Report - research-453468889.xlsm

ScreenShot
Created 2021.06.11 12:32 Machine s1_win7_x6402
Filename research-453468889.xlsm
Type Microsoft Excel 2007+
AI Score Not founds Behavior Score
4.8
ZERO API file : clean
VT API (file)
md5 11465058b522cd71f419238bd897a2f1
sha256 48effc21ccb3c741305df3e4a886c96429375856d6591bf1603caf90d405c657
ssdeep 3072:rLmZz+X+dDdTkdm3bGeAxidxVymd1xXPMU9VlUBWA6CFvA7bRCxAVIKDbAX:38TkeGKdxVyWxfMU3liWA6FsYE
imphash
impfuzzy
  Network IP location

Signature (9cnts)

Level Description
danger Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually)
watch Communicates with host for which no DNS query was performed
watch Network communications indicative of a potential document or script payload download was initiated by the process excel.exe
watch One or more non-whitelisted processes were created
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates (office) documents on the filesystem
notice Creates a suspicious process
notice Creates executable files on the filesystem
notice Creates hidden or system file

Rules (0cnts)

Level Name Description Collection

Network (5cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
keema.tk US PUBLIC-DOMAIN-REGISTRY 207.174.212.247 clean
birliklpgotogaz.com TR Ibrahim Can 46.31.79.106 clean
46.31.79.106 TR Ibrahim Can 46.31.79.106 clean
142.250.204.67 US GOOGLE 142.250.204.67 clean
207.174.212.247 US PUBLIC-DOMAIN-REGISTRY 207.174.212.247 phishing

Suricata ids



Similarity measure (PE file only) - Checking for service failure