Report - PO 825468.xls

VBA_macro Malicious Packer MSOffice File
ScreenShot
Created 2021.06.03 09:19 Machine s1_win7_x6401
Filename PO 825468.xls
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Titl
AI Score Not founds Behavior Score
5.0
ZERO API file : clean
VT API (file) 22 detected (malicious, moderate confidence, Valyria, Eldorado, OLE2, Dridex, ai score=81, Probably Heur, W97Obfuscated, ObfusVBA@ML, Static AI, Suspicious OLE)
md5 d24d609e6ac612f69030bfc3695e6aad
sha256 7b14612ff42c9c8e8abdc45ca2d55abf3ccb523e5787e62b91a2cf2c2a289890
ssdeep 24576:WWGuTsXFlLsNPVoAMoWJaCgzYiDomDZqYYS8:ZGuT6nutdNWJaCgHDogeS8
imphash
impfuzzy
  Network IP location

Signature (7cnts)

Level Description
danger The process excel.exe wrote an executable file to disk which it then attempted to execute
danger Office document performs HTTP request (possibly to download malware)
warning File has been identified by 22 AntiVirus engines on VirusTotal as malicious
watch Creates suspicious VBA object
watch One or more non-whitelisted processes were created
notice Allocates read-write-execute memory (usually to unpack itself)
notice Performs some HTTP requests

Rules (3cnts)

Level Name Description Collection
warning Contains_VBA_macro_code Detect a MS Office document with embedded VBA macro code [binaries] binaries (upload)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)

Network (10cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
https://arboretsens72.fr/wp-content/themes/twentyseventeen/template-parts/footer/X8FJlzkyXi8ixjn.php FR OVH SAS 5.135.136.199 clean
https://zabalit.com/wp-content/plugins/wordpress-seo/css/dist/3IR10ztB.php ES 1&1 Ionos Se 82.223.12.53 clean
bwcreativestudio.com SG OVH SAS 51.79.223.113 clean
sunshineserviceproviders.com US UNIFIEDLAYER-AS-1 192.185.145.128 clean
zabalit.com ES 1&1 Ionos Se 82.223.12.53 clean
arboretsens72.fr FR OVH SAS 5.135.136.199 clean
82.223.12.53 ES 1&1 Ionos Se 82.223.12.53 clean
51.79.223.113 SG OVH SAS 51.79.223.113 clean
5.135.136.199 FR OVH SAS 5.135.136.199 clean
192.185.145.128 US UNIFIEDLAYER-AS-1 192.185.145.128 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure