Report - document_133_invoice_PDF.msi

Malicious Library ASPack MSOffice File OS Processor Check CAB
ScreenShot
Created 2022.12.07 09:18 Machine s1_win7_x6402
Filename document_133_invoice_PDF.msi
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Code pa
AI Score Not founds Behavior Score
2.6
ZERO API file : clean
VT API (file)
md5 76bf2b13ab0bdb12c1b8fc474fb9984e
sha256 070f9169977c766c426e9c1a8161a40f54a068ef7cc1c3090d226e87dc890095
ssdeep 12288:nwHL0D7CkCPumy9chfA+tO5O//M777777LwmqLuSgF3u:wHL0S/zyt+M5OX/qtF3u
imphash
impfuzzy
  Network IP location

Signature (8cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice Performs some HTTP requests
notice Queries the disk size which could be used to detect virtual machine with small fixed size or dynamic allocation
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info Queries for the computername

Rules (5cnts)

Level Name Description Collection
watch ASPack_Zero ASPack packed file binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
info CAB_file_format CAB archive file binaries (upload)
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)

Network (3cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://saintrefunda.com/ US DIGITALOCEAN-ASN 165.227.104.80 clean
saintrefunda.com US DIGITALOCEAN-ASN 165.227.104.80 clean
165.227.104.80 US DIGITALOCEAN-ASN 165.227.104.80 mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure