Report - SNC-612086596-Apr-6.xlsb

Malicious Library Excel Binary Workbook file format(xlsb)
ScreenShot
Created 2022.04.07 11:26 Machine s1_win7_x6401
Filename SNC-612086596-Apr-6.xlsb
Type Microsoft Excel 2007+
AI Score Not founds Behavior Score
5.6
ZERO API file : clean
VT API (file) 9 detected (Save, ma35, SneakyBin, Eldorado, Macro40)
md5 4625181b70514f226dcddbb7e9ff87fd
sha256 b7cdf96a1312ef4996f18b710215c9a00d40219867d80095b635ce4dbd2fdb23
ssdeep 24576:GF+BnmJkeGC2PbA/HMoNYIPeuVe2HHCkm6CyIwl6hafINeWHWR72vF+BnmJkeGC9:6ymaeGC9YSeQHCkXC/wl6LcW2929ymaW
imphash
impfuzzy
  Network IP location

Signature (11cnts)

Level Description
danger Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually)
watch Communicates with host for which no DNS query was performed
watch Network communications indicative of a potential document or script payload download was initiated by the process excel.exe
watch One or more non-whitelisted processes were created
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates a suspicious process
notice Creates executable files on the filesystem
notice Creates hidden or system file
notice File has been identified by 9 AntiVirus engines on VirusTotal as malicious
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice Performs some HTTP requests

Rules (2cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
info xlsb Excel Binary Workbook file format detection binaries (upload)

Network (5cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://91.234.254.131/7790983516.dat NL WorldStream B.V. 91.234.254.131 15827 mailcious
http://212.46.38.179/7790983516.dat SA Saudi Business Machines Ltd 212.46.38.179 15828 mailcious
212.46.38.179 SA Saudi Business Machines Ltd 212.46.38.179 mailcious
104.225.129.111 US FIBERHUB 104.225.129.111 mailcious
91.234.254.131 NL WorldStream B.V. 91.234.254.131 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure