Report - docx006.docx

VBA_macro Word 2007 file format(docx) ZIP Format
ScreenShot
Created 2024.11.26 09:51 Machine s1_win7_x6403
Filename docx006.docx
Type Microsoft Word 2007+
AI Score Not founds Behavior Score
2.6
ZERO API file : clean
VT API (file) 38 detected (Malicious, score, Thus, Valyria, Save, APMP, high confidence, V97M, APMPKILL, dsetwk, CLASSIC, VBA5, docx, WM97, Highly Suspicious, ABTrojan, YATZ, OMacro)
md5 ed76eb774c6db599f8ad50d4489e3c31
sha256 902c15cdab0459f9fcabafd664c466331a49fb535f0e199db0dabb8d3d189ce5
ssdeep 384:C6LZC78M0DUe3ngh0VqvWGoBnJ9VQF9p0lhS0wJzizefxY4W1G:Bq81Df38Fo3Qvp0lhS0ozwefxYY
imphash
impfuzzy
  Network IP location

Signature (5cnts)

Level Description
danger File has been identified by 38 AntiVirus engines on VirusTotal as malicious
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Creates (office) documents on the filesystem
notice Creates hidden or system file
notice Word document hooks document open

Rules (3cnts)

Level Name Description Collection
warning Contains_VBA_macro_code Detect a MS Office document with embedded VBA macro code [binaries] binaries (upload)
info docx Word 2007 file format detection binaries (upload)
info zip_file_format ZIP file format binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure