Report - diagram-58895225.xls

MSOffice File
ScreenShot
Created 2021.05.18 09:56 Machine s1_win7_x6401
Filename diagram-58895225.xls
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Autho
AI Score Not founds Behavior Score
2.6
ZERO API file : clean
VT API (file) 15 detected (a variant of VBA, Artemis, ai score=80, EncDoc, Nastya)
md5 16ec6ae1941a5f788d18aa6673be5fee
sha256 2bafd475672e6b1f42edf45d4a2829688b9bc1b46b87fe501b0a9a10c5fd10ba
ssdeep 6144:IcPiNQApW/89bK103eGvgZqr3h8GB3ckt6Uqa5DPdG9uS9QLn4z8yOj:ut6Uqa5DPdG9uS9QLn4z8j
imphash
impfuzzy
  Network IP location

Signature (6cnts)

Level Description
watch File has been identified by 15 AntiVirus engines on VirusTotal as malicious
watch Network communications indicative of a potential document or script payload download was initiated by the process excel.exe
watch One or more non-whitelisted processes were created
notice Allocates read-write-execute memory (usually to unpack itself)
info Checks amount of memory in system
info One or more processes crashed

Rules (1cnts)

Level Name Description Collection
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)

Network (2cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
hermescomm.net US UNIFIEDLAYER-AS-1 162.241.27.24 mailcious
162.241.27.24 US UNIFIEDLAYER-AS-1 162.241.27.24 suspicious

Suricata ids



Similarity measure (PE file only) - Checking for service failure