Report - 20231025_정책간담회 사례비 양식.hwp

HWP MSOffice File GIF Format Lnk Format
Created 2023.09.14 19:04 Machine s1_win7_x6402
Filename 20231025_정책간담회 사례비 양식.hwp
Type Hangul (Korean) Word Processor File 5.x
AI Score Not founds Behavior Score
ZERO API file : clean
VT API (file)
md5 df53040b208a5ac37ad207ddfd828bb0
sha256 ac1eacda937e6e30ef1fdff5e6ed2ad83fedb1c7da8043954540f6e67eebb58a
ssdeep 384:8Jxv2xOfJufDdvjYmbiFSIKQ7R5xh2+OdVxfi+RuB6b/Zd7C3dea:guxCGF8mbiFSC6o6b/ue
  Network IP location

Signature (4cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates a shortcut to an executable file
notice Creates executable files on the filesystem
info Checks if process is being debugged by a debugger

Rules (6cnts)

Level Name Description Collection
info HWP_file_format HWP Document File binaries (download)
info HWP_file_format HWP Document File binaries (upload)
info lnk_file_format Microsoft Windows Shortcut File Format binaries (download)
info Lnk_Format_Zero LNK Format binaries (download)
info Microsoft_Office_File_Zero Microsoft Office File binaries (download)
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

Similarity measure (PE file only) - Checking for service failure