Report - Invoice-No.-9004_20210908.xlsb

ScreenShot
Created 2021.09.09 08:51 Machine s1_win7_x6403
Filename Invoice-No.-9004_20210908.xlsb
Type Microsoft Excel 2007+
AI Score Not founds Behavior Score
1.6
ZERO API file : clean
VT API (file) 5 detected (XLS4, IcedID, Artemis, Outbreak)
md5 cc064043229bad8f94a41de8a6ce8721
sha256 ab0918b014bd81b35ac4e11e74dcd68add1ca8318dde0a48139152627e6f3c03
ssdeep 1536:EWw/szrvkfOEwt1sMwv2sSMGuCAnq1Ue+TAj/h3vD4SZ/Z/hJGBfmIGEumGxfVx5:FTt7s32sSMLCx1KwpD4o/hwBuI5udyU3
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Creates hidden or system file
notice File has been identified by 5 AntiVirus engines on VirusTotal as malicious

Rules (0cnts)

Level Name Description Collection

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure