Report - macapa.pdf

ZIP Format
ScreenShot
Created 2023.09.15 17:28 Machine s1_win7_x6401
Filename macapa.pdf
Type Zip archive data, at least v2.0 to extract
AI Score Not founds Behavior Score
1.0
ZERO API file : clean
VT API (file) 7 detected (VMProtect, Malicious, score, Banbra, AGEN, Generic@AI, RDML, 0uPRMj4G6e+3BP6KBSfHjQ)
md5 ecda023859fe1b0449dc23140267b39c
sha256 a60b1b4a3431128b1a421dcb0d9bf91addb8f83b80e8c9f3aff393d603a9c48c
ssdeep 393216:wGsRnlwDYO55wk9mjss0l8NAhcsCYvGqFfstV:k5SDYscj9GfC2G4kV
imphash
impfuzzy
  Network IP location

Signature (2cnts)

Level Description
watch Communicates with host for which no DNS query was performed
notice File has been identified by 7 AntiVirus engines on VirusTotal as malicious

Rules (1cnts)

Level Name Description Collection
info zip_file_format ZIP file format binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
156.236.72.121 US HK Kwaifong Group Limited 156.236.72.121 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure