Report - setup.7z

Stealc PrivateLoader Amadey Vidar Escalate priviledges PWS KeyLogger AntiDebug AntiVM
ScreenShot
Created 2023.10.23 16:08 Machine s1_win7_x6402
Filename setup.7z
Type 7-zip archive data, version 0.4
AI Score Not founds Behavior Score
7.2
ZERO API file : malware
VT API (file)
md5 a4e3febc2031d844ad89ed5f3ed2c206
sha256 025d0503faf5a187f7b1dd30a482fa7495bd27955320a0062a980039c3cce7dc
ssdeep 98304:LH5UsKKrQV7TCJPPUGw5N9sRyfWOXb2ZBTxT3nEOqdfCa0Bt:LHFrQVUPPYLOR1kb2ZBFnlKCamt
imphash
impfuzzy
  Network IP location

Signature (15cnts)

Level Description
danger Connects to IP addresses that are no longer responding to requests (legitimate services will remain up-and-running usually)
warning Generates some ICMP traffic
watch Communicates with host for which no DNS query was performed
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
notice Communication to multiple IPs on high port numbers possibly indicative of a peer-to-peer (P2P) or non-standard command and control protocol
notice Creates executable files on the filesystem
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice Looks up the external IP address
notice Performs some HTTP requests
notice Resolves a suspicious Top Level Domain (TLD)
notice Sends data using the HTTP POST Method
notice Yara rule detected in process memory
info Checks amount of memory in system
info Checks if process is being debugged by a debugger

Rules (11cnts)

Level Name Description Collection
notice Escalate_priviledges Escalate priviledges memory
notice Generic_PWS_Memory_Zero PWS Memory memory
notice KeyLogger Run a KeyLogger memory
info anti_dbg Checks if being debugged memory
info DebuggerCheck__GlobalFlags (no description) memory
info DebuggerCheck__QueryInfo (no description) memory
info DebuggerHiding__Active (no description) memory
info DebuggerHiding__Thread (no description) memory
info disable_dep Bypass DEP memory
info SEH__vectored (no description) memory
info ThreadControl__Context (no description) memory

Network (181cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://171.22.28.226/download/WWW14_64.exe DE CMCS 171.22.28.226 36907 malware
http://gobo03fc.top/build.exe RU Trader soft LLC 85.143.220.63 clean
http://wyattsebastian.top/e9c345fc99a4e67e.php Unknown 37.139.129.88 37497 mailcious
http://109.107.182.2/race/bus50.exe RU Teleport-TV Ltd 109.107.182.2 37496 malware
http://193.42.33.68/vpnmhcvbszad/boblspsqgegf.exe Unknown 193.42.33.68 malware
http://zexeq.com/test2/get.php?pid=CD20CF071BA7C05D5F5E6CAF42496E78&first=true KR SK Broadband Co Ltd 175.120.254.9 27911 mailcious
http://77.91.68.249/fuza/sus.exe RU Foton Telecom CJSC 77.91.68.249 clean
http://45.15.156.229/api/firegate.php RU CJSC Kolomna-Sviaz TV 45.15.156.229 36052 mailcious
http://colisumy.com/dl/build2.exe AR Telecom Argentina S.A. 190.224.203.37 31026 malware
http://85.217.144.143/files/My2.exe Unknown 85.217.144.143 34643 malware
http://apps.identrust.com/roots/dstrootcax3.p7c US AKAMAI-AS 23.32.56.72 clean
http://77.91.68.249/fuza/foto2552.exe RU Foton Telecom CJSC 77.91.68.249 clean
http://185.172.128.69/newumma.exe RU OOO Nadym Svyaz Service 185.172.128.69 37499 malware
http://jackantonio.top/timeSync.exe Unknown 37.139.129.88 37357 malware
http://zexeq.com/files/1/build3.exe KR LG DACOM Corporation 211.181.24.132 27913 malware
http://77.91.68.249/zoom/angi.exe RU Foton Telecom CJSC 77.91.68.249 clean
http://171.22.28.221/files/Ads.exe DE CMCS 171.22.28.221 37468 malware
http://94.142.138.131/api/firegate.php RU Ihor Hosting LLC 94.142.138.131 32650 mailcious
http://171.22.28.226/download/Services.exe DE CMCS 171.22.28.226 37064 malware
http://77.91.68.249/fuza/2.ps1 RU Foton Telecom CJSC 77.91.68.249 clean
http://lakuiksong.known.co.ke/netTimer.exe Unknown 146.59.70.14 37358 malware
http://193.42.32.118/api/tracemap.php Unknown 193.42.32.118 36180 mailcious
http://77.91.68.249/fuza/nalo.exe RU Foton Telecom CJSC 77.91.68.249 clean
http://77.91.124.1/theme/index.php RU Foton Telecom CJSC 77.91.124.1 37040 mailcious
http://45.15.156.229/api/tracemap.php RU CJSC Kolomna-Sviaz TV 45.15.156.229 33783 mailcious
http://176.113.115.84:8080/4.php RU OOO Network of data-centers Selectel 176.113.115.84 34795 mailcious
http://193.233.255.73/loghub/master RU OOO FREEnet Group 193.233.255.73 37500 mailcious
http://94.142.138.131/api/tracemap.php RU Ihor Hosting LLC 94.142.138.131 28311 mailcious
http://193.42.32.118/api/firecom.php Unknown 193.42.32.118 36700 mailcious
http://net.geo.opera.com/opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767 US OPERASOFTWARE 107.167.110.216 clean
http://www.maxmind.com/geoip/v2.1/city/me US CLOUDFLARENET 104.18.146.235 clean
http://171.22.28.213/3.exe DE CMCS 171.22.28.213 37068 malware
http://www.google.com/ US GOOGLE 142.250.76.132 clean
https://vk.com/doc52355237_667021459?hash=JwfD1ZCA6QgwzFekXEx3DZwJrazNVwknSJ4vBCdj3Ys&dl=GOvejb9TzKE4gYCzHfWoYwfHsCK1bKByDgPNozGoPQ0&api=1&no_preview=1 RU VKontakte Ltd 87.240.132.78 mailcious
https://db-ip.com/demo/home.php?s=175.208.134.152 US CLOUDFLARENET 104.26.5.15 clean
https://flyawayaero.net/baf14778c246e15550645e30ba78ce1c.exe US CLOUDFLARENET 104.21.93.225 36783 malware
https://diplodoka.net/16d7385732355adc773732b0327e9c0c/7a54bdb20779c4359694feaa1398dd25.exe US CLOUDFLARENET 172.67.217.52 clean
https://grabyourpizza.com/7a54bdb20779c4359694feaa1398dd25.exe US CLOUDFLARENET 172.67.197.174 37397 malware
https://vk.com/doc791620691_663065029?hash=Efubo9FQtw3Bdj42XJVcJwymfIH3PazMKz8g5wJ0dZX&dl=G44TCNRSGA3DSMI:1682787066:QgrgzF33wDt9bwmmOgWCYTv61J7HwhLVZOXGaEdWiKP&api=1&no_preview=1#stats RU VKontakte Ltd 87.240.132.78 mailcious
https://vk.com/doc52355237_667162081?hash=4BgzraSUlIskCw5J6xGm3ViPzq8b7svHxEssqfvoCPH&dl=LANzNVd3qg51q6TImeUt70feNJmp9qZlTmWM3bxixcD&api=1&no_preview=1#test22 RU VKontakte Ltd 87.240.132.78 mailcious
https://experiment.pw/setup294.exe US CLOUDFLARENET 104.21.34.37 37436 malware
https://potatogoose.com/16d7385732355adc773732b0327e9c0c/baf14778c246e15550645e30ba78ce1c.exe US CLOUDFLARENET 172.67.180.173 clean
https://sun6-23.userapi.com/c909518/u52355237/docs/d49/5c0d068b2eac/PL_Client.bmp?extra=b8v6B06HpzoI3tSK0mTSwwXQMXnLc3q1jWsNUxfrUhg37IPgrTLUxJuXVjoqdaD6wxqd5omwvfT1I4ifIHPUpzMI6CdiRlp1tMXpPcZQCoixxWWU44eu8GW5XHCV-7gyuNDh4krMD77l0Vqy RU VKontakte Ltd 95.142.206.3 clean
https://api.myip.com/ US CLOUDFLARENET 172.67.75.163 clean
https://steamcommunity.com/profiles/76561199563297648 US Akamai International B.V. 104.76.78.101 37362 mailcious
https://sun6-20.userapi.com/c909518/u52355237/docs/d7/9d03fcd9d5bd/test2222.bmp?extra=Wry9QF8NRzHXFhuAyX10K2cUiDS0DTKoIRmO3Gdqy2Pqlg5wpKdUMJGOb4-PdzAqr5weQJRr6xl0yQWHUlmTdrUW1y_n1wiM2ewm5-R5m1ExpU4IOhw5iaaLryf706xSvx5M-MQjL18eDFOc RU VKontakte Ltd 95.142.206.0 clean
https://sun6-23.userapi.com/c909618/u52355237/docs/d9/334aaa965d98/tmvwr.bmp?extra=8vKP1hUU8FXC9Qe8mMCGvUfa8Cp8pOwsD2JU4mCuyllGkHmKNdLdm5pJBH5n8fLgBYOEugKzlYD-S8BALhWt6cB4_4dQu6dsu8wxVcZgawhp4z7JO3yqL-PS8fMBHOwRaKfmmF-W_XhYYWdH RU VKontakte Ltd 95.142.206.3 clean
https://sun6-23.userapi.com/c909228/u52355237/docs/d50/f10f18a7f79c/RisePro.bmp?extra=Xyda-uNNyJmyTQ5S8ByoXlhlokLU9vlSrjsRGgjAiDtxiqFtWK4WlDj9f-W0msD9rV2oEuDwnqK7I8iKgaM_YsJkIyFSOZrP_X0lYZZwVAEqwL_9-ZsHTgq9slIJgndIgavwE7f4PVOoEQjB RU VKontakte Ltd 95.142.206.3 clean
https://vk.com/doc52355237_667233820?hash=ksqvnpPOTVnZUBQvgNWMHz7b34SlhrJYzyLwhjI3p2w&dl=9z5K5NGG8CQyYYjYV1UsyBwEjOrCNpWsf0ZuYRFDUpz&api=1&no_preview=1#1 RU VKontakte Ltd 87.240.132.78 mailcious
https://dzen.ru/?yredirect=true RU Invest Mobile LLC 62.217.160.2 clean
https://vk.com/doc52355237_667128433?hash=c75kTaBvy8XsGUHj9nZuWnwfdY9ZY2Vr0W0kqMRZKj4&dl=yd0Kt5iJ7qiHq1ne4m1DmzhCyz12TwydRCTVOZYwpg8&api=1&no_preview=1#redcl RU VKontakte Ltd 87.240.132.78 mailcious
https://vk.com/doc52355237_667205062?hash=Svqj7zCdrED1hyD81lRt9NeObuiSXNy8bJzdPsMUx1w&dl=zCXthZXeky7MxZ1PAEfvkLNfEWm2gZlF4zhzbI8exz4&api=1&no_preview=1 RU VKontakte Ltd 87.240.132.78 mailcious
https://vk.com/doc52355237_666904463?hash=UxTczsuPw9hubob0BlwxReQuXuRVMu7K4lkIHd53nfc&dl=pL6TKclvjp9CpzQWGzva7G0EpGDeSydWo0xKWmJnj6o&api=1&no_preview=1#WW11 RU VKontakte Ltd 87.240.132.78 mailcious
https://pastebin.com/raw/xYhKBupz US CLOUDFLARENET 172.67.34.170 36780 mailcious
https://vk.com/doc52355237_667276452?hash=wkBRUPYuo43rYtxIzQc6pAfTM1sBDD9zNWcmfsnUyZk&dl=pSqUmbLaVdyliolYK30HXXznJ7HpQH0ZxzieEabZe7k&api=1&no_preview=1#zxc RU VKontakte Ltd 87.240.132.78 mailcious
https://vk.com/doc746114504_647280747?hash=cvDFKP5q0CQEjBCbeoeHvPNrWE0xbMxZEmrkIeNKcET&dl=G42DMMJRGQ2TANA:1661413520:uZNj68vRUvQaydRD8wpAK8zluN0I7otw5AHbA1ZlN9T&api=1&no_preview=1 RU VKontakte Ltd 87.240.132.78 mailcious
https://net.geo.opera.com/opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767 US OPERASOFTWARE 107.167.110.216 clean
https://api.2ip.ua/geo.json US CLOUDFLARENET 104.21.65.24 clean
https://vk.com/doc52355237_666996873?hash=DTmX6GpQzg0mSZJ3QBf9KMyoAQLjAN2VneVoP2TiOB8&dl=3T0LCAZCJSJEhCRk9I2GHnvey9MXQk00H3a77N9btwD&api=1&no_preview=1 RU VKontakte Ltd 87.240.132.78 mailcious
https://sun6-23.userapi.com/c909518/u52355237/docs/d49/5c0d068b2eac/PL_Client.bmp?extra=b8v6B06HpzoI3tSK0mTSwwXQMXnLc3q1jWsNUxfrUhg37IPgrTLUxJuXVjoqdaD6wxqd5omwvfT1I4ifIHPUpzMI6CdiRlp1tMXpPcZQCoixxWWU5YWu8GW5XHCV-7gyvoe17RzAXLzj21i0 RU VKontakte Ltd 95.142.206.3 clean
https://neuralshit.net/bd7fce869cc9dad0938390c13f85c712/7725eaa6592c80f8124e769b4e8a07f7.exe US CLOUDFLARENET 104.21.6.10 clean
https://sun6-23.userapi.com/c235031/u52355237/docs/d21/7cb744cd40e6/crypted.bmp?extra=ijasbvJahzXSeNdqXSXLMGpGHvjz4jGBIbrjMTotAwPSDg7ZJWoTCMEgnrXhoT-UPrEIyIsw-zYLJvngWwPvMPOtEmMltl6PXIlTO5aNN0Qq0AxSsWwHuMhtvwLx9L6tGIXloB7OODUZzlM9 RU VKontakte Ltd 95.142.206.3 clean
https://vk.com/doc52355237_667260318?hash=5fIVbEMD7QFCeMOR3scNeKxSNfqeBg9KoduBU4Y3tID&dl=koAos1zT2zeVbUu3VEeFdVGaQOOEBZEWHNqrz2p7C1k&api=1&no_preview=1#rise RU VKontakte Ltd 87.240.132.78 mailcious
https://sun6-23.userapi.com/c909228/u52355237/docs/d50/f10f18a7f79c/RisePro.bmp?extra=Xyda-uNNyJmyTQ5S8ByoXlhlokLU9vlSrjsRGgjAiDtxiqFtWK4WlDj9f-W0msD9rV2oEuDwnqK7I8iKgaM_YsJkIyFSOZrP_X0lYZZwVAEqwL_9_5kHTgq9slIJgndI1KD0Q-CqPlv7RQef RU VKontakte Ltd 95.142.206.3 clean
https://vk.com/doc791620691_663065029?hash=Efubo9FQtw3Bdj42XJVcJwymfIH3PazMKz8g5wJ0dZX&dl=G44TCNRSGA3DSMI:1682787066:QgrgzF33wDt9bwmmOgWCYTv61J7HwhLVZOXGaEdWiKP&api=1&no_preview=1#test RU VKontakte Ltd 87.240.132.78 mailcious
https://sun6-20.userapi.com/c237131/u52355237/docs/d23/7cd7043f8e90/New_crypt_test.bmp?extra=vYj8TsuI4Mh2GARpTfNUmOIhtAIFlk_aV6rN4fuV8RoazN2oSjvkW3gF0yYbSbvEdEIhlBKvLFNzrDhjXjuLtzBxm3t7UAjcRP6wVkJIC2mfq9v9-q12np5vLrprxlhFhALs6yun22McEsNj RU VKontakte Ltd 95.142.206.0 clean
https://sso.passport.yandex.ru/push?uuid=9d27acac-cdcd-4aed-b07a-81869e366ae7&retpath=https%3A%2F%2Fdzen.ru%2F%3Fyredirect%3Dtrue RU YANDEX LLC 213.180.204.24 clean
https://sun6-23.userapi.com/c235131/u52355237/docs/d29/d447d9047e01/2.bmp?extra=G5NjMO4sTn6SbCFGk7CD_SOlopWCbJMwNATWfk18b8h6W5KpzIWtQpereK3vm9yQmMyGT0c1IH0TTJppN4VFVi2l828xcy6v8sK2jl4z9PQdlNlCBd13ABRJJbdaK_NhKXaUEg0AhxvYwqFU RU VKontakte Ltd 95.142.206.3 clean
https://api.db-ip.com/v2/p31e4d59ee6ad1a0b5cc80695a873e43a8fbca06/self US CLOUDFLARENET 172.67.75.166 clean
https://vk.com/doc52355237_666778887?hash=MsypGwgfzH9k8tAFuGqJl0MJgVVDiak3EKsK8zRZBXP&dl=zbnEaURFd1h1t5v6QgcpBauCKgnVbU0YGtRdWYWulE8&api=1&no_preview=1 RU VKontakte Ltd 87.240.132.78 mailcious
https://octocrabs.com/7725eaa6592c80f8124e769b4e8a07f7.exe US CLOUDFLARENET 172.67.200.10 36716 mailcious
neuralshit.net US CLOUDFLARENET 172.67.134.35 malware
db-ip.com US CLOUDFLARENET 172.67.75.166 clean
jackantonio.top Unknown 37.139.129.88 malware
dzen.ru RU Invest Mobile LLC 62.217.160.2 clean
vanaheim.cn RU RETN Limited 45.11.27.150 mailcious
t.me GB Telegram Messenger Inc 149.154.167.99 mailcious
lrefjviufewmcd.org RU Petersburg Internet Network ltd. 91.215.85.209 malware
ipinfo.io US GOOGLE 34.117.59.81 clean
sun6-23.userapi.com RU VKontakte Ltd 95.142.206.3 mailcious
iplogger.org DE Hetzner Online GmbH 148.251.234.83 mailcious
potatogoose.com US CLOUDFLARENET 172.67.180.173 malware
diplodoka.net US CLOUDFLARENET 172.67.217.52 malware
api.2ip.ua US CLOUDFLARENET 172.67.139.220 clean
steamcommunity.com US Akamai International B.V. 104.76.78.101 mailcious
grabyourpizza.com US CLOUDFLARENET 104.21.90.82 malware
laubenstein.space RU Beget LLC 45.130.41.101 mailcious
twitter.com US TWITTER 104.244.42.193 clean
telegram.org GB Telegram Messenger Inc 149.154.167.99 clean
yip.su US CLOUDFLARENET 104.21.79.77 mailcious
sun6-20.userapi.com RU VKontakte Ltd 95.142.206.0 mailcious
octocrabs.com US CLOUDFLARENET 172.67.200.10 mailcious
www.instagram.com US FACEBOOK 157.240.11.174 clean
sso.passport.yandex.ru RU YANDEX LLC 213.180.204.24 clean
lakuiksong.known.co.ke Unknown 146.59.70.14 malware
experiment.pw US CLOUDFLARENET 104.21.34.37 malware
yandex.ru RU YANDEX LLC 5.255.255.77 clean
net.geo.opera.com US OPERASOFTWARE 107.167.110.211 clean
gobo03fc.top RU Trader soft LLC 85.143.220.63 clean
iplogger.com DE Hetzner Online GmbH 148.251.234.93 mailcious
zexeq.com KR SK Broadband Co Ltd 123.213.233.131 malware
wyattsebastian.top Unknown 37.139.129.88 mailcious
api.db-ip.com US CLOUDFLARENET 104.26.4.15 clean
colisumy.com BR Sercomtel Participacoes S.A. 187.18.108.158 malware
www.google.com US GOOGLE 142.250.76.132 clean
iplis.ru DE Hetzner Online GmbH 148.251.234.93 mailcious
i.instagram.com IE FACEBOOK 31.13.82.52 clean
pastebin.com US CLOUDFLARENET 104.20.68.143 mailcious
flyawayaero.net US CLOUDFLARENET 104.21.93.225 malware
www.maxmind.com US CLOUDFLARENET 104.18.145.235 clean
vk.com RU VKontakte Ltd 93.186.225.194 mailcious
api.myip.com US CLOUDFLARENET 104.26.9.59 clean
lycheepanel.info US CLOUDFLARENET 172.67.187.122 malware
148.251.234.93 DE Hetzner Online GmbH 148.251.234.93 mailcious
194.169.175.128 Unknown 194.169.175.128 mailcious
37.139.129.88 Unknown 37.139.129.88 mailcious
104.18.146.235 US CLOUDFLARENET 104.18.146.235 clean
142.250.66.132 US GOOGLE 142.250.66.132 clean
171.22.28.213 DE CMCS 171.22.28.213 malware
172.67.167.220 US CLOUDFLARENET 172.67.167.220 malware
157.240.31.63 US FACEBOOK 157.240.31.63 clean
77.91.124.1 RU Foton Telecom CJSC 77.91.124.1 malware
62.122.184.92 Unknown 62.122.184.92 mailcious
193.233.255.73 RU OOO FREEnet Group 193.233.255.73 mailcious
104.26.5.15 US CLOUDFLARENET 104.26.5.15 clean
85.217.144.143 Unknown 85.217.144.143 malware
85.143.220.63 RU Trader soft LLC 85.143.220.63 malware
149.154.167.99 GB Telegram Messenger Inc 149.154.167.99 mailcious
104.21.65.24 US CLOUDFLARENET 104.21.65.24 clean
61.111.58.34 KR LG DACOM Corporation 61.111.58.34 malware
104.21.34.37 US CLOUDFLARENET 104.21.34.37 phishing
62.217.160.2 RU Invest Mobile LLC 62.217.160.2 clean
172.67.75.163 US CLOUDFLARENET 172.67.75.163 clean
83.97.73.44 DE Limitless Mobile GmbH 83.97.73.44 clean
172.67.75.166 US CLOUDFLARENET 172.67.75.166 clean
121.254.136.18 KR LG DACOM Corporation 121.254.136.18 clean
171.22.28.239 DE CMCS 171.22.28.239 mailcious
45.11.27.150 RU RETN Limited 45.11.27.150 clean
172.67.187.122 US CLOUDFLARENET 172.67.187.122 malware
104.21.79.77 US CLOUDFLARENET 104.21.79.77 phishing
171.22.28.226 DE CMCS 171.22.28.226 malware
87.240.132.78 RU VKontakte Ltd 87.240.132.78 mailcious
171.22.28.221 DE CMCS 171.22.28.221 malware
34.117.59.81 US GOOGLE 34.117.59.81 clean
77.91.68.249 RU Foton Telecom CJSC 77.91.68.249 malware
172.67.200.10 US CLOUDFLARENET 172.67.200.10 mailcious
176.113.115.84 RU OOO Network of data-centers Selectel 176.113.115.84 mailcious
172.67.34.170 US CLOUDFLARENET 172.67.34.170 mailcious
148.251.234.83 DE Hetzner Online GmbH 148.251.234.83 clean
104.26.8.59 US CLOUDFLARENET 104.26.8.59 clean
104.21.6.10 US CLOUDFLARENET 104.21.6.10 malware
45.130.41.101 RU Beget LLC 45.130.41.101 mailcious
193.42.32.118 Unknown 193.42.32.118 mailcious
176.113.115.135 RU OOO Network of data-centers Selectel 176.113.115.135 mailcious
176.113.115.136 RU OOO Network of data-centers Selectel 176.113.115.136 mailcious
185.172.128.69 RU OOO Nadym Svyaz Service 185.172.128.69 malware
109.107.182.133 RU Teleport-TV Ltd 109.107.182.133 clean
77.88.55.88 RU YANDEX LLC 77.88.55.88 clean
80.66.75.4 RU Alexander Valerevich Mokhonko 80.66.75.4 mailcious
172.67.197.174 US CLOUDFLARENET 172.67.197.174 clean
91.215.85.209 RU Petersburg Internet Network ltd. 91.215.85.209 mailcious
169.148.95.39 Unknown 169.148.95.39 clean
45.15.156.229 RU CJSC Kolomna-Sviaz TV 45.15.156.229 mailcious
157.240.31.174 US FACEBOOK 157.240.31.174 clean
107.167.110.216 US OPERASOFTWARE 107.167.110.216 clean
95.142.206.3 RU VKontakte Ltd 95.142.206.3 mailcious
195.158.3.162 GB Uzbektelekom Joint Stock Company 195.158.3.162 clean
45.143.201.238 Unknown 45.143.201.238 mailcious
172.67.217.52 US CLOUDFLARENET 172.67.217.52 malware
104.21.93.225 US CLOUDFLARENET 104.21.93.225 phishing
146.59.70.14 Unknown 146.59.70.14 malware
104.244.42.193 US TWITTER 104.244.42.193 suspicious
193.42.33.68 Unknown 193.42.33.68 malware
213.180.204.24 RU YANDEX LLC 213.180.204.24 clean
172.67.180.173 US CLOUDFLARENET 172.67.180.173 malware
95.142.206.0 RU VKontakte Ltd 95.142.206.0 mailcious
80.66.75.77 RU Alexander Valerevich Mokhonko 80.66.75.77 mailcious
109.107.182.2 RU Teleport-TV Ltd 109.107.182.2 malware
171.22.28.236 DE CMCS 171.22.28.236 mailcious
104.76.78.101 US Akamai International B.V. 104.76.78.101 mailcious
94.142.138.131 RU Ihor Hosting LLC 94.142.138.131 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure