Report - Setup.7z

Stealc Vidar PrivateLoader Amadey Escalate priviledges PWS KeyLogger AntiDebug AntiVM
ScreenShot
Created 2023.10.20 18:12 Machine s1_win7_x6402
Filename Setup.7z
Type 7-zip archive data, version 0.4
AI Score Not founds Behavior Score
7.8
ZERO API file : malware
VT API (file)
md5 72b145dcb4456a0892b5b725eec5d1b4
sha256 8e4c9d073c391fa9b96c86ce80f1f59b0a935b0935c70885c046b91f83398d1c
ssdeep 98304:Ee3mSdKIiCTdJbVlDQ4YENxV5yTSJhLEuO/SUILbWw0TMPjaAC+/8S:Ee3mSdKKJDpYBT7/OSw0oPNC+/H
imphash
impfuzzy
  Network IP location

Signature (17cnts)

Level Description
danger Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually)
warning Generates some ICMP traffic
watch Communicates with host for which no DNS query was performed
watch Performs a TXT record DNS lookup potentially for command and control or covert channel
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
notice Communication to multiple IPs on high port numbers possibly indicative of a peer-to-peer (P2P) or non-standard command and control protocol
notice Connects to SIP Stun Server
notice Creates executable files on the filesystem
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice Looks up the external IP address
notice Performs some HTTP requests
notice Resolves a suspicious Top Level Domain (TLD)
notice Sends data using the HTTP POST Method
notice Yara rule detected in process memory
info Checks amount of memory in system
info Checks if process is being debugged by a debugger

Rules (11cnts)

Level Name Description Collection
notice Escalate_priviledges Escalate priviledges memory
notice Generic_PWS_Memory_Zero PWS Memory memory
notice KeyLogger Run a KeyLogger memory
info anti_dbg Checks if being debugged memory
info DebuggerCheck__GlobalFlags (no description) memory
info DebuggerCheck__QueryInfo (no description) memory
info DebuggerHiding__Active (no description) memory
info DebuggerHiding__Thread (no description) memory
info disable_dep Bypass DEP memory
info SEH__vectored (no description) memory
info ThreadControl__Context (no description) memory

Network (207cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://171.22.28.226/download/WWW14_64.exe DE CMCS 171.22.28.226 36907 malware
http://kevinrobinson.top/e9c345fc99a4e67e.php CZ Coolhousing s.r.o. 45.132.1.20 37432 mailcious
http://172.86.97.117/himeffectivelyproress.exe CA QUICKPACKET 172.86.97.117 37400 malware
http://85.217.144.143/files/Amadey.exe Unknown 85.217.144.143 37253 malware
http://5.75.212.77/13088c19c5a97b42d0d1d9573cc9f1b8 DE Hetzner Online GmbH 5.75.212.77 clean
http://5.75.212.77/upgrade.zip DE Hetzner Online GmbH 5.75.212.77 37406 mailcious
http://zexeq.com/test2/get.php?pid=CD20CF071BA7C05D5F5E6CAF42496E78&first=true KR LG DACOM Corporation 211.181.24.133 27911 mailcious
http://45.15.156.229/api/firegate.php RU CJSC Kolomna-Sviaz TV 45.15.156.229 36052 mailcious
http://galandskiyher5.com/downloads/toolspub1.exe Unknown 194.169.175.127 37396 malware
http://colisumy.com/dl/build2.exe HU Telenor Hungary plc 84.224.231.39 31026 malware
http://gobo02fc.top/build.exe RU Trader soft LLC 85.143.220.63 37395 malware
http://85.217.144.143/files/My2.exe Unknown 85.217.144.143 34643 malware
http://apps.identrust.com/roots/dstrootcax3.p7c US Akamai International B.V. 23.67.53.17 clean
http://5.75.212.77/55d1d90f582be35927dbf245a6a59f6e DE Hetzner Online GmbH 5.75.212.77 37430 mailcious
http://104.194.128.170/svp/Hfxbflp.mp3 CA QUICKPACKET 104.194.128.170 clean
http://jackantonio.top/timeSync.exe CZ Coolhousing s.r.o. 45.132.1.20 37357 malware
http://zexeq.com/files/1/build3.exe KR LG DACOM Corporation 211.119.84.112 27913 malware
http://171.22.28.221/files/Ads.exe DE CMCS 171.22.28.221 malware
http://94.142.138.113/api/tracemap.php RU Ihor Hosting LLC 94.142.138.113 28877 mailcious
http://193.42.32.118/api/firegate.php Unknown 193.42.32.118 36458 mailcious
http://171.22.28.226/download/Services.exe DE CMCS 171.22.28.226 37064 malware
http://5.42.92.88/loghub/master RU CJSC Kolomna-Sviaz TV 5.42.92.88 37264 mailcious
http://193.42.33.7/mbSDvj3/index.php Unknown 193.42.33.7 37449 mailcious
http://lakuiksong.known.co.ke/netTimer.exe Unknown 146.59.70.14 37358 malware
http://193.42.32.118/api/tracemap.php Unknown 193.42.32.118 36180 mailcious
http://5.75.212.77/ DE Hetzner Online GmbH 5.75.212.77 37407 mailcious
http://45.129.14.83/fra.exe GB Bunea TELECOM SRL 45.129.14.83 clean
http://45.15.156.229/api/tracemap.php RU CJSC Kolomna-Sviaz TV 45.15.156.229 33783 mailcious
http://171.22.28.213/3.exe DE CMCS 171.22.28.213 37068 malware
http://94.142.138.113/api/firegate.php RU Ihor Hosting LLC 94.142.138.113 36152 mailcious
http://171.22.28.221/files/Random.exe DE CMCS 171.22.28.221 37434 malware
http://193.42.32.118/api/firecom.php Unknown 193.42.32.118 36700 mailcious
http://net.geo.opera.com/opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767 US OPERASOFTWARE 107.167.110.216 clean
http://www.maxmind.com/geoip/v2.1/city/me US CLOUDFLARENET 104.18.145.235 clean
http://gons01b.top/build.exe RU Trader soft LLC 85.143.220.63 37402 malware
http://77.91.68.249/navi/kur90.exe RU Foton Telecom CJSC 77.91.68.249 37069 malware
http://193.42.33.7/newumma.exe Unknown 193.42.33.7 mailcious
https://vk.com/doc52355237_667021459?hash=JwfD1ZCA6QgwzFekXEx3DZwJrazNVwknSJ4vBCdj3Ys&dl=GOvejb9TzKE4gYCzHfWoYwfHsCK1bKByDgPNozGoPQ0&api=1&no_preview=1 RU VKontakte Ltd 87.240.132.72 mailcious
https://msdl.microsoft.com/download/symbols/winload_prod.pdb/768283CA443847FB8822F9DB1F36ECC51/winload_prod.pdb US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.219 clean
https://sun6-23.userapi.com/c909228/u52355237/docs/d38/847843b59260/d3h782af.bmp?extra=47rdXWAczPPHoELmIB5F-wINKuHjiWx6MelbVcVKX-XzpjSlHCjtPC1dX3n_SIjy-E4a7Hg3ljMBe_q87PD5QlZ2pVx4ON5lHKAy5mRVFJ1gUNHTUI93vvVaO6EwzCqnfk4tvVE6n497Lvvo RU VKontakte Ltd 95.142.206.3 clean
https://db-ip.com/demo/home.php?s=175.208.134.152 US CLOUDFLARENET 104.26.5.15 clean
https://flyawayaero.net/baf14778c246e15550645e30ba78ce1c.exe US CLOUDFLARENET 172.67.216.81 36783 malware
https://vsblobprodscussu5shard58.blob.core.windows.net/b-4712e0edc5a240eabf23330d7df68e77/98A14A45856422D571CDEA18737E156B89D4C85FE7A2C03E353274FC83996DE200.blob?sv=2019-07-07&sr=b&si=1&sig=a00cd6w1eEWAICwyKE1cTFHt5KkPpREimUXb%2F8yxloI%3D&spr=https&se=202 US MICROSOFT-CORP-MSN-AS-BLOCK 20.150.79.68 clean
https://vsblobprodscussu5shard10.blob.core.windows.net/b-4712e0edc5a240eabf23330d7df68e77/3361580E1DAA2301EF4C62D105FB67166BD89EA03FCDE3C800EACFAF71EE01C200.blob?sv=2019-07-07&sr=b&si=1&sig=i2VslFCszJFPcsoKvioFglCJvuT3uSV4ZcbuBEr9zkw%3D&spr=https&se=2023- US MICROSOFT-CORP-MSN-AS-BLOCK 20.150.38.228 clean
https://sun6-20.userapi.com/c909618/u52355237/docs/d11/f10de79a60ff/zxc.bmp?extra=2IWemhXJCtxsmHnrEM-ehLyp7-WvTFYNf8GWUSetJ8-guOw5s09JP69BhcVtGTfTBNve75XWmGAhxDunL7CtJMC1rNTCZuAvsRuanIuDufmraKQuKFdW0Cm_40H7Ham6r6z6YAx4u-VxVNfo RU VKontakte Ltd 95.142.206.0 clean
https://msdl.microsoft.com/download/symbols/ntkrnlmp.pdb/3844DBB920174967BE7AA4A2C20430FA2/ntkrnlmp.pdb US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.219 clean
https://grabyourpizza.com/7a54bdb20779c4359694feaa1398dd25.exe US CLOUDFLARENET 104.21.90.82 37397 malware
https://vk.com/doc791620691_663065029?hash=Efubo9FQtw3Bdj42XJVcJwymfIH3PazMKz8g5wJ0dZX&dl=G44TCNRSGA3DSMI:1682787066:QgrgzF33wDt9bwmmOgWCYTv61J7HwhLVZOXGaEdWiKP&api=1&no_preview=1#stats RU VKontakte Ltd 93.186.225.194 mailcious
https://vk.com/doc52355237_667162081?hash=4BgzraSUlIskCw5J6xGm3ViPzq8b7svHxEssqfvoCPH&dl=LANzNVd3qg51q6TImeUt70feNJmp9qZlTmWM3bxixcD&api=1&no_preview=1#test22 RU VKontakte Ltd 93.186.225.194 clean
https://potatogoose.com/011c9f113ddd731c796c737fa640ca01/baf14778c246e15550645e30ba78ce1c.exe US CLOUDFLARENET 172.67.180.173 clean
https://experiment.pw/setup294.exe US CLOUDFLARENET 172.67.167.220 37436 malware
https://pastebin.com/raw/HPj0MzD6 US CLOUDFLARENET 104.20.67.143 37403 mailcious
https://sun6-23.userapi.com/c909518/u52355237/docs/d49/2461e2bfbe4c/PL_Client.bmp?extra=rsx6YdeS1TMyj8hstvsuJl4qhUAw0Cl_BDL9zlBtIcqYM_c5iOMTGcoEDS3olEnkyxRuhLKtQgZ_Zj9A57UjQvMe0WnaTE5UkrhQZfK52loM8JRRAIGs9XcvugIqJJ1mp3W0eylyXuWPRmvv RU VKontakte Ltd 95.142.206.3 clean
https://api.myip.com/ US CLOUDFLARENET 104.26.8.59 clean
https://steamcommunity.com/profiles/76561199563297648 US Akamai International B.V. 104.76.78.101 37362 mailcious
https://sun6-23.userapi.com/c235131/u52355237/docs/d29/c2ec420964d3/2.bmp?extra=smxM9cx8UEWCOi7dAazlPSUrryzvsUncAMkw9IxCyGfvRsBfqF9Kcg1S-tNZodsGOZ48oxP5EllG8Xt2Ml5MTfQOxvIXD5_Fz8dySEBwkZD0lSlzpLf7fEFS2icznum8dAEPSqE3f4Oo6JPe RU VKontakte Ltd 95.142.206.3 clean
https://msdl.microsoft.com/download/symbols/index2.txt US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.219 clean
https://sso.passport.yandex.ru/push?uuid=f7ac55a0-6e6f-4cd3-8e26-a48c8345246e&retpath=https%3A%2F%2Fdzen.ru%2F%3Fyredirect%3Dtrue RU YANDEX LLC 213.180.204.24 clean
https://sun6-23.userapi.com/c909518/u52355237/docs/d48/367eee565503/WWW11_32.bmp?extra=lT8dVRtZIQ6vp6oOAx94JFf1Pro4u-Ic3tMl1CwZ8XPaX73x5ZrR1KeXmhnzlfj7eyhv7kwN3ufSPWi09MsfgYLRAda7vmz9jpdhAXH9UFKpzlAsiGhAQn-f4zeU-Bw9pQ0y1tekcHh7kG0I RU VKontakte Ltd 95.142.206.3 clean
https://sun6-20.userapi.com/c909518/u52355237/docs/d7/12f243df05d7/test2222.bmp?extra=5bKT7bWgmxjzByTTdgZLdjnXojvB8-hfjOtwHYX6E6fgUFd2WSjbF6OE-4IlOSj2ex_qerAma71rtt-akOzRHhnyyLh_hGKtJNRiHlwRwkCy1H5_zDaf6KrOyd06nRcyKhI_1KX0VQOBkLZW RU VKontakte Ltd 95.142.206.0 clean
https://dzen.ru/?yredirect=true RU Invest Mobile LLC 62.217.160.2 clean
https://vk.com/doc52355237_667128433?hash=c75kTaBvy8XsGUHj9nZuWnwfdY9ZY2Vr0W0kqMRZKj4&dl=yd0Kt5iJ7qiHq1ne4m1DmzhCyz12TwydRCTVOZYwpg8&api=1&no_preview=1#redcl RU VKontakte Ltd 87.240.132.72 mailcious
https://vk.com/doc52355237_666904463?hash=UxTczsuPw9hubob0BlwxReQuXuRVMu7K4lkIHd53nfc&dl=pL6TKclvjp9CpzQWGzva7G0EpGDeSydWo0xKWmJnj6o&api=1&no_preview=1#WW11 RU VKontakte Ltd 93.186.225.194 mailcious
https://pastebin.com/raw/xYhKBupz US CLOUDFLARENET 104.20.68.143 36780 mailcious
https://vk.com/doc746114504_647280747?hash=cvDFKP5q0CQEjBCbeoeHvPNrWE0xbMxZEmrkIeNKcET&dl=G42DMMJRGQ2TANA:1661413520:uZNj68vRUvQaydRD8wpAK8zluN0I7otw5AHbA1ZlN9T&api=1&no_preview=1 RU VKontakte Ltd 87.240.132.72 mailcious
https://net.geo.opera.com/opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767 US OPERASOFTWARE 107.167.110.211 clean
https://api.2ip.ua/geo.json US CLOUDFLARENET 104.21.65.24 clean
https://sun6-22.userapi.com/c909228/u52355237/docs/d34/5396c88b015b/RisePro_0_9.bmp?extra=yXqSXHL5f2CYAzONeUP1CPICSmUZrVngDGEO05ensD48azqcKnZhT4LnpLZSM8Awzy3VfNBN9qtudAdBqvG2Bz9DjytesrB8-F7i4ClmlyfNYz5P0OZKhaPjYFvjyA3yFHnDZDJPNuyzY6lZ RU VKontakte Ltd 95.142.206.2 clean
https://vk.com/doc52355237_666996873?hash=DTmX6GpQzg0mSZJ3QBf9KMyoAQLjAN2VneVoP2TiOB8&dl=3T0LCAZCJSJEhCRk9I2GHnvey9MXQk00H3a77N9btwD&api=1&no_preview=1 RU VKontakte Ltd 87.240.132.72 mailcious
https://vk.com/doc52355237_666990393?hash=FTORQeSjuGQM3QZ0VZVmUaPzzMTjiHgVozgZL1VKkLs&dl=WHDNqvgddqa5sNEafsQGa9H9myfZRZuS1RHM37yysD8&api=1&no_preview=1 RU VKontakte Ltd 93.186.225.194 mailcious
https://vk.com/doc52355237_667141516?hash=HsWBQHEyToldG20L9sZwIGv5gYpaCVz2I4NaffNltj4&dl=bzijOkGFnqMWzUUPzsZAF8ZEAo0nny8RcsO8lHuWRKD&api=1&no_preview=1#rise RU VKontakte Ltd 87.240.132.72 clean
https://diplodoka.net/011c9f113ddd731c796c737fa640ca01/7a54bdb20779c4359694feaa1398dd25.exe US CLOUDFLARENET 172.67.217.52 clean
https://vk.com/doc791620691_663065029?hash=Efubo9FQtw3Bdj42XJVcJwymfIH3PazMKz8g5wJ0dZX&dl=G44TCNRSGA3DSMI:1682787066:QgrgzF33wDt9bwmmOgWCYTv61J7HwhLVZOXGaEdWiKP&api=1&no_preview=1#test RU VKontakte Ltd 93.186.225.194 mailcious
https://vk.com/doc52355237_667106954?hash=u1nxcEZaxcLM5gBJiodoTcIasNoT55fLzvwrRyhTuIk&dl=eHGUUzvGf3mld3Z4uL26ddKyh2AQiccctdzWDv3HEzk&api=1&no_preview=1#1 RU VKontakte Ltd 93.186.225.194 mailcious
https://vk.com/doc52355237_667169888?hash=0FXstFY9YauEmcBFs6Ju2Y5tz7xvBx6HWmEsxICLiEk&dl=ZYeU9AHGQRsNeFvrDCqd9qZaUAOggliBMioUMK71cy8&api=1&no_preview=1#t1 RU VKontakte Ltd 93.186.225.194 clean
https://api.db-ip.com/v2/p31e4d59ee6ad1a0b5cc80695a873e43a8fbca06/self US CLOUDFLARENET 172.67.75.166 clean
https://neuralshit.net/011c9f113ddd731c796c737fa640ca01/7725eaa6592c80f8124e769b4e8a07f7.exe US CLOUDFLARENET 104.21.6.10 clean
https://vk.com/doc52355237_666778887?hash=MsypGwgfzH9k8tAFuGqJl0MJgVVDiak3EKsK8zRZBXP&dl=zbnEaURFd1h1t5v6QgcpBauCKgnVbU0YGtRdWYWulE8&api=1&no_preview=1 RU VKontakte Ltd 93.186.225.194 mailcious
https://octocrabs.com/7725eaa6592c80f8124e769b4e8a07f7.exe US CLOUDFLARENET 104.21.21.189 36716 mailcious
https://sun6-20.userapi.com/c235131/u52355237/docs/d47/44a24ce675a2/crypted.bmp?extra=zC6h-JiJEnlq0D7d34kRb8Vbq1AnLg6Vg_zNG5ePklvOfDwaCO35VzPPNI5eK99N1s35KXwS1iDpWGb2FFRintE43fmGTCnpX9oWSgb42LHByV-2U5b5oyRP2ZmgndiJVmc8OeFX9UV2rI2A RU VKontakte Ltd 95.142.206.0 clean
neuralshit.net US CLOUDFLARENET 172.67.134.35 malware
www.maxmind.com US CLOUDFLARENET 104.18.146.235 clean
db-ip.com US CLOUDFLARENET 172.67.75.166 clean
jackantonio.top CZ Coolhousing s.r.o. 45.132.1.20 malware
dzen.ru RU Invest Mobile LLC 62.217.160.2 clean
t.me GB Telegram Messenger Inc 149.154.167.99 mailcious
lrefjviufewmcd.org RU Petersburg Internet Network ltd. 91.215.85.209 malware
ipinfo.io US GOOGLE 34.117.59.81 clean
sun6-23.userapi.com RU VKontakte Ltd 95.142.206.3 mailcious
galandskiyher5.com Unknown 194.169.175.127 malware
iplogger.org DE Hetzner Online GmbH 148.251.234.83 mailcious
potatogoose.com US CLOUDFLARENET 104.21.35.235 malware
darianentertainment.com US ALABANZA-BALT 65.109.26.240 clean
lakuiksong.known.co.ke Unknown 146.59.70.14 malware
api.2ip.ua US CLOUDFLARENET 172.67.139.220 clean
steamcommunity.com US Akamai International B.V. 104.76.78.101 mailcious
martvl.com US ISPNET-1 69.48.143.183 malware
api.db-ip.com US CLOUDFLARENET 172.67.75.166 clean
laubenstein.space RU Beget LLC 45.130.41.101 mailcious
twitter.com US TWITTER 104.244.42.129 clean
telegram.org GB Telegram Messenger Inc 149.154.167.99 clean
yip.su DE Hetzner Online GmbH 148.251.234.93 mailcious
cdn.discordapp.com Unknown 162.159.135.233 malware
sun6-20.userapi.com RU VKontakte Ltd 95.142.206.0 mailcious
kevinrobinson.top CZ Coolhousing s.r.o. 45.132.1.20 mailcious
octocrabs.com US CLOUDFLARENET 104.21.21.189 mailcious
ab07dfb1-b583-46f4-8c3d-99c8152cf07f.uuid.filesdumpplace.org BG ITL LLC 185.82.216.96 clean
sun6-21.userapi.com RU VKontakte Ltd 95.142.206.1 mailcious
msdl.microsoft.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.219 clean
diplodoka.net US CLOUDFLARENET 104.21.78.56 malware
experiment.pw US CLOUDFLARENET 104.21.34.37 malware
yandex.ru RU YANDEX LLC 77.88.55.60 clean
grabyourpizza.com US CLOUDFLARENET 172.67.197.174 malware
iplogger.com DE Hetzner Online GmbH 148.251.234.93 mailcious
gons01b.top RU Trader soft LLC 85.143.220.63 malware
zexeq.com KR LG DACOM Corporation 211.119.84.112 malware
stun4.l.google.com US GOOGLE 172.253.127.127 clean
vsblobprodscussu5shard10.blob.core.windows.net US MICROSOFT-CORP-MSN-AS-BLOCK 20.150.70.36 clean
colisumy.com MX Uninet S.A. de C.V. 201.124.243.137 malware
net.geo.opera.com US OPERASOFTWARE 107.167.110.211 clean
api.myip.com US CLOUDFLARENET 172.67.75.163 clean
gobo02fc.top RU Trader soft LLC 85.143.220.63 malware
sun6-22.userapi.com RU VKontakte Ltd 95.142.206.2 mailcious
pastebin.com US CLOUDFLARENET 104.20.67.143 mailcious
flyawayaero.net US CLOUDFLARENET 104.21.93.225 malware
vsblobprodscussu5shard58.blob.core.windows.net US MICROSOFT-CORP-MSN-AS-BLOCK 20.150.38.228 clean
vk.com RU VKontakte Ltd 87.240.132.67 mailcious
sso.passport.yandex.ru RU YANDEX LLC 213.180.204.24 clean
server11.filesdumpplace.org BG ITL LLC 185.82.216.96 clean
iplis.ru DE Hetzner Online GmbH 148.251.234.93 mailcious
lycheepanel.info US CLOUDFLARENET 104.21.32.208 malware
148.251.234.93 DE Hetzner Online GmbH 148.251.234.93 mailcious
194.169.175.128 Unknown 194.169.175.128 mailcious
85.217.144.143 Unknown 85.217.144.143 malware
104.18.146.235 US CLOUDFLARENET 104.18.146.235 clean
193.42.33.7 Unknown 193.42.33.7 mailcious
93.186.225.194 RU VKontakte Ltd 93.186.225.194 mailcious
171.22.28.213 DE CMCS 171.22.28.213 malware
69.48.143.183 US ISPNET-1 69.48.143.183 malware
172.67.167.220 US CLOUDFLARENET 172.67.167.220 malware
194.169.175.127 Unknown 194.169.175.127 malware
185.225.75.171 DE Mayak Smart Services Ltd. 185.225.75.171 mailcious
77.91.124.55 RU Foton Telecom CJSC 77.91.124.55 mailcious
104.20.68.143 US CLOUDFLARENET 104.20.68.143 mailcious
162.159.135.233 Unknown 162.159.135.233 malware
62.217.160.2 RU Invest Mobile LLC 62.217.160.2 clean
104.244.42.1 US TWITTER 104.244.42.1 suspicious
104.26.5.15 US CLOUDFLARENET 104.26.5.15 clean
5.255.255.70 RU YANDEX LLC 5.255.255.70 clean
172.86.97.117 CA QUICKPACKET 172.86.97.117 malware
104.20.67.143 US CLOUDFLARENET 104.20.67.143 mailcious
149.154.167.99 GB Telegram Messenger Inc 149.154.167.99 mailcious
104.21.65.24 US CLOUDFLARENET 104.21.65.24 clean
104.21.34.37 US CLOUDFLARENET 104.21.34.37 phishing
45.129.14.83 GB Bunea TELECOM SRL 45.129.14.83 malware
20.150.38.228 US MICROSOFT-CORP-MSN-AS-BLOCK 20.150.38.228 clean
104.21.90.82 US CLOUDFLARENET 104.21.90.82 malware
95.142.206.1 RU VKontakte Ltd 95.142.206.1 mailcious
91.215.85.209 RU Petersburg Internet Network ltd. 91.215.85.209 mailcious
204.79.197.219 US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.219 clean
172.67.187.122 US CLOUDFLARENET 172.67.187.122 malware
190.187.52.42 PE AMERICATEL PERU S.A. 190.187.52.42 clean
171.22.28.224 DE CMCS 171.22.28.224 clean
171.22.28.226 DE CMCS 171.22.28.226 malware
171.22.28.221 DE CMCS 171.22.28.221 malware
20.150.79.68 US MICROSOFT-CORP-MSN-AS-BLOCK 20.150.79.68 clean
34.117.59.81 US GOOGLE 34.117.59.81 clean
77.91.68.249 RU Foton Telecom CJSC 77.91.68.249 malware
85.143.220.63 RU Trader soft LLC 85.143.220.63 malware
104.21.21.189 US CLOUDFLARENET 104.21.21.189 clean
104.21.35.235 US CLOUDFLARENET 104.21.35.235 clean
185.82.216.96 BG ITL LLC 185.82.216.96 clean
148.251.234.83 DE Hetzner Online GmbH 148.251.234.83 clean
104.26.8.59 US CLOUDFLARENET 104.26.8.59 clean
104.21.6.10 US CLOUDFLARENET 104.21.6.10 malware
190.219.136.87 PA Cable Onda 190.219.136.87 clean
193.42.32.118 Unknown 193.42.32.118 mailcious
5.75.212.77 DE Hetzner Online GmbH 5.75.212.77 mailcious
45.132.1.20 CZ Coolhousing s.r.o. 45.132.1.20 mailcious
104.21.32.208 US CLOUDFLARENET 104.21.32.208 malware
172.67.75.166 US CLOUDFLARENET 172.67.75.166 clean
172.67.216.81 US CLOUDFLARENET 172.67.216.81 malware
94.142.138.113 RU Ihor Hosting LLC 94.142.138.113 mailcious
172.67.197.174 US CLOUDFLARENET 172.67.197.174 clean
121.254.136.9 KR LG DACOM Corporation 121.254.136.9 clean
65.109.26.240 US ALABANZA-BALT 65.109.26.240 mailcious
45.130.41.101 RU Beget LLC 45.130.41.101 mailcious
104.21.78.56 US CLOUDFLARENET 104.21.78.56 malware
107.167.110.211 US OPERASOFTWARE 107.167.110.211 clean
45.15.156.229 RU CJSC Kolomna-Sviaz TV 45.15.156.229 mailcious
104.194.128.170 CA QUICKPACKET 104.194.128.170 mailcious
193.42.32.29 Unknown 193.42.32.29 malware
95.142.206.3 RU VKontakte Ltd 95.142.206.3 mailcious
95.142.206.2 RU VKontakte Ltd 95.142.206.2 mailcious
172.67.139.220 US CLOUDFLARENET 172.67.139.220 clean
185.216.70.238 Unknown 185.216.70.238 mailcious
172.67.217.52 US CLOUDFLARENET 172.67.217.52 malware
95.142.206.0 RU VKontakte Ltd 95.142.206.0 mailcious
146.59.70.14 Unknown 146.59.70.14 malware
171.22.28.239 DE CMCS 171.22.28.239 clean
213.180.204.24 RU YANDEX LLC 213.180.204.24 clean
172.67.180.173 US CLOUDFLARENET 172.67.180.173 malware
87.240.132.72 RU VKontakte Ltd 87.240.132.72 mailcious
142.251.2.127 US GOOGLE 142.251.2.127 clean
171.22.28.236 DE CMCS 171.22.28.236 clean
104.76.78.101 US Akamai International B.V. 104.76.78.101 mailcious
5.42.92.88 RU CJSC Kolomna-Sviaz TV 5.42.92.88 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure