Report - XXW-902058.xlsm

MS_XLSX_Macrosheet
ScreenShot
Created 2023.02.14 08:35 Machine s1_win7_x6402
Filename XXW-902058.xlsm
Type Microsoft Excel 2007+
AI Score Not founds Behavior Score
4.4
ZERO API file : clean
VT API (file) 41 detected (Emotet, MSOfficeExcel, GenericKDS, FCHG, Save, ma35, GenericS, XLSM, aggr, Camelot, Malcode, multiple detections, VSNTCF22, Emotet03222, MalDoc, ali1000101, CLASSIC, ai score=86, ASMalwRG, PKCL, Malicious, score, XlmMacro, S1774, Probably Heur, W97ShellN, XmlMacroSheet, Mofer, bXEmOA)
md5 877dd4503b88a3610e98c057ed0de96c
sha256 4666110c67ad5b96bc4ff1f9b5ebf21ccbbd4ed2604049e52965589221967dc9
ssdeep 1536:llFXmY3B6Y8r7mfqN1+TpCgcgsMA6VIcrW:ll1mG4YqVN1+TtRrW
imphash
impfuzzy
  Network IP location

Signature (9cnts)

Level Description
danger File has been identified by 41 AntiVirus engines on VirusTotal as malicious
watch Network communications indicative of a potential document or script payload download was initiated by the process excel.exe
notice Allocates read-write-execute memory (usually to unpack itself)
notice An application raised an exception which may be indicative of an exploit crash
notice Creates (office) documents on the filesystem
notice Creates executable files on the filesystem
notice Creates hidden or system file
notice Performs some HTTP requests
info One or more processes crashed

Rules (1cnts)

Level Name Description Collection
watch MS_XLSX_with_Macrosheet (no description) binaries (upload)

Network (16cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://apps.identrust.com/roots/dstrootcax3.p7c US CCCH-3 23.43.165.105 clean
http://www.babylinesl.com/catalog/iVsl6YvlyIyX/ Unknown 185.70.93.244 malware
alebit.de DE netcup GmbH 91.204.46.166 malware
unada.us US GOOGLE 216.239.36.21 malware
www.arkpp.com Unknown malware
physioacademy.co.uk GB Paragon Internet Group Limited 31.170.127.252 malware
automobile-facile.fr Unknown 146.59.209.152 clean
www.avrworks.com Unknown malware
apps.identrust.com US CCCH-3 23.43.165.105 clean
www.babylinesl.com Unknown 185.70.93.244 malware
91.204.46.166 DE netcup GmbH 91.204.46.166 malware
216.239.34.21 US GOOGLE 216.239.34.21 mailcious
121.254.136.57 KR LG DACOM Corporation 121.254.136.57 clean
185.70.93.244 Unknown 185.70.93.244 clean
146.59.209.152 Unknown 146.59.209.152 phishing
31.170.127.252 GB Paragon Internet Group Limited 31.170.127.252 malware

Suricata ids



Similarity measure (PE file only) - Checking for service failure