Report - FBR Circular.docx

ScreenShot
Created 2021.07.13 13:20 Machine s1_win7_x6402
Filename FBR Circular.docx
Type Microsoft Word 2007+
AI Score Not founds Behavior Score
2.2
ZERO API file : clean
VT API (file) 31 detected (DownLoader40, OPRY, VSNW0BG21, Malicious, score, druvzi, fhdip, ai score=84, Wacatac, CLASSIC, Psyme, down)
md5 2c171622a19a378ea51d08748c70eb59
sha256 c1923226d58186c7e0735e058be80022a57e7e819e1e41b4c6e03065252be11f
ssdeep 12288:t4lEug1Rp7WzxW+T0y5T9r1+2Y2fB/8xjygh8Hf:t4l8fGnIy3r1R1/pghu
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
danger File has been identified by 31 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates (office) documents on the filesystem
notice Creates hidden or system file

Rules (1cnts)

Level Name Description Collection
info OleStream (no description) scripts

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure