Report - Government%20policy%20Updated%202023.docx

ZIP Format Word 2007 file format(docx)
ScreenShot
Created 2023.05.31 17:48 Machine s1_win7_x6401
Filename Government%20policy%20Updated%202023.docx
Type Zip archive data, at least v2.0 to extract
AI Score Not founds Behavior Score
5.0
ZERO API file : malware
VT API (file) 38 detected (CVE-2017-0199, CVE-2022-3019, Save, many, DOCX, aggr, Camelot, Malicious, score, equmby, AGDX, 7LNQUR, ai score=82, Embed, oleurl, Wacatac, Detected, S1842, Probably Heur, W97OleLink, ExtLink, CLASSIC, Etecer, bZaQy0)
md5 975ea012aff8d8dcc37638be840684e5
sha256 a2694a68b2edb61185dcbcafddf0889ad0d55150136d171674ce2e03a260c838
ssdeep 192:GEhM0o7Z/c+8poF1d3jvvtlsv9264wpKGhe/b8oCrGxjPCfZUUEc:GqlWcfa7pr1lY92hwsGA/bxCyxjPCfZF
imphash
impfuzzy
  Network IP location

Signature (7cnts)

Level Description
danger Connects to IP addresses that are no longer responding to requests (legitimate services will remain up-and-running usually)
danger File has been identified by 38 AntiVirus engines on VirusTotal as malicious
watch Communicates with host for which no DNS query was performed
watch Libraries known to be associated with a CVE were requested (may be False Positive)
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates (office) documents on the filesystem
notice Creates hidden or system file

Rules (2cnts)

Level Name Description Collection
info docx Word 2007 file format detection binaries (upload)
info zip_file_format ZIP file format binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
104.248.88.180 NL DIGITALOCEAN-ASN 104.248.88.180 malware

Suricata ids



Similarity measure (PE file only) - Checking for service failure