bikealma_document_20.06.2022.doc
Classification: Malicious
bikealma_document_20.06.2022.doc is a malicious file sample. Linked to Svcready malware. Reported by 1 threat source, last seen 2022-06-20.
Detection summary
- 25 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: SVCREADY (S1064)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| SVCReady | MalwareBazaar Abuse.ch | 2022-06-20 21:20:30 | 2022-06-20 21:20:30 | malicious-activity | S1064 SVCReady |
Sample information
- Filenames
- bikealma_document_20.06.2022.doc
- File type
- application/zip
- MD5
e2237eac90e20fe703806ad6b8221597- SHA-1
e18a0dea6b4a10046e3b50d6ab910868c4c52574- SHA-256
17f0487ceadb25c4d72e3861ab850c601ac0c4c09a54b103c9074ca86014f4f0- First indexed
- 2022-06-20 23:15:07
- Last updated
- 2025-09-23 23:02:41
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.Multi.Generic.4!c |
| Elastic | malicious (high confidence) |
| FireEye | VBA:Amphitryon.1454 |
| Alibaba | Trojan:Office/Shelod.f5cdda21 |
| Cyren | ABRisk.DOTG-0 |
| ESET-NOD32 | VBA/Agent.AEY |
| Avast | VBA:Obfuscated-AH [Cryp] |
| Kaspersky | UDS:DangerousObject.Multi.Generic |
| BitDefender | VBA:Amphitryon.1454 |
| DrWeb | Trojan.Siggen18.6702 |
| McAfee-GW-Edition | X97M/Downloader.pf |
| Emsisoft | VBA:Amphitryon.1454 (B) |
| SentinelOne | Static AI - Malicious OPENXML |
| Avira | VBA/Agent.rdqlx |
| Microsoft | Trojan:O97M/Sadoca.C!ml |
| ViRobot | DOC.Z.Agent.2748010 |
| GData | VBA:Amphitryon.1454 |
| Cynet | Malicious (score: 99) |
| AhnLab-V3 | Dropper/MSOffice.Generic |
| Acronis | suspicious |
| MAX | malware (ai score=89) |
| Rising | Malware.Obfus/[email protected] (VBA) |
| Yandex | Trojan.Mofer.bYcXwf.1 |
| Fortinet | VBA/Agent.DXB!tr |
| AVG | VBA:Obfuscated-AH [Cryp] |