Report - The_Progress_and_Promise_of_the_Moon-Kim_Summit.doc

VBA_macro
ScreenShot
Created 2021.07.05 09:42 Machine s1_win7_x6402
Filename The_Progress_and_Promise_of_the_Moon-Kim_Summit.doc
Type Microsoft Word 2007+
AI Score Not founds Behavior Score
3.6
ZERO API file : clean
VT API (file) 41 detected (malicious, high confidence, EmoooDldr, MalDoc, ali1000101, KIMSUK, ZKGJ, MSHTA, SLoad, Ole2, druvzi, Emooo, Iscodtas, TOPIS, 2CQpMiFTF1I, PBMD, Static AI, Malicious OPENXML, score, ai score=100, qexvmc)
md5 6ead104743be6575e767986a71cf4bd9
sha256 d1b5d606c866c304c3eb28fc52ed700c6b292e6e4387e0dac1a895e231bfe5b3
ssdeep 1536:WkNSQuGkD6MUc8CBllIIWv13Z33Le9AlwkWC7pguCr1eMVdj+WWZdDaft:WU1uGkmMrwIWv13ZDCZnuueMLj+BZdDQ
imphash
impfuzzy
  Network IP location

Signature (6cnts)

Level Description
danger File has been identified by 41 AntiVirus engines on VirusTotal as malicious
watch Communicates with host for which no DNS query was performed
watch Libraries known to be associated with a CVE were requested (may be False Positive)
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates (office) documents on the filesystem
notice Creates hidden or system file

Rules (2cnts)

Level Name Description Collection
warning Contains_VBA_macro_code Detect a MS Office document with embedded VBA macro code [binaries] binaries (upload)
info test_office test url scripts

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure