SUSPICIOUS — 0f4d783011e6311b680144351c251d185ce32ad550d8e70f7f88a9ee88dcf966
SUSPICIOUS — 0f4d783011e6311b680144351c251d185ce32ad550d8e70f7f88a9ee88dcf966 is a office-ooxml sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (36/100). 2 of 54 detection engines flagged it.
Identification
- SHA-256:
0f4d783011e6311b680144351c251d185ce32ad550d8e70f7f88a9ee88dcf966 - SHA-1:
a6153e59a52f9493122787676d0624af046ee6af - MD5:
79b027a713332c98198142c5c772e6cd - ssdeep:
384:97RBljxk679CSzq4emkUExvOhIST2PnCB/1FYmDgET2:H/ji63emkbVOyF/yFtd2 - TLSH:
T1E62BBFDDD2BC4C15D2C4EA5AD467398D5CC414F48F398AD296BA80C36983207AA3806F - Submitted as: 0f4d783011e6311b680144351c251d185ce32ad550d8e70f7f88a9ee88dcf966
- File type: office-ooxml · Size: 23062 bytes
- Verdict: suspicious (36/100)
Detections (2 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): HEUR:Trojan.MSOffice.Generic
Why this verdict
The suspicious score of 36/100 is the fusion of 2 weighted signals:
- Document contains macros/active content: xlm-macro - static signal, weight 0.35, confidence 0.75
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report