Report - 482c30dc5680e0c01b8a117ce969aef0.doc

MSOffice File
ScreenShot
Created 2024.07.08 14:16 Machine s1_win7_x6401
Filename 482c30dc5680e0c01b8a117ce969aef0.doc
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Title: , Author: 1, Template: count.mc6, Last Saved By: Good, Revision Number: 42, Name of Creating Application: Microsoft Office Word, Total Editing Time:
AI Score Not founds Behavior Score
2.0
ZERO API file : clean
VT API (file) 3 detected (OLE2, UrtBadur, genw)
md5 482c30dc5680e0c01b8a117ce969aef0
sha256 56921f89c747387aed20dc42aa31d4fa1abc11ac43a09d45db1ffa3663839335
ssdeep 384:xSJcZsleQGEZg/6iiSAoKXMVkRDE1dAHkkgRPXDUxz99:7moQG3eMVkF1YXDUxz99
imphash
impfuzzy
  Network IP location

Signature (5cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates (office) documents on the filesystem
notice Creates hidden or system file
notice File has been identified by 3 AntiVirus engines on VirusTotal as malicious
notice Resolves a suspicious Top Level Domain (TLD)

Rules (1cnts)

Level Name Description Collection
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
aloud.relax98.bilotora.ru Unknown mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure