Report - catalog-1546008837.xlsm

ScreenShot
Created 2021.05.01 09:16 Machine s1_win7_x6402
Filename catalog-1546008837.xlsm
Type Microsoft Excel 2007+
AI Score Not founds Behavior Score
3.8
ZERO API file : clean
VT API (file) 6 detected (XLSM, Sneaky, Camelot)
md5 37b83bacfc6b313270f925e32e5fde4d
sha256 eda51f3985e926823f5343aa69faaca3f0dd97c659acdbc0b1df68aaf06f5a6c
ssdeep 3072:CmIxNUlpIfw8SGopH8x+iHdoLqp6vif+zUD:CmIr4Ga8x7HdLp6vif+zUD
imphash
impfuzzy
  Network IP location

Signature (9cnts)

Level Description
watch Communicates with host for which no DNS query was performed
watch Network communications indicative of a potential document or script payload download was initiated by the process excel.exe
watch One or more non-whitelisted processes were created
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates (office) documents on the filesystem
notice Creates hidden or system file
notice File has been identified by 6 AntiVirus engines on VirusTotal as malicious
info Checks amount of memory in system
info One or more processes crashed

Rules (0cnts)

Level Name Description Collection

Network (4cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
legalopspr.com US UNIFIEDLAYER-AS-1 192.185.20.98 mailcious
dentistelmhurstny.com US UNIFIEDLAYER-AS-1 192.185.5.2 mailcious
192.185.20.98 US UNIFIEDLAYER-AS-1 192.185.20.98 phishing
192.185.5.2 US UNIFIEDLAYER-AS-1 192.185.5.2 malware

Suricata ids



Similarity measure (PE file only) - Checking for service failure