isifim-invoice-12.05.doc
Classification: Malicious
isifim-invoice-12.05.doc is a malicious file sample. Linked to Svcready malware. Reported by 1 threat source, last seen 2022-06-07.
Detection summary
- 37 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: SVCREADY (S1064)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| SVCReady | MalwareBazaar Abuse.ch | 2022-06-07 11:22:53 | 2022-06-07 11:22:53 | malicious-activity | S1064 SVCReady |
| Generic.Malware | MalwareBazaar Abuse.ch | 2022-06-07 11:22:53 | 2022-06-07 11:22:53 | malicious-activity |
Sample information
- Filenames
- isifim-invoice-12.05.doc
- File type
- application/zip
- MD5
32b15e5d5a507f0b8096fdea8e8df03c- SHA-1
fa008acb8bbf7e3e0763170e94be73362918e006- SHA-256
99df2cc2535c82b84ba23384df290d7506242532123d8414c1cfc61967072c28- First indexed
- 2022-06-07 13:15:17
- Last updated
- 2026-05-03 02:30:40
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.Multi.Generic.4!c |
| Elastic | malicious (high confidence) |
| McAfee | W97M/Downloader.dvi |
| Alibaba | Trojan:Office/Shelod.7a189059 |
| Cyren | ABRisk.BAGD-2 |
| ESET-NOD32 | VBA/Agent.AEY |
| TrendMicro-HouseCall | Trojan.VBS.SHELOD.VSNW08F22 |
| Avast | Script:SNH-gen [Trj] |
| Kaspersky | UDS:DangerousObject.Multi.Generic |
| BitDefender | Trojan.GenericKD.49136691 |
| ViRobot | DOC.Z.Agent.2662127 |
| TrendMicro | Trojan.VBS.SHELOD.VSNW08F22 |
| McAfee-GW-Edition | Artemis!Trojan |
| FireEye | Trojan.GenericKD.49136691 |
| GData | Trojan.GenericKD.49136691 |
| Microsoft | Trojan:O97M/Donoff!MSR |
| Arcabit | HEUR.VBA.CG.1 |
| Acronis | suspicious |
| MAX | malware (ai score=82) |
| Rising | Malware.Obfus/[email protected] (VBA) |
| SentinelOne | Static AI - Malicious OPENXML |
| Fortinet | VBA/Agent.DXB!tr |
| AVG | Script:SNH-gen [Trj] |
| AVG | VBA:Obfuscated-AH [Cryp] |
| Ad-Aware | Trojan.GenericKD.49136691 |
| AhnLab-V3 | Dropper/MSOffice.Generic |
| Avast | VBA:Obfuscated-AH [Cryp] |
| Avira | VBA/Agent.egvkc |
| CAT-QuickHeal | Ole.Trojan.A5665225 |
| Cynet | Malicious (score: 99) |
| Cyren | PP97M/Dloader.L |
| DrWeb | Trojan.Siggen18.6702 |
| Emsisoft | Trojan.GenericKD.49136691 (B) |
| Kingsoft | Win32.Troj.Archived.jm.(kcloud) |
| McAfee-GW-Edition | W97M/Downloader.dvi |
| MicroWorld-eScan | Trojan.GenericKD.49136691 |
| Tencent | Trojan.MsOffice.MacroS.12450034 |