Report - 15.docx

VBA_macro MSOffice File
ScreenShot
Created 2021.07.21 09:10 Machine s1_win7_x6403
Filename 15.docx
Type Microsoft Word 2007+
AI Score Not founds Behavior Score
2.4
ZERO API file : clean
VT API (file) 9 detected (Groooboor, CVE-2017-0199, equmby, ai score=88)
md5 0e3e79026507f3cf814f75cd53fea060
sha256 30113bb379e8104f9471bb5430eabc6fa2cfedd7b67d6fe69f83dac8ee808765
ssdeep 6144:td8C3Aj15H+uL6jYp8u97Q5J1fE3tbWS2QOuv3ibzwSDHuR:DHqnL6jd31s3p3ifwSqR
imphash
impfuzzy
  Network IP location

Signature (6cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Creates (office) documents on the filesystem
notice Creates hidden or system file
notice File has been identified by 9 AntiVirus engines on VirusTotal as malicious
notice Performs some HTTP requests

Rules (2cnts)

Level Name Description Collection
warning Contains_VBA_macro_code Detect a MS Office document with embedded VBA macro code [binaries] binaries (download)
info Microsoft_Office_File_Zero Microsoft Office File binaries (download)

Network (5cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
https://feedbackportal.download/ecm/ibm/3173379797/ US DIGITALOCEAN-ASN 208.68.37.17 clean
https://feedbackportal.download/ecm/ibm/3173379797/converter.dot US DIGITALOCEAN-ASN 208.68.37.17 mailcious
https://feedbackportal.download/ecm/ibm/ US DIGITALOCEAN-ASN 208.68.37.17 clean
feedbackportal.download US DIGITALOCEAN-ASN 208.68.37.17 mailcious
208.68.37.17 US DIGITALOCEAN-ASN 208.68.37.17 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure