Report - ATTR-926289951-Apr-4.xlsb

Malicious Library Excel Binary Workbook file format(xlsb)
ScreenShot
Created 2022.04.05 17:54 Machine s1_win7_x6401
Filename ATTR-926289951-Apr-4.xlsb
Type Microsoft Excel 2007+
AI Score Not founds Behavior Score
4.2
ZERO API file : clean
VT API (file)
md5 79b334216825f7afbc495d0d07abed1c
sha256 988dc864a33c9e5abc5d3519b5334b1cbb958ab945c975a114c39b29e83720b3
ssdeep 24576:zvTXkVoeBosJ0Rev1ke6P00TDKqKxBNKxBvKxBfKxBdKxBVKxBOId:zDkvBokCP00XKq+N+v+f+d+V+OY
imphash
impfuzzy
  Network IP location

Signature (9cnts)

Level Description
watch Communicates with host for which no DNS query was performed
watch Network communications indicative of a potential document or script payload download was initiated by the process excel.exe
watch One or more non-whitelisted processes were created
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates a suspicious process
notice Creates executable files on the filesystem
notice Creates hidden or system file
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice Performs some HTTP requests

Rules (2cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
info xlsb Excel Binary Workbook file format detection binaries (upload)

Network (6cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://149.255.36.223/44651,6679619213.dat DE HVC-AS 149.255.36.223 15659 mailcious
http://185.33.86.42/44651,6679619213.dat US HZ Hosting Ltd 185.33.86.42 mailcious
http://185.82.126.17/44651,6679619213.dat LV Sia Nano IT 185.82.126.17 15661 mailcious
149.255.36.223 DE HVC-AS 149.255.36.223 mailcious
185.33.86.42 US HZ Hosting Ltd 185.33.86.42 mailcious
185.82.126.17 LV Sia Nano IT 185.82.126.17 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure