Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
VirusTotal += Docguard
#1
Information 
Quote:
[Image: Logo_VT_Horizontal.png]

We are excited to announce our integration with DOCGuard for the analysis of Office documents, PDFs and other file types as a behavioral analysis engine. This document analysis collaboration will allow the community to get the another opinion on the scanned documents. 

In their own words:
 
Quote:DOCGuard is a malware analysis service, whose main use case is to integrate with SEGs (Secure Email Gateways) and SOAR solutions.
 
Quote:The service performs a new kind of static analysis called structural analysis. The structural analysis dissembles the malwares and passes it to the core engines with respect to file structure components. By the aid of this approach, DOCGuard can precisely detect the malwares and extract the F/P free IOCs and may also identify obfuscation and encryption in the form of string encoding and document encryption.
 
Quote:The currently supported file types are Microsoft Office Files, PDFs, HTMLs, HTMs, LNKs, JScripts, ISOs, IMGs, VHDs, VCFs, and archives(.zip, .rar, .7z etc.). The detailed findings of the structural analysis are presented in an aggregated view in the GUI and can be downloaded as a JSON report and can also be gathered over API.

Going further, users can explore the behavior tab of the file scanned for more details. In the example below, we see a detected macro of a malicious Excel XLS file
 
[Image: docguard-2d6.png]


In a malicious document, we can see memory pattern urls.

9cd785dbcceced90590f87734b8a3dbc066a26bd90d4e4db9a480889731b6d29 
[Image: docguard-memory-urls.png]...
Reply


Messages In This Thread
VirusTotal += Docguard - by harlan4096 - 21 June 23, 08:47

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
VPN brand brings transparent toilet to t...
VPN provider Surfs...Rotem — 15:57
Movies! Movies!
Godzilla x Kong: T...jAcos — 13:44
Microsoft is testing Game Pass ads on th...
Look, another adve...harlan4096 — 11:23
Notepad++ 8.6.7
Notepad++ 8.6.7: ...harlan4096 — 09:23
GFYI [Official] Ashampoo Snap 16 Giveaw...
Thank you and congra...mjcn19 — 03:33

[-]
Birthdays
Today's Birthdays
avatar (43)tiojusop
avatar (40)Damiennug
avatar (38)acoraxe
Upcoming Birthdays
avatar (26)akiratoriyama
avatar (46)Jerrycix
avatar (38)awedoli
avatar (80)WinRARHowTo
avatar (37)axuben
avatar (38)ihijudu
avatar (47)contjrat
avatar (42)knigiJow
avatar (44)1stOnecal
avatar (48)Mirzojap
avatar (34)idilysaju
avatar (38)GregoryRog
avatar (43)mediumog
avatar (38)odukoromu
avatar (44)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>