.122.170.171 NL Serverel Inc. 62.122.170.171 clean
133.125.38.187 JP SAKURA Internet Inc. 133.125.38.187 mailcious
80.82.115.227 GB 34SP.com Limited 80.82.115.227 mailcious
104.21.48.207 US CLOUDFLARENET 104.21.48.207 clean
79.96.32.254 PL home.pl S.A. 79.96.32.254 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure