Report - 협의이혼의사확인신청서.doc

VBA_macro ZIP Format Word 2007 file format(docx) GIF Format
ScreenShot
Created 2023.07.14 13:37 Machine s1_win7_x6402
Filename 협의이혼의사확인신청서.doc
Type Microsoft Word 2007+
AI Score Not founds Behavior Score
4.4
ZERO API file : clean
VT API (file) 31 detected (SAgent, malicious, high confidence, Valyria, ABRisk, ADTI, score, CodeLoader, CLASSIC, Redcap, sisum, Artemis, uxgjm, ai score=81, Detected, MacroS, Static AI, Malicious OPENXML)
md5 716b5e039177f7f6d50404bde0be9e4b
sha256 ea451e5c064f79f66433d2311e90b965d1ee26cabc411f633d826cdb6920b83e
ssdeep 768:jhIUoMxPbkRETTe2kiqZfcHpr+K/7LZ3evVoS782zL:mUoMd3TT7rqCJyKjLZ3e9PtzL
imphash
impfuzzy
  Network IP location

Signature (10cnts)

Level Description
danger File has been identified by 31 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice An application raised an exception which may be indicative of an exploit crash
notice Creates (office) documents on the filesystem
notice Creates a shortcut to an executable file
notice Creates executable files on the filesystem
notice Creates hidden or system file
notice Downloads a file or document from Google Drive
notice Performs some HTTP requests
info One or more processes crashed

Rules (4cnts)

Level Name Description Collection
warning Contains_VBA_macro_code Detect a MS Office document with embedded VBA macro code [binaries] binaries (upload)
info docx Word 2007 file format detection binaries (upload)
info Lnk_Format_Zero LNK Format binaries (download)
info zip_file_format ZIP file format binaries (upload)

Network (3cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
https://drive.google.com/uc?export=download&id=1SoDzDxjeD9T-yPcpXXI1hWkYpwGq7-00&confirm=t US GOOGLE 172.217.24.238 mailcious
drive.google.com US GOOGLE 142.250.76.142 mailcious
172.217.24.238 US GOOGLE 172.217.24.238 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure