Report - doc-144430402.xls

Downloader MSOffice File
ScreenShot
Created 2021.10.06 18:16 Machine s1_win7_x6403
Filename doc-144430402.xls
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1251, Name
AI Score Not founds Behavior Score
4.0
ZERO API file : clean
VT API (file)
md5 8e7e1a9a754cdaf05c7969966d6ab878
sha256 231816b66c49c187966b86a66b6213ef4f7f4cd8cede3031f69952bccd7534ca
ssdeep 6144:wKpb8rGYrMPe3q7Q0XV5xtuEsi8/dgD9jWXcZZRBTq1BOzTwvOsPDslAvS32vI7Z:59jVzTmszTwvTDy33LvfP1OW/
imphash
impfuzzy
  Network IP location

Signature (7cnts)

Level Description
danger The process excel.exe wrote an executable file to disk which it then attempted to execute
watch Network communications indicative of a potential document or script payload download was initiated by the process excel.exe
watch One or more non-whitelisted processes were created
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Creates a suspicious process
notice Performs some HTTP requests

Rules (2cnts)

Level Name Description Collection
warning Microsoft_Office_File_Downloader_Zero Microsoft Office File Downloader binaries (upload)
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)

Network (7cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://access-cs.com/WH0dOuF31Vjo/sep.html US INMOTI-1 198.46.82.18 clean
http://proflizbowles.com/FC28yk4Sx7Rr/sep.html US INMOTI-1 198.46.82.18 clean
access-cs.com US INMOTI-1 198.46.82.18 clean
proflizbowles.com US INMOTI-1 198.46.82.18 clean
dreamonvibes.gr US UNIFIEDLAYER-AS-1 192.185.35.74 clean
192.185.35.74 US UNIFIEDLAYER-AS-1 192.185.35.74 mailcious
198.46.82.18 US INMOTI-1 198.46.82.18 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure