Report - docx005.docx

VBA_macro Word 2007 file format(docx) ZIP Format
ScreenShot
Created 2024.11.26 09:53 Machine s1_win7_x6401
Filename docx005.docx
Type Microsoft Word 2007+
AI Score Not founds Behavior Score
2.2
ZERO API file : clean
VT API (file) 38 detected (Malicious, score, Thus, Valyria, Save, APMP, high confidence, V97M, APMPKILL, dsetwk, CLASSIC, VBA5, docx, WM97, Highly Suspicious, ABTrojan, YATZ, OMacro)
md5 6d3b90b7d6da1af9cd77b1a348c3e1a7
sha256 7d66370f91b0574e202760391402acaa5216f3f2fe7748573e43cdb93f933e4c
ssdeep 384:C6LZC78+isH2SNkuHekv0VqvWGoBnJ9VQF9p0lhS0wMrzizefxY4WHg3:Bq8xDSNklOFo3Qvp0lhS0nzwefxYU
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
danger File has been identified by 38 AntiVirus engines on VirusTotal as malicious
notice Creates (office) documents on the filesystem
notice Creates hidden or system file
notice Word document hooks document open

Rules (3cnts)

Level Name Description Collection
warning Contains_VBA_macro_code Detect a MS Office document with embedded VBA macro code [binaries] binaries (upload)
info docx Word 2007 file format detection binaries (upload)
info zip_file_format ZIP file format binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure