Report - ATTR-147470270-Apr-4.xlsb

Malicious Library Excel Binary Workbook file format(xlsb)
ScreenShot
Created 2022.04.06 17:22 Machine s1_win7_x6402
Filename ATTR-147470270-Apr-4.xlsb
Type Microsoft Excel 2007+
AI Score Not founds Behavior Score
4.8
ZERO API file : clean
VT API (file) 13 detected (Save, ma35, SneakyBin, Eldorado, GreenOffice12210, Macro40, Artemis, Qakbot, AMDG)
md5 31d57098f695e4a999a109309cc6cc6a
sha256 8b711bf4fd44853bbd5e833d5b472a7d7214ab637083eaf99590acd1aca8691a
ssdeep 24576:vvTXkVoeBosJ0Rev1ke6P00TDKqKxBNKxBvKxBfKxBdKxBVKxBOId:vDkvBokCP00XKq+N+v+f+d+V+OY
imphash
impfuzzy
  Network IP location

Signature (10cnts)

Level Description
watch Communicates with host for which no DNS query was performed
watch File has been identified by 13 AntiVirus engines on VirusTotal as malicious
watch Network communications indicative of a potential document or script payload download was initiated by the process excel.exe
watch One or more non-whitelisted processes were created
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates a suspicious process
notice Creates executable files on the filesystem
notice Creates hidden or system file
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice Performs some HTTP requests

Rules (2cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
info xlsb Excel Binary Workbook file format detection binaries (upload)

Network (6cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://185.82.126.17/44651,6679619213.dat LV Sia Nano IT 185.82.126.17 15661 mailcious
http://185.33.86.42/44651,6679619213.dat US HZ Hosting Ltd 185.33.86.42 mailcious
http://149.255.36.223/44651,6679619213.dat DE HVC-AS 149.255.36.223 15659 mailcious
149.255.36.223 DE HVC-AS 149.255.36.223 mailcious
185.33.86.42 US HZ Hosting Ltd 185.33.86.42 mailcious
185.82.126.17 LV Sia Nano IT 185.82.126.17 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure