Report - achform.docx

Doc XML Downloader ZIP Format Word 2007 file format(docx)
ScreenShot
Created 2023.06.07 07:47 Machine s1_win7_x6401
Filename achform.docx
Type Microsoft Word 2007+
AI Score Not founds Behavior Score
1.8
ZERO API file : malware
VT API (file)
md5 2a824a7c1f57740354cdf6a3275df44f
sha256 7c20632a8cd7fbf66250360b78cb6cd814abee4afd570ab9806badc5fb03d68e
ssdeep 768:d3NNCIDoCl+UgxiNfvH7cU/vAtEPpc4FA1XU6zg7JC0kcjS4TV3PPd0Rwntt0cmV:pNIfE+dx4vHASzuUig3/fntt0l8sv
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
watch Libraries known to be associated with a CVE were requested (may be False Positive)
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates (office) documents on the filesystem
notice Creates hidden or system file

Rules (3cnts)

Level Name Description Collection
warning Doc_XML_Downloader Detect a MS Office document with embedded XML Downloader binaries (upload)
info docx Word 2007 file format detection binaries (upload)
info zip_file_format ZIP file format binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure