ScreenShot
Created | 2022.03.18 11:39 | Machine | s1_win7_x6403 |
Filename | exe-in-word-97-2003.doc | ||
Type | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Autho | ||
AI Score | Not founds | Behavior Score |
|
ZERO API | file : mailcious | ||
VT API (file) | 12 detected (Generickdz, MacroE, Artemis, possible, Threat, Embedded, ExeInOffice, Presenoker, YzY0OhWDtOJIaF40) | ||
md5 | 3ceb8fe2322f4ba44b32318ddfb0bee2 | ||
sha256 | f291d4e18f91ed409a23b73174a57b01f9197064f0bcd798e80777ec5d3548cd | ||
ssdeep | 1536:WdzsphWYZUghygDgcnAeu/3QWiD6quwj4gXV/o0RBC:WdzsfWmnAe7mykgXV/oGQ | ||
imphash | |||
impfuzzy |
Network IP location
Signature (7cnts)
Level | Description |
---|---|
watch | File has been identified by 12 AntiVirus engines on VirusTotal as malicious |
notice | Allocates read-write-execute memory (usually to unpack itself) |
notice | An application raised an exception which may be indicative of an exploit crash |
notice | Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time) |
notice | Creates (office) documents on the filesystem |
notice | Creates hidden or system file |
info | One or more processes crashed |
Rules (3cnts)
Level | Name | Description | Collection |
---|---|---|---|
watch | Malicious_Library_Zero | Malicious_Library | binaries (upload) |
info | Microsoft_Office_File_Zero | Microsoft Office File | binaries (upload) |
info | OS_Processor_Check_Zero | OS Processor Check | binaries (upload) |
Network (0cnts) ?
Request | CC | ASN Co | IP4 | Rule ? | ZERO ? |
---|