Report - qfqe.docx

ZIP Format Word 2007 file format(docx)
ScreenShot
Created 2024.01.12 15:55 Machine s1_win7_x6401
Filename qfqe.docx
Type Microsoft Word 2007+
AI Score Not founds Behavior Score
1.6
ZERO API file : clean
VT API (file) 1 detected (Artemis)
md5 8972149b5dabf81f7a446a230aac0c96
sha256 0e10ae1c6a1d1991e5765bc6cce380373f3344af98d15692de0882e26844cf2a
ssdeep 384:dVPHaIFsRplqiJF/hgbMLgfAani7vdU6E9c:vPHja0iJth0cghni7vC6E2
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates (office) documents on the filesystem
notice Creates hidden or system file
notice File has been identified by one AntiVirus engine on VirusTotal as malicious

Rules (2cnts)

Level Name Description Collection
info docx Word 2007 file format detection binaries (upload)
info zip_file_format ZIP file format binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure