tuttoverdeshop-file-25.05.2022.doc
Classification: Malicious
tuttoverdeshop-file-25.05.2022.doc is a malicious file sample. Linked to Svcready malware. Reported by 1 threat source, last seen 2022-06-07.
Detection summary
- 48 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: SVCREADY (S1064)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| SVCReady | MalwareBazaar Abuse.ch | 2022-06-07 11:19:05 | 2022-06-07 11:19:05 | malicious-activity | S1064 SVCReady |
| Generic.Malware | MalwareBazaar Abuse.ch | 2022-06-07 11:19:05 | 2022-06-07 11:19:05 | malicious-activity |
Sample information
- Filenames
- tuttoverdeshop-file-25.05.2022.doc
- File type
- application/zip
- MD5
90ee378b87e7c35dd4a4272ee0bb9127- SHA-1
462db6506076e6085a47539b80dbb15050addf22- SHA-256
c24266cc16d65f0b8d72bb7df80a6b2ffe343429a764afb9fb0a9c20d53ab9af- First indexed
- 2022-06-07 13:15:18
- Last updated
- 2025-11-09 03:33:02
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.MSOffice.Shelod.4!c |
| Elastic | malicious (high confidence) |
| McAfee | RDN/GenericOLE |
| Alibaba | Trojan:Office/Shelod.0affedbd |
| Cyren | ABRisk.EYWN-7 |
| ESET-NOD32 | VBA/Agent.AEY |
| Avast | SNH:Script [Dropper] |
| Kaspersky | UDS:DangerousObject.Multi.Generic |
| ViRobot | DOC.Z.Agent.2687322 |
| McAfee-GW-Edition | Artemis!Trojan |
| Microsoft | Trojan:Script/Wacatac.B!ml |
| Arcabit | HEUR.VBA.CG.1 |
| Acronis | suspicious |
| Rising | Malware.Obfus/[email protected] (VBA) |
| SentinelOne | Static AI - Malicious OPENXML |
| Fortinet | VBA/Agent.DXB!tr |
| AVG | SNH:Script [Dropper] |
| ALYac | Trojan.Downloader.DOC.Gen |
| AVG | VBA:Obfuscated-AH [Cryp] |
| AhnLab-V3 | Dropper/MSOffice.Generic |
| Antiy-AVL | Trojan/Macro.Agent |
| Avast | VBA:Obfuscated-AH [Cryp] |
| Avira | HEUR/Macro.Downloader |
| BitDefender | Trojan.GenericKD.49136641 |
| CTX | docx.trojan.w97m |
| ClamAV | Doc.Downloader.SVCReady-c5c43a913b3eccc9-9953477-0 |
| Cynet | Malicious (score: 99) |
| DrWeb | Trojan.Siggen18.6702 |
| Emsisoft | Trojan.GenericKD.49136641 (B) |
| F-Secure | Heuristic.HEUR/Macro.Downloader |
| Fortinet | VBA/Agent.PF!tr |
| GData | Trojan.GenericKD.49136641 |
| Highly Suspicious | |
| Ikarus | Trojan-Downloader.PS.Agent |
| Kingsoft | Win32.Troj.Archived.jm |
| Lionic | Trojan.MSWord.Shelod.4!c |
| MicroWorld-eScan | Trojan.GenericKD.49136641 |
| Skyhigh | W97M/Downloader.dvi |
| Symantec | W97M.Downloader |
| TACHYON | Suspicious/WOX.Obfus.Gen |
| Tencent | Trojan.MsOffice.MacroS.11021700 |
| TrellixENS | W97M/Downloader.dvi |
| TrendMicro | Trojan.W97M.SVCREADY.YPCFH |
| TrendMicro-HouseCall | Trojan.W97M.SVCREADY.YPCFH |
| VIPRE | Trojan.GenericKD.49136641 |
| Varist | PP97/Dloader.J |
| alibabacloud | Trojan:MSOffice/Donoff.Gen |
| huorong | HEUR:OMacro/Obfuscated.x |