Report - mac.dotm

VBA_macro
ScreenShot
Created 2021.08.21 12:17 Machine s1_win7_x6401
Filename mac.dotm
Type Microsoft Word 2007+
AI Score Not founds Behavior Score
1.8
ZERO API file : clean
VT API (file) 18 detected (Emooo, malicious, high confidence, Save, Obfuscated, Obfuscation, EmoooDldr, Ole2, druvzi, modification of W97M, ai score=83, Probably Heur, W97Obfuscated, Static AI, Suspicious OPENXML)
md5 d9b583dae1c7d4bdef40a58e084651f8
sha256 a4781b36e0846a2a6b8e80e41367b70b440293eac9071f9bff8a9c44ae4c6cb5
ssdeep 384:tcKf+StdSjYHTSksFqXKFVOfSQm1sqcwNc:p+odMYdsFr/t1sjmc
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
watch File has been identified by 18 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates (office) documents on the filesystem
notice Creates hidden or system file

Rules (1cnts)

Level Name Description Collection
warning Contains_VBA_macro_code Detect a MS Office document with embedded VBA macro code [binaries] binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure