Report - PREMIUM FINANCE AGREEMENT.docx

ScreenShot
Created 2021.06.03 20:50 Machine s1_win7_x6401
Filename PREMIUM FINANCE AGREEMENT.docx
Type Microsoft Word 2007+
AI Score Not founds Behavior Score
3.4
ZERO API file : clean
VT API (file) 11 detected (CVE-2017-0199, CVE170199, VSNW03F21, SDrop, equmby, Ole2link, Artemis, Phishing)
md5 677e96c969263b6ab69587e55731cffa
sha256 4835f6d3b8e1414e0176a9142c154d8b67f3cf0183ce9b230cb240ba110d8140
ssdeep 384:f0ynju7aJ+QkT5lYdQ6+b1XBRQiujrq2yVvGnZZOPz:9FJvkTUdQ607ADyVvU38
imphash
impfuzzy
  Network IP location

Signature (6cnts)

Level Description
danger Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually)
watch File has been identified by 11 AntiVirus engines on VirusTotal as malicious
watch Libraries known to be associated with a CVE were requested (may be False Positive)
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates (office) documents on the filesystem
notice Creates hidden or system file

Rules (0cnts)

Level Name Description Collection

Network (2cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
micrsoft365.live RU EuroByte LLC 95.142.40.241 mailcious
95.142.40.241 RU EuroByte LLC 95.142.40.241 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure