Report - Манифест.docx

ScreenShot
Created 2021.08.03 09:40 Machine s1_win7_x6403
Filename Манифест.docx
Type Zip archive data, at least v2.0 to extract
AI Score Not founds Behavior Score
2.2
ZERO API file : clean
VT API (file) 15 detected (GenericKD, Artemis, Malicious, score, Probably Heur, W97OleLink)
md5 224cb9048f8743986b552d04f9e804cd
sha256 0661fc4eb09e99ba4d8e28a2d5fae6bb243f6acc0289870f9414f9328721010a
ssdeep 384:JkZMeqjOzfbaqIhhUscTo3eaf0TG4gBcGlb0PhvtQwVmTnc:uOeE8D6UscToDf0TlgL10FXIc
imphash
impfuzzy
  Network IP location

Signature (5cnts)

Level Description
watch File has been identified by 15 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Creates (office) documents on the filesystem
notice Creates hidden or system file

Rules (0cnts)

Level Name Description Collection

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
cloud-documents.com Unknown clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure