Report - Invoice_9255471.xls

VBA_macro MSOffice File
ScreenShot
Created 2021.07.22 11:09 Machine s1_win7_x6402
Filename Invoice_9255471.xls
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Title
AI Score Not founds Behavior Score
1.0
ZERO API file : mailcious
VT API (file) 16 detected (malicious, high confidence, Dridex, CVE-2017-8570, Ole2, druvzi, ai score=84, Probably Heur, W97ShellB, obfuscated)
md5 556daf1119d264ba2732fee95b65ea70
sha256 413934e841b46e2dba1902765b5c49d2386736af1492ae274ccb0e50353a388b
ssdeep 12288:kGDH3roxGMC/mc4bl3q5uaFsvCgdz2l5MjavMmIf+f:kGDXEUH/4EnsvJZ2lKjavMm/
imphash
impfuzzy
  Network IP location

Signature (2cnts)

Level Description
watch File has been identified by 16 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)

Rules (2cnts)

Level Name Description Collection
warning Contains_VBA_macro_code Detect a MS Office document with embedded VBA macro code [binaries] binaries (upload)
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure