We are thrilled to announce that InQuest has been acquired by OPSWAT. Read more.
Overview
Malicious
application/vnd.openxmlformats-officedocument.wordprocessingml.document
16dfd825ff1a23bddc22ed840d6d2c41
ad0dab25de5739a6b645f1f29e996f0ef85e85cf
797ad98c5e34adaf78da488638b1bfe724d2750844e2d67725b0e84a2aa14c06
b6611ba260578d3326c374979f1e2cf88f04c7017ce4e34f9f86b16b46d83dc11b32d522d3df5b179724e39af6ca730fbffc7e8e970494296ff6c2b292743af3
100,927B
376,312B (272.86% increase in inspectable content)
2022-08-26 03:56:26
2022-08-26 03:57:12
2022-08-26 03:57:04
Machine Learning
InQuest ML Classifier Unknown
Heuristics
External Relationship ElementDocument contains an externally hosted relationship, which fetches further content.
Macro Execution Coercion in ImageDetected an image that appears to social engineer the user into activating embedded logic.
Deep File Inspection (DFI) Layers
Optical Character Recognition (907B)
  • 1T|2022|mW,..ftd l;IN1tC11t1ty Sll,MI l:ll.U_,..w4C'l.
  • 2 
  • 3Lode., Cleo to99 ,.._.,~,,|bb|
  • 4 
  • 5T ...... ~.t/1"'
  • 6 
  • 7PURCHASE ORDER
  • 8 
  • 9ore Ma
  • 10 
  • 114gt Geway D
  • 12 
  • 131 ....... Aw-~
  • 14 
  • 15-
  • 16 
  • 17-:-
  • 18 
  • 19to 4@9712
  • 20 
  • 21-OAffe Olil'-'!OIS T'nblr,,'f(<do--y$dloo)I
  • 22 
  • 23, ..
  • 24 
  • 2512 Matot Loadfflwoed,C......,_
  • 26 
  • 27-- -- --
  • 28 ""' I - I O&OVb)I)
  • 29
  • 30- -|b7| - -- --
  • 31- 12 '-" .... ......
  • 32.. """ o .. ., ... $1.0.00
  • 33"- .,,.. to9ypaper su .... ,.,. ..
  • 34' ta a22 ,_ .. ,.., $.2 ..... ,
  • 35 SICI0.00
  • 36 """
  • 37' "'
  • 38 "'"'
  • 39---
  • 40Office
  • 41 
  • 42|bb|
  • 43 
  • 44Open the document in Microsoft Office. Previewing online is not available for protected documents
  • 45 
  • 46This document is protected
  • 47 
  • 48c|bb|
  • 49 
  • 50If this document was downloaded from your email, please click "Enable Editing" from the yellow bar above
Metadata (1.5KB)
  • 1File Size : 52 kB
  • 2File Modification Date/Time : 2022:08:26 03:56:42+00:00
  • 3File Access Date/Time : 2022:08:26 03:56:46+00:00
  • 4File Inode Change Date/Time : 2022:08:26 03:56:45+00:00
  • 5File Permissions : rw-rwxrw-
  • 6File Type : PNG
  • 7File Type Extension : png
  • 8MIME Type : image/png
  • 9Image Width : 360
  • 10Image Height : 469
  • 11Bit Depth : 8
  • 12Color Type : RGB
  • 13Compression : Deflate/Inflate
  • 14Filter : Adaptive
  • 15Interlace : Noninterlaced
  • 16Gamma : 2.2
  • 17White Point X : 0.31269
  • 18White Point Y : 0.32899
  • 19Red X : 0.63999
  • 20Red Y : 0.33001
  • 21Green X : 0.3
  • 22Green Y : 0.6
  • 23Blue X : 0.15
  • 24Blue Y : 0.05999
  • 25Background Color : 255 255 255
  • 26Pixels Per Unit X : 2835
  • 27Pixels Per Unit Y : 2835
  • 28Pixel Units : meters
  • 29Modify Date : 2016:05:16 21:17:30
  • 30Datecreate : 2016-05-16T21:17:30+00:00
  • 31Datemodify : 2016-05-16T21:17:30+00:00
  • 32Image Size : 360x469
  • 33Megapixels : 0.169
  • 34 
  • 35---
IOCs
looks like: domain
mygreatlearning.com
looks like: filename
42d9f9b97273cd1696af1452b4858f52.png image2.png
looks like: filepath
i:\TT
looks like: url
https://mygreatlearning.com@gbd.life/fc
API Request
  • 1curl "https://labs.inquest.net/api/dfi/summary?sha256=797ad98c5e34adaf78da488638b1bfe724d2750844e2d67725b0e84a2aa14c06"
Attributes API Request
  • 1curl "https://labs.inquest.net/api/dfi/details/attributes?sha256=797ad98c5e34adaf78da488638b1bfe724d2750844e2d67725b0e84a2aa14c06"
Copied to clipboard.
1333 free API requests remaining
Sign (Up|In) for a free API key.
Sign (Up|In) for a free API key.
Content is too long to search. Try selecting a smaller section or filtering it down.
Content is too long to search. Try selecting a smaller section or filtering it down.
Content is too long to search. Try selecting a smaller section or filtering it down.
Content is too long to search. Try selecting a smaller section or filtering it down.