Report - 1.xlsb

Excel Binary Workbook file format(xlsb)
ScreenShot
Created 2021.11.02 14:39 Machine s1_win7_x6403
Filename 1.xlsb
Type Microsoft Excel 2007+
AI Score Not founds Behavior Score
1.8
ZERO API file : clean
VT API (file) 18 detected (GenericKD, XLS4, IcedID, XLSB, Camelot, a variant of DOC, ai score=85, EncDoc, PMSH, Malicious, score)
md5 dee6841dad2810dbb7d487803e3f2b4c
sha256 f7c19c2b33e47e2ab2d742587e9b593ac3d8756caf37c710ae1f2800aeb144a9
ssdeep 6144:8LuLooVw6XdPYlqpxEHjXaAtt3A1DXy47LZxUvsQafh:8KLoaXdWEEDXaAzg+iU0Q8
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
watch File has been identified by 18 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Creates hidden or system file

Rules (1cnts)

Level Name Description Collection
info xlsb Excel Binary Workbook file format detection binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure