Report - Fattura_01120879.xlsm

VBA_macro
ScreenShot
Created 2021.05.12 10:13 Machine s1_win7_x6402
Filename Fattura_01120879.xlsm
Type Microsoft Excel 2007+
AI Score Not founds Behavior Score
2.4
ZERO API file : clean
VT API (file) 11 detected (Office97, Eldorado, VSNTEB21, Ursnif)
md5 5bcdab4ff6b87ec09850a81bb992a58f
sha256 e98abe41124d07ab54cb2bf7115e61beb856eb7b82872e0a1bd79735bf8b8259
ssdeep 768:F7Wjul2WJdPXCpPyFNgQA9B0r6u3kWkH+9dN3qGZFIsQHSIzBlOfelYU5qdc6Z8S:BWjgPqpqAD02JWke9/3qsQyIz9YUMdJd
imphash
impfuzzy
  Network IP location

Signature (5cnts)

Level Description
watch Communicates with host for which no DNS query was performed
watch File has been identified by 11 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates (office) documents on the filesystem
notice Creates hidden or system file

Rules (1cnts)

Level Name Description Collection
warning Contains_VBA_macro_code Detect a MS Office document with embedded VBA macro code [binaries] binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure