f7fa22f3710cd7906a268081b51e34784be3798ed94dcef9cd7562707c5db608.doc
Classification: Malicious
f7fa22f3710cd7906a268081b51e34784be3798ed94dcef9cd7562707c5db608.doc is a malicious file sample. Linked to Invisimole malware.
Detection summary
- 56 antivirus detections (35% detection ratio)
- 0 IDS alerts
- 2 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Invisimole |
Maltiverse |
2023-03-31 04:13:54 |
2023-04-01 00:17:32 |
malicious-activity
|
S0260 InvisiMole
|
| Ghostwriter |
Maltiverse |
2023-03-31 04:13:54 |
2023-04-01 00:17:26 |
malicious-activity
|
|
| VB.Chartres.1 |
Hybrid-Analysis |
2020-07-16 10:45:25 |
2020-07-16 10:45:25 |
|
|
Sample information
- Filenames
- f7fa22f3710cd7906a268081b51e34784be3798ed94dcef9cd7562707c5db608.doc
- File type
- Microsoft Word 2007+
- Size
- 5280423 bytes
- MD5
980d6c8bdcd52b3dfa9573e3d4dd21e5
- SHA-1
974bfeaffaea42fbb3eb82184309a278cfc885d9
- SHA-256
f7fa22f3710cd7906a268081b51e34784be3798ed94dcef9cd7562707c5db608
- First indexed
- 2020-07-16 10:45:25
- Last updated
- 2026-04-12 03:21:55
Antivirus detections
| Engine | Detection |
| MicroWorld-eScan | VB.Chartres.1.Gen |
| Alibaba | TrojanDownloader:VBA/MalDoc.ali1000101 |
| Arcabit | VB.Chartres.1.Gen |
| Cyren | Trojan.VITW-7 |
| Avast | Other:Malware-gen [Trj] |
| Kaspersky | HEUR:Trojan-Dropper.MSOffice.SDrop.gen |
| BitDefender | VB.Chartres.1.Gen |
| Ad-Aware | VB.Chartres.1.Gen |
| F-Secure | Malware.W97M/Drop.SDrop.jwpry |
| FireEye | VB.Chartres.1.Gen |
| Emsisoft | VB.Chartres.1.Gen (B) |
| Ikarus | Trojan-Downloader.VBA.Agent |
| Avira | word/vbaProject.bin |
| Microsoft | TrojanDownloader:O97M/Tnega.RA!MTB |
| Endgame | malicious (high confidence) |
| ZoneAlarm | HEUR:Trojan-Dropper.MSOffice.SDrop.gen |
| GData | VB.Chartres.1.Gen |
| Cynet | Malicious (score: 85) |
| Rising | Dropper.Agent/VBA!1.C602 (CLASSIC) |
| SentinelOne | DFI - Malicious OPENXML |
| Fortinet | VBA/Agent.98AE!tr |
| AVG | Other:Malware-gen [Trj] |
| ALYac | Trojan.Downloader.DOC.Gen |
| AhnLab-V3 | Dropper/DOC.Lazarus.S1277 |
| Antiy-AVL | Trojan[APT]/MSOffice.Lazarus |
| Arcabit | HEUR.VBA.Trojan.d |
| Avira | HEUR/Macro.Downloader.MRACV.Gen |
| BitDefender | VB:Trojan.Valyria.7020 |
| CAT-QuickHeal | O97M.Downloader.40479 |
| CTX | docx.trojan.valyria |
| ClamAV | Win.Malware.Agent-9378641-0 |
| Cynet | Malicious (score: 99) |
| DrWeb | W97M.Dropper.128 |
| ESET-NOD32 | a variant of VBA/TrojanDropper.Agent.BIT |
| Elastic | malicious (high confidence) |
| Emsisoft | VB:Trojan.Valyria.7020 (B) |
| F-Secure | Heuristic.HEUR/Macro.Downloader.MRACV.Gen |
| GData | VB:Trojan.Valyria.7020 |
| Google | Highly Suspicious |
| Ikarus | Trojan-Dropper.VBA.Agent |
| Kaspersky | UDS:DangerousObject.Multi.Generic |
| Kingsoft | Win32.Troj.Undef.a |
| Lionic | Trojan.MSWord.Valyria.4!c |
| MicroWorld-eScan | VB:Trojan.Valyria.7020 |
| Rising | Dropper.[Lazarus]Agent/VBA!1.C602 (CLASSIC) |
| Sangfor | Malware.Generic-Macro.Save.38503260 |
| SentinelOne | Static AI - Malicious OPENXML |
| Skyhigh | X97M/Dropper.ag |
| Symantec | W97M.Downloader |
| TACHYON | Suspicious/WOX.DRP.Gen |
| Tencent | Trojan.MsOffice.MacroS.11027010 |
| TrellixENS | X97M/Dropper.ag |
| VIPRE | VB:Trojan.Valyria.7020 |
| Varist | PP97M/Chartres.A.gen!Eldorado |
| ViRobot | W97M.S.Agent.5280423 |
| huorong | TrojanSpy/VBS.Stealer.d |
Process list
| Name | Command line |
| WINWORD.EXE | /n "C:\f7fa22f3710cd7906a268081b51e34784be3798ed94dcef9cd7562707c5db608.doc" |
| WINWORD.EXE | /Automation -Embedding |