Report - 1311719753.ppt

VBA_macro Generic Malware MSOffice File
ScreenShot
Created 2021.10.19 17:11 Machine s1_win7_x6403
Filename 1311719753.ppt
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Titl
AI Score Not founds Behavior Score
1.6
ZERO API file : clean
VT API (file) 22 detected (Valyria, Eldorado, VSNTJI21, Ole2, druvzi, Siggen3, Artemis, ai score=87, Powdow)
md5 3e804f9f266483ec4884546f08e396a8
sha256 93002698d17ed42fda59a7a37533c12bd13ce27fae60d6673c7b71f94a0eccc7
ssdeep 384:Z9caf4fFqIlETSlyCFKkr0pw1MKUP5Pv6AZJlcbclFo39D:AagNblETSlyCFKvw1W6Gcbcjo
imphash
impfuzzy
  Network IP location

Signature (3cnts)

Level Description
warning File has been identified by 22 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)

Rules (3cnts)

Level Name Description Collection
warning Contains_VBA_macro_code Detect a MS Office document with embedded VBA macro code [binaries] binaries (upload)
warning Generic_Malware_Zero Generic Malware binaries (upload)
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)

Network (2cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
www.bitly.com US GOOGLE-PRIVATE-CLOUD 67.199.248.14 mailcious
67.199.248.15 US GOOGLE-PRIVATE-CLOUD 67.199.248.15 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure