Report - ComplianceRep-1549899952-Apr-18.xlsb

Excel Binary Workbook file format(xlsb)
ScreenShot
Created 2022.04.19 09:20 Machine s1_win7_x6403
Filename ComplianceRep-1549899952-Apr-18.xlsb
Type Microsoft Excel 2007+
AI Score Not founds Behavior Score
4.8
ZERO API file : clean
VT API (file)
md5 05a9cccfd383c90fc0c6ce68363f4632
sha256 0849368ebc533c3c9e37a09f271e54ffd5665ae2b23b7270c3ce3b2f40399b75
ssdeep 24576:7MMok4+D/HMoNYIPeuVe2HHCkm6CyIwl6hafINeWHWR72fMMok4+EWFBGcMKSWXF:7n4+NYSeQHCkXC/wl6LcW292fn4+JjMc
imphash
impfuzzy
  Network IP location

Signature (11cnts)

Level Description
watch Communicates with host for which no DNS query was performed
watch Network communications indicative of a potential document or script payload download was initiated by the process excel.exe
watch One or more non-whitelisted processes were created
notice Allocates read-write-execute memory (usually to unpack itself)
notice An application raised an exception which may be indicative of an exploit crash
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Creates a suspicious process
notice Creates hidden or system file
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice Performs some HTTP requests
info One or more processes crashed

Rules (1cnts)

Level Name Description Collection
info xlsb Excel Binary Workbook file format detection binaries (upload)

Network (6cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://146.70.87.163/44666,6175321759.dat Unknown 146.70.87.163 clean
http://91.194.11.15/44666,6175321759.dat IL A.b Internet Solutions 91.194.11.15 clean
http://5.254.118.198/44666,6175321759.dat RO Voxility LLP 5.254.118.198 clean
146.70.87.163 Unknown 146.70.87.163 clean
91.194.11.15 IL A.b Internet Solutions 91.194.11.15 mailcious
5.254.118.198 RO Voxility LLP 5.254.118.198 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure