Report - REF-1188572401-Dec-20.xlsb

Excel Binary Workbook file format(xlsb)
ScreenShot
Created 2021.12.21 09:27 Machine s1_win7_x6403
Filename REF-1188572401-Dec-20.xlsb
Type Microsoft Excel 2007+
AI Score Not founds Behavior Score
5.6
ZERO API file : clean
VT API (file)
md5 5542ead8d0d49cc5161a4b91e679c053
sha256 3b75f70103fcaad2e3ede65e9921daa9f9b816b3fd88ba7e3ef0b1f812c0087d
ssdeep 12288:Q/ij6LhR8bTsmoRhqrpSbZao+zcm0lTvLeK60sI+B/VONLb15i3amcYVspp3waIq:Q7haboKSBTvLeKoIK/VeLb3i3a8Vk9BP
imphash
impfuzzy
  Network IP location

Signature (11cnts)

Level Description
danger Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually)
watch Communicates with host for which no DNS query was performed
watch Network communications indicative of a potential document or script payload download was initiated by the process excel.exe
watch One or more non-whitelisted processes were created
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Creates a suspicious process
notice Creates executable files on the filesystem
notice Creates hidden or system file
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice Performs some HTTP requests

Rules (1cnts)

Level Name Description Collection
info xlsb Excel Binary Workbook file format detection binaries (upload)

Network (5cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://185.82.127.240/44551.3878077546.dat LV Sia Nano IT 185.82.127.240 clean
http://101.99.95.227/44551.3878077546.dat Unknown 101.99.95.227 clean
101.99.95.227 Unknown 101.99.95.227 clean
45.87.154.132 Unknown 45.87.154.132 clean
185.82.127.240 LV Sia Nano IT 185.82.127.240 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure