Report - 조선 시장 물가 분석(신의주).hwp

HWP PS PostScript MSOffice File Lnk Format GIF Format
ScreenShot
Created 2024.01.25 13:56 Machine s1_win7_x6403_us
Filename 조선 시장 물가 분석(신의주).hwp
Type Hangul (Korean) Word Processor File 5.x
AI Score Not founds Behavior Score
1.6
ZERO API file : clean
VT API (file) 15 detected (VSNW09A24, Detected, Phish, Eplw)
md5 e26422ba7e1eed4481e9389806e798c3
sha256 b6e1351f1767a2cacb3fc7515f0a67691bbd8b9274a26c2953ba898ba879ebea
ssdeep 1536:Mil5mCJP+/UR4jLClxvBRaBOJjHXjMkgbGNZYB1JA:MilcCF+sR4jLAUOtHzMkyk8
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
watch File has been identified by 15 AntiVirus engines on VirusTotal as malicious
notice Creates a shortcut to an executable file
notice Creates executable files on the filesystem
info Checks if process is being debugged by a debugger

Rules (7cnts)

Level Name Description Collection
watch Win32_HWP_PostScript_Zero Detect a HWP with embedded Post Script code binaries (upload)
info HWP_file_format HWP Document File binaries (download)
info HWP_file_format HWP Document File binaries (upload)
info lnk_file_format Microsoft Windows Shortcut File Format binaries (download)
info Lnk_Format_Zero LNK Format binaries (download)
info Microsoft_Office_File_Zero Microsoft Office File binaries (download)
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure