Report - Inv%2004256248.xls

VBA_macro MSOffice File
ScreenShot
Created 2021.06.03 20:55 Machine s1_win7_x6401
Filename Inv%2004256248.xls
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title
AI Score Not founds Behavior Score
3.2
ZERO API file : clean
VT API (file) 21 detected (malicious, high confidence, Valyria, Eldorado, ObfusVBA@ML, OLE2, Static AI, Suspicious OLE, Sadoca, ai score=87, Probably Heur, W97Obfuscated)
md5 10a6370bb359ff9f3a595c3ad389222c
sha256 d605724b31d8627ffbf203ec7d917cb70019e6c95d0c501a7136f7e2b72b79bb
ssdeep 12288:HspCOElpb+2pUpkNXu5d3QB2RNv+ot0N8Mx6jKe3bhjWWiMLRwD:H5pjNQxE2RNvBt0N8fjKe4WikU
imphash
impfuzzy
  Network IP location

Signature (5cnts)

Level Description
danger Office document performs HTTP request (possibly to download malware)
warning File has been identified by 21 AntiVirus engines on VirusTotal as malicious
watch Creates suspicious VBA object
notice Allocates read-write-execute memory (usually to unpack itself)
notice Performs some HTTP requests

Rules (2cnts)

Level Name Description Collection
warning Contains_VBA_macro_code Detect a MS Office document with embedded VBA macro code [binaries] binaries (upload)
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)

Network (22cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
https://menuiserie-lemoine.bzh/wp-content/themes/twentynineteen/template-parts/content/x0XxEHWGdeyPBEj.php FR OVH SAS 188.165.53.185 mailcious
https://tineo.gal/wp-content/plugins/wordpress-seo/vendor/composer/installers/tests/Composer/Installers/lSNBjeKdHn.php ES DinaHosting S.L. 82.98.169.3 mailcious
kweraltd.com CA OVH SAS 54.39.133.15 mailcious
ootashop.com US NAMECHEAP-NET 199.188.205.57 mailcious
labrie-sabette.com US ASACENET1 173.230.252.50 mailcious
thelottery.io US DIGITALOCEAN-ASN 138.68.242.172 mailcious
menuiserie-lemoine.bzh FR OVH SAS 188.165.53.185 mailcious
shantijoseph.com GB Paragon Internet Group Limited 87.247.240.31 mailcious
vitiligomatch.com US UNIFIEDLAYER-AS-1 192.185.16.122 mailcious
srivinaysalian.com US None 216.37.42.46 mailcious
abidshakir.co.uk DE Contabo GmbH 62.171.164.209 mailcious
tineo.gal ES DinaHosting S.L. 82.98.169.3 mailcious
192.185.16.122 US UNIFIEDLAYER-AS-1 192.185.16.122 mailcious
188.165.53.185 FR OVH SAS 188.165.53.185 mailcious
216.37.42.46 US None 216.37.42.46 mailcious
82.98.169.3 ES DinaHosting S.L. 82.98.169.3 mailcious
87.247.240.31 GB Paragon Internet Group Limited 87.247.240.31 mailcious
54.39.133.15 CA OVH SAS 54.39.133.15 mailcious
138.68.242.172 US DIGITALOCEAN-ASN 138.68.242.172 mailcious
173.230.252.50 US ASACENET1 173.230.252.50 mailcious
199.188.205.57 US NAMECHEAP-NET 199.188.205.57 mailcious
62.171.164.209 DE Contabo GmbH 62.171.164.209 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure