Report - OCC.doc

MSOffice File
ScreenShot
Created 2021.06.24 20:20 Machine s1_win7_x6402
Filename OCC.doc
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Autho
AI Score Not founds Behavior Score
2.4
ZERO API file : clean
VT API (file)
md5 dc836881ad266d654325720a8341eec7
sha256 a77d4bea223fefea9372cd1b01aae4f41b8624d1ed4d9e593d212e1f42295b5e
ssdeep 384:05555A7siAZGa+JoJ/iJVAEJE+JJr127tz1NsbNJNiN+NsEmCiSY5UfF:05555pfZ31QNJYUl
imphash
impfuzzy
  Network IP location

Signature (5cnts)

Level Description
watch Communicates with host for which no DNS query was performed
watch Libraries known to be associated with a CVE were requested (may be False Positive)
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates (office) documents on the filesystem
notice Creates hidden or system file

Rules (1cnts)

Level Name Description Collection
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure