Report - Receipt-894324.xls

VBA_macro MSOffice File
ScreenShot
Created 2024.02.12 23:12 Machine s1_win7_x6401
Filename Receipt-894324.xls
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Title: Invoice 894324 from Quickbooks, LLC, Author: Quickbooks, LLC, Last Saved By: user, Name of Creating Application: Microsoft Excel, Create Time/Date: Wed J
AI Score Not founds Behavior Score
3.4
ZERO API file : mailcious
VT API (file) 41 detected (malicious, high confidence, score, OLE2, Macros, Dridex, Save, 0NA103GF21, druvzi, TOPIS, wwFjRqjqO3C, AJAM, Siggen3, ADXD, Detected, ai score=100, Malware@#lc7v1onpryii, PSTT, Eldorado, Static AI, Malicious OLE)
md5 73f2506109fae384bc40c7ba7cb5fc9c
sha256 eb5b61b197c89ba6a19d3eaeda56d858f6bd30beaff0a43719fc5c6591e7ad2d
ssdeep 12288:DRYbXrlUc6XS/CwRl+4MW1H5onZHBDznxcp/c0UGtkbByxlFYd2DrpE9Nr:sUc6EjDMW1UrDjxcNcfgZI2or
imphash
impfuzzy
  Network IP location

Signature (6cnts)

Level Description
danger File has been identified by 41 AntiVirus engines on VirusTotal as malicious
watch Creates suspicious VBA object
watch One or more non-whitelisted processes were created
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates a suspicious process
info Checks amount of memory in system

Rules (2cnts)

Level Name Description Collection
warning Contains_VBA_macro_code Detect a MS Office document with embedded VBA macro code [binaries] binaries (upload)
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
jeromfastsolutions.com Unknown mailcious

Suricata ids



Similarity measure (PE file only) - Checking for service failure