× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 5ff7c57adfe4055d36f0c021d9ac93f178134b92541dcf8a61ca94ca513ac183
File name: noreply@ubuntu.si_20170731_802065.doc
Detection ratio: 0 / 58
Analysis date: 2017-07-31 14:27:59 UTC ( 5 months, 1 week ago ) View latest
Antivirus Result Update
Ad-Aware 20170731
AegisLab 20170731
AhnLab-V3 20170731
Alibaba 20170731
ALYac 20170731
Antiy-AVL 20170731
Arcabit 20170731
Avast 20170731
AVG 20170731
Avira (no cloud) 20170731
AVware 20170731
Baidu 20170728
BitDefender 20170731
Bkav 20170731
CAT-QuickHeal 20170731
ClamAV 20170731
CMC 20170731
Comodo 20170731
CrowdStrike Falcon (ML) 20170710
Cylance 20170731
Cyren 20170731
DrWeb 20170731
Emsisoft 20170731
Endgame 20170721
ESET-NOD32 20170731
F-Prot 20170731
F-Secure 20170731
Fortinet 20170731
GData 20170731
Ikarus 20170731
Sophos ML 20170607
Jiangmin 20170731
K7AntiVirus 20170731
K7GW 20170731
Kaspersky 20170731
Kingsoft 20170731
Malwarebytes 20170731
MAX 20170731
McAfee 20170731
McAfee-GW-Edition 20170731
Microsoft 20170731
eScan 20170731
NANO-Antivirus 20170731
nProtect 20170731
Palo Alto Networks (Known Signatures) 20170731
Panda 20170731
Qihoo-360 20170731
Rising 20170731
SentinelOne (Static ML) 20170718
Sophos AV 20170731
SUPERAntiSpyware 20170731
Symantec 20170731
Symantec Mobile Insight 20170730
Tencent 20170731
TheHacker 20170730
TrendMicro 20170731
TrendMicro-HouseCall 20170731
Trustlook 20170731
VBA32 20170731
VIPRE 20170731
ViRobot 20170731
Webroot 20170731
WhiteArmor 20170731
Yandex 20170728
Zillya 20170731
ZoneAlarm by Check Point 20170731
Zoner 20170731
The file being studied follows the Compound Document File format! More specifically, it is a MS Word Document file.
OLE Streams
name
Root Entry
clsid
type_literal
root
clsid_literal
on
sid
0
size
1920
type_literal
stream
size
64
name
\x06DataSpaces/DataSpaceInfo/StrongEncryptionDataSpace
sid
6
type_literal
stream
size
112
name
\x06DataSpaces/DataSpaceMap
sid
4
type_literal
stream
size
200
name
\x06DataSpaces/TransformInfo/StrongEncryptionTransform/\x06Primary
sid
9
type_literal
stream
size
76
name
\x06DataSpaces/Version
sid
3
type_literal
stream
size
50952
name
EncryptedPackage
sid
1
type_literal
stream
size
1289
name
EncryptionInfo
sid
10
ExifTool file metadata
MIMEType
image/vnd.fpx

FileType
FPX

FileTypeExtension
fpx

File identification
MD5 c1bf2fcb24adfeb7265286bc1cfb47b4
SHA1 dbb2020e18300f8ccdbd33e9a672393df62ab27f
SHA256 5ff7c57adfe4055d36f0c021d9ac93f178134b92541dcf8a61ca94ca513ac183
ssdeep
768:BkIfFAqjlXO6FJjn+T6ptpMyRA/l+6akfrVNSRwbeqfJaE/NHjuSU4WIQvvC3:BkIfKqZVF1n+BhdpJaq8SUrIGvC3

File size 56.5 KB ( 57856 bytes )
File type MS Word Document
Magic literal
Cannot read summary info

TrID Generic OLE2 / Multistream Compound File (100.0%)
Tags
doc attachment

VirusTotal metadata
First submission 2017-07-31 13:12:08 UTC ( 5 months, 1 week ago )
Last submission 2017-09-21 06:44:19 UTC ( 3 months, 3 weeks ago )
File names noreply@striata.com_20170731_265501.doc
noreply_20170731_135505.doc
noreply@rola-spirits.de_20170731_605011.doc
noreply@wohnbedarf.ch_20170731_004535.doc
noreply@simpronet.com_20170731_750151.doc
noreply@wge.im_20170731_333035.doc
noreply@molinorosso.com_20170731_514461.doc
infected.doc
noreply@kohlhammerdruck.de_20170731_388603.doc
c1bf2fcb24adfeb7265286bc1cfb47b4
noreply@schwager.de_20170731_843562.doc
20170731_637468.doc
noreply@carboncore.de_20170731_097063.doc
noreply@hetzerei.woas.net_20170731_197144.doc
noreply@ubuntu.si_20170731_802065.doc
noreply@cdubitterfeld.de_20170731_099890.doc
noreply@uvm.edu_20170731_777279.doc
noreply@fiemme3000.it_20170731_987639.doc
noreply@st-irmingard.de_20170731_903376.doc
noreply@airliquide.com_20170731_499269.doc
4fa94abbdd2375a70cd8155e7c9513b8fb1a8787
noreply@mwfreight.co.uk_20170731_347818.doc
noreply@mauerbach.gv.at_20170731_312139.doc
noreply@komfort.hu_20170731_062532.doc
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!