Report - file.xls

VBA_macro Antivirus MSOffice File
ScreenShot
Created 2023.06.07 17:59 Machine s1_win7_x6402
Filename file.xls
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Autho
AI Score Not founds Behavior Score
1.8
ZERO API file : clean
VT API (file) 29 detected (malicious, high confidence, Valyria, score, Powershell, MacroS, modification of W97M, OLE2, Wacatac, Detected, ai score=88, Probably Heur, W97ShellS, CLASSIC)
md5 b4b1d0f39ef9ad937d94513e95d324d0
sha256 b711f09fc3ea81a624d6103df522d4bd46661525f0d1c7165046c8f8929f7a26
ssdeep 3072:lU1jBEwpI62IlFbKEa9orXCQ5AX3wxv8Sx+cEA9bY:IBEwpI62IyEaYSBQVZA
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
warning File has been identified by 29 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice An application raised an exception which may be indicative of an exploit crash
info One or more processes crashed

Rules (3cnts)

Level Name Description Collection
warning Contains_VBA_macro_code Detect a MS Office document with embedded VBA macro code [binaries] binaries (upload)
watch Antivirus Contains references to security software binaries (upload)
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure