SUSPICIOUS — 685eef568bf4d6b4dc5f938b5d8bedae3cd787554e56103959369435ad84b083
SUSPICIOUS — 685eef568bf4d6b4dc5f938b5d8bedae3cd787554e56103959369435ad84b083 is a office-ooxml sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (36/100). 2 of 51 detection engines flagged it.
Identification
- SHA-256:
685eef568bf4d6b4dc5f938b5d8bedae3cd787554e56103959369435ad84b083 - SHA-1:
8385856d9a45e7363ee2f2d28e8d2f7812d25bd6 - MD5:
825df4e917155f9246130933e2e8cf0a - ssdeep:
384:97m2lvxQ679CSzq4emkUExvOhIST2PnCB41FYZDgEaA:Ymve63emkbVOyF/NF+wA - TLSH:
T17B2BAFC6C2BD0825E6DCE792D135399D6CC815758865CEA197A780C2AEC1207AB3906F - Submitted as: 685eef568bf4d6b4dc5f938b5d8bedae3cd787554e56103959369435ad84b083
- File type: office-ooxml · Size: 23062 bytes
- Verdict: suspicious (36/100)
Detections (2 of 51 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): HEUR:Trojan.MSOffice.Generic
Why this verdict
The suspicious score of 36/100 is the fusion of 2 weighted signals:
- Document contains macros/active content: xlm-macro - static signal, weight 0.35, confidence 0.75
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report