Report - taxve_710451_20210816_93407095_353985987.xlsm

ScreenShot
Created 2021.08.23 18:58 Machine s1_win7_x6403
Filename taxve_710451_20210816_93407095_353985987.xlsm
Type Microsoft Excel 2007+
AI Score Not founds Behavior Score
4.8
ZERO API file : clean
VT API (file) 27 detected (GenericKDZ, XLS4, IcedID, MalDoc, ali1000101, XLSM, Camelot, FCEV, Woreflint, Malicious, score, ai score=83, Probably Heur, W97ShellN, XmlMacroSheet, Icedld)
md5 9a812ebcc070d2a63465ebb416ba8b95
sha256 5335f80d6710c813429b45a7a9dd460c1d9a4ffd460a4fa42088b35e71534f9d
ssdeep 6144:ScNSLcq+YXEsIGJWFXkpMQfmnoM0G1TY+Z6WysSIS:/PYXEshasMumZ0aT7KrH
imphash
impfuzzy
  Network IP location

Signature (10cnts)

Level Description
warning File has been identified by 27 AntiVirus engines on VirusTotal as malicious
warning Generates some ICMP traffic
watch One or more non-whitelisted processes were created
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Creates (office) documents on the filesystem
notice Creates a suspicious process
notice Creates hidden or system file
notice Performs some HTTP requests
info Checks amount of memory in system

Rules (0cnts)

Level Name Description Collection

Network (10cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
https://investtomontenegro.com/wp-content/plugins/wordpress-seo/lib/migrations/8dXd8jlaax.php US GOOGLE 34.94.136.184 mailcious
https://cdn.discordapp.com/attachments/876792192524501045/876837688651681843/1.dll Unknown 162.159.130.233 clean
https://cdn.discordapp.com/attachments/876792192524501045/876837576193998848/1.dll Unknown 162.159.130.233 clean
https://cdn.discordapp.com/attachments/876792192524501045/876837913906774076/1.dll Unknown 162.159.130.233 clean
investtomontenegro.com US GOOGLE 34.94.136.184 mailcious
lamisionerafm.com CA OVH SAS 51.222.42.168 clean
cdn.discordapp.com Unknown 162.159.129.233 malware
34.94.136.184 US GOOGLE 34.94.136.184 mailcious
51.222.42.168 CA OVH SAS 51.222.42.168 mailcious
162.159.130.233 Unknown 162.159.130.233 malware

Suricata ids



Similarity measure (PE file only) - Checking for service failure