bikealma_document_20.06.2022.doc

Classification: Malicious

bikealma_document_20.06.2022.doc is a malicious file sample. Linked to Svcready malware. Reported by 1 threat source, last seen 2022-06-20.

Detection summary

  • 25 antivirus detections
  • 0 IDS alerts
  • 0 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: SVCREADY (S1064)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
SVCReady MalwareBazaar Abuse.ch 2022-06-20 21:20:30 2022-06-20 21:20:30 malicious-activity S1064 SVCReady

Sample information

Filenames
bikealma_document_20.06.2022.doc
File type
application/zip
MD5
e2237eac90e20fe703806ad6b8221597
SHA-1
e18a0dea6b4a10046e3b50d6ab910868c4c52574
SHA-256
17f0487ceadb25c4d72e3861ab850c601ac0c4c09a54b103c9074ca86014f4f0
First indexed
2022-06-20 23:15:07
Last updated
2025-09-23 23:02:41

Antivirus detections

EngineDetection
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
FireEyeVBA:Amphitryon.1454
AlibabaTrojan:Office/Shelod.f5cdda21
CyrenABRisk.DOTG-0
ESET-NOD32VBA/Agent.AEY
AvastVBA:Obfuscated-AH [Cryp]
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderVBA:Amphitryon.1454
DrWebTrojan.Siggen18.6702
McAfee-GW-EditionX97M/Downloader.pf
EmsisoftVBA:Amphitryon.1454 (B)
SentinelOneStatic AI - Malicious OPENXML
AviraVBA/Agent.rdqlx
MicrosoftTrojan:O97M/Sadoca.C!ml
ViRobotDOC.Z.Agent.2748010
GDataVBA:Amphitryon.1454
CynetMalicious (score: 99)
AhnLab-V3Dropper/MSOffice.Generic
Acronissuspicious
MAXmalware (ai score=89)
RisingMalware.Obfus/[email protected] (VBA)
YandexTrojan.Mofer.bYcXwf.1
FortinetVBA/Agent.DXB!tr
AVGVBA:Obfuscated-AH [Cryp]